H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 232

Advertising
background image

218

[AC2-isp-dm1] authorization portal radius-scheme rs1

[AC2-isp-dm1] accounting portal radius-scheme rs1

[AC2-isp-dm1] quit

4.

Enable portal authentication on the interface connected to the client:
# Configure the portal server, with name configured as local, IP address as 16.16.0.8 (the virtual
IP address of VRRP group 1), and URL as http://16.16.0.8/portal/logon.htm.

[AC2] portal server local ip 16.16.0.8 url http://16.16.0.8/portal/logon.htm

# Configure a portal-free rule on AC 2, allowing packets from AC 1 to pass through without portal

authentication. This configuration is required only when the roles (master/backup) of the ACs for

stateful failover are different from those for VRRP.

[AC2]portal free-rule 0 source interface gigabitethernet1/0/1 destination any

# Configure the local portal server to support HTTP.

[AC2]portal local-server http

# On the interface connected to the client, specify the authentication domain dm1 for portal users

and enable portal authentication.

[AC2] interface vlan-interface 100

[AC2–Vlan-interface100] portal domain dm1

[AC2–Vlan-interface100] portal server local method direct

# Specify the source IP address for outgoing portal packets as 16.16.0.8, the virtual IP address of

VRRP group 1.

[AC2–Vlan-interface100] portal nas-ip 16.16.0.8

5.

Configure portal stateful failover:
# Assign interface VLAN-interface 100 to portal group 1.

[AC2] interface vlan-interface 100

[AC2–Vlan-interface100] portal backup-group 1

[AC2–Vlan-interface100] quit

# Set the device ID of AC 2 in the stateful failover mode to 2.

[AC2] nas device-id 2

# Configure the source IP address for outgoing RADIUS packets as 8.1.1.68, the virtual IP address
of VRRP group 2.

[AC2] radius nas-ip 8.1.1.68

6.

Configure the WLAN service:
# Specify the backup AC IP address.

[AC2] wlan backup-ac ip 2.2.2.1

# Enable hot backup.

[AC2] hot-backup enable

# Configure VLAN 10 as the VLAN for AC hot backup.

[AC2] hot-backup vlan 10

[AC2] quit

# Create interface WLAN-ESS 1, and add it to VLAN 100.

[AC2] interface WLAN-ESS 1

[AC2-WLAN-ESS1] port link-type hybrid

[AC2-WLAN-ESS1] port hybrid vlan 100 untagged

[AC2-WLAN-ESS1] port hybrid pvid VLAN 100

[AC2-WLAN-ESS1] quit

Advertising