设为首页收藏本站language→→ 语言切换

鸿鹄论坛

 找回密码
 论坛注册

QQ登录

先注册再绑定QQ

查看: 2153|回复: 0
收起左侧

[文档资料] 华为WLAN安全认证配置Portal认证,外置Protal服务器TSM对接

[复制链接]
 成长值: 59200
发表于 2024-1-8 17:43:54 | 显示全部楼层 |阅读模式
简介
这也是安全认证的最后一种方式了,就是AC与外边Protal服务器对接的认证,这里采用的是华为​ ​TSM​​(目前最新的已经改为policy center了),也支持第三方认证服务器,这里只是简单演示下,更多策略的控制跟应用,可以参考手册说明。
拓扑(省略)
拓扑其实很简单的,跟平常的无线拓扑一样,可以参考之前的文章即可,这里主要讲解AC上面的Protal定义,以及测试。
AC初始化
[Huawei-AC6605]dhcp enable
[Huawei-AC6605]vlan batch 88 100
[Huawei-AC6605]interface Vlanif 88
[Huawei-AC6605-Vlanif88]ip address 192.168.88.1 255.255.255.0
[Huawei-AC6605-Vlanif88]dhcp select interface
[Huawei-AC6605]interface Vlanif 100
[Huawei-AC6605-Vlanif100]ip address 192.168.100.1 255.255.255.0
[Huawei-AC6605-Vlanif100]dhcp select interface
[Huawei-AC6605-Vlanif100]dhcp server dns-list 218.85.152.99
[Huawei-AC6605]interface Vlanif 1
[Huawei-AC6605-Vlanif1]ip address 192.168.31.100 255.255.255.0
配置AC与AP相连的端口
[Huawei-AC6605]interface GigabitEthernet0/0/11
[Huawei-AC6605-GigabitEthernet0/0/11]port link-type trunk
[Huawei-AC6605-GigabitEthernet0/0/11]port trunk pvid vlan 88
[Huawei-AC6605-GigabitEthernet0/0/11]undo port trunk allow-pass vlan 1
[Huawei-AC6605-GigabitEthernet0/0/11]port trunk allow-pass vlan 88 100
配置RADIUS服务器模版
[Huawei-AC6605]radius-server template portal
[Huawei-AC6605-radius-portal]radius-server authentication 192.168.31.209 1812
[Huawei-AC6605-radius-portal]radius-server accounting 192.168.31.209 1813
[Huawei-AC6605-radius-portal]radius-server shared-key simple huawei123
配置RADIUS授权服务器
[Huawei-AC6605]radius-server authorization 192.168.31.209 shared-key simple huawei123
配置认证方案和计费方案
[Huawei-AC6605] aaa
[Huawei-AC6605-aaa]authentication-scheme portal
[Huawei-AC6605-aaa-authen-portal] authentication-mode radius
[Huawei-AC6605-aaa]accounting-scheme portal
[Huawei-AC6605-aaa-accounting-portal] accounting-mode none
配置域
[Huawei-AC6605-aaa]domain portal
[Huawei-AC6605-aaa-domain-portal]radius-server portal
[Huawei-AC6605-aaa-domain-portal]authentication-scheme portal
[Huawei-AC6605-aaa-domain-portal]accounting-scheme portal
配置Portal认证服务器
[Huawei-AC6605]web-auth-server portal
[Huawei-AC6605-web-auth-server-portal]server-ip 192.168.31.209
[Huawei-AC6605-web-auth-server-portal]port 50100
[Huawei-AC6605-web-auth-server-portal]shared-key simple password
[Huawei-AC6605-web-auth-server-portal]url https://192.168.31.209:8443/newwebauth
在接口下绑定Portal认证服务器
[Huawei-AC6605]interface vlanif 100
[Huawei-AC6605-Vlanif100]web-auth-server portal direct
配置免认证规则
[Huawei-AC6605]portal free-rule 0 destination ip 192.168.31.209 mask 255.255.255.255
[Huawei-AC6605]portal free-rule 1 destination ip 218.85.152.99 mask 255.255.255.255
建立wlan-ess接口和调用Portal认证服务器与认证域
[Huawei-AC6605]interface Wlan-Ess 1
[Huawei-AC6605-Wlan-Ess1] port hybrid pvid vlan 100
[Huawei-AC6605-Wlan-Ess1] port hybrid untagged vlan 100
[Huawei-AC6605-Wlan-Ess1] web-authentication first-mac
[Huawei-AC6605-Wlan-Ess1] permit-domain name portal
配置wlan-ess接口,在wlan-ess接口调用内置Portal与允许的认证域
[Huawei-AC6605]interface Wlan-Ess 1
[Huawei-AC6605-Wlan-Ess1]port hybrid pvid vlan 100
[Huawei-AC6605-Wlan-Ess1]port hybrid untagged vlan 100
[Huawei-AC6605-Wlan-Ess1]portal local-server enable
[Huawei-AC6605-Wlan-Ess1]permit-domain name default
配置AC的源接口,用于AC和AP之间建立隧道通信。
[Huawei-AC6605]wlan
[Huawei-AC6605-wlan-view]wlan ac source interface vlanif88
配置AP的认证方式为免认证
[Huawei-AC6605-wlan-view]ap-auth-mode no-auth
添加AP
[Huawei-AC6605-wlan-view]ap id 0 type-id 31 mac d4b1-10ac-0b00 sn 210235582910D6000354
创建名为“wmm1”的WMM模版,参数采用默认配置
[Huawei-AC6605-wlan-view]wmm-profile name wmm1 id 1
创建名为“radio1”的射频模版,绑定WMM模版“wmm1”
[Huawei-AC6605-wlan-view]radio-profile name radio1 id 1
[Huawei-AC6605-wlan-radio-prof-radio1]wmm-profile id 1
创建名为“traffic1”的流量模版,参数采用默认配置
[Huawei-AC6605-wlan-view]traffic-profile name traffic1 id 1
创建名为“security1”的安全模版,认证方式为WEP认证,开放认证,不加密
[Huawei-AC6605-wlan-view]security-profile name security1 id 1
创建名为“service1”的服务集,并绑定流量模版和安全模版,WLAN-ESS接口
[Huawei-AC6605-wlan-view]service-set name service1 id 1
[Huawei-AC6605-wlan-service-set-service1]wlan-ess 1
[Huawei-AC6605-wlan-service-set-service1]ssid huawei-portal
[Huawei-AC6605-wlan-service-set-service1]traffic-profile id 1
[Huawei-AC6605-wlan-service-set-service1]security-profile id 1
[Huawei-AC6605-wlan-service-set-service1]service-vlan 100
配置AP对应的VAP,下发WLAN服务
[Huawei-AC6605-wlan-view]ap 0 radio 0
[Huawei-AC6605-wlan-radio-0/0]radio-profile id 1
[Huawei-AC6605-wlan-radio-0/0]service-set id 1 wlan 1
下发AP的WLAN配置
[Huawei-AC6605-wlan-view]commit all

评分

参与人数 1好评度 +1 收起 理由
leader_gst + 1

查看全部评分

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2024-4-28 04:54 , Processed in 0.057026 second(s), 9 queries , Redis On.  

  Powered by Discuz!

  © 2001-2024 HH010.COM

快速回复 返回顶部 返回列表