无线AC本地web portal server与Cisco认证服务器ISE完成对接,实现portal认证。
前置要求:无线AC需要R5428及更新版本
给AC传入定制的本地ISE portal页面文件。(已放在本案例附件文件)
配置AC:
#
dhcp server ip-pool 12
gateway-list 191.12.1.54
network 191.12.0.0 mask 255.255.0.0
#
wlan service-template ise
ssid H3C_ise
vlan 12
portal enable method direct
portal domain ise
portal apply web-server ise
service-template enable
#
interface NULL0
#
interface Vlan-interface1
ip address 192.168.0.100 255.255.255.0
#
interface Vlan-interface12
ip address 191.12.1.54 255.255.0.0
#
interface Vlan-interface1200
ip address 191.120.1.54 255.255.0.0
#
radius scheme ise
primary authentication 8.1.1.19 key cipher $c$3$Wcl9eNw215DB2uk6ucQKsBJMQXif7AM=
primary accounting 8.1.1.19 key cipher $c$3$9gdSv7PGosMXJkTDMQMm1sfvArovU6o=
user-name-format without-domain
nas-ip 191.120.1.54
#
domain ise
authentication default radius-scheme ise
authorization default radius-scheme ise
accounting default radius-scheme ise
#
portal host-check enable
portal free-rule 10000 destination ip 191.12.1.54 255.255.255.255
#
portal web-server ise
url https://8.1.1.19:8443/portal/PortalSetup.action?portal=f0ae43f0-7159-11e7-a355-005056aba474
server-type ise
#
portal local-web-server http
default-logon-page ise_h3c.zip
#
portal local-web-server https
default-logon-page ise_h3c.zip
#
ip http enable
ip https enable
#
wlan ap-group default-group
vlan 1
#
wlan ap ax3 model WA5530
serial-id 219801A0YF9172G02233
vlan 1
radio 1
channel 36
radio enable
service-template ise
配置Cisco ISE服务器
1) 添加AC设备。选择“Administration > Network Resources > Network
Device Profiles”,在左侧区域单击“Add”,新建网络设备模板“H3c”,“Supported Protocols”配
置为“RADIUS”,单击“Submit”
2) 添加AC设备。选择“Administration > Network Resources > Network Devices”,在右侧操作区域单击“Add”,配置设备名称为“ac”, IP地址为“191.120.1.54/32”,RADIUS共享密钥为“H3c123”,单击“Submit”。
3)
Protocols”,勾选“Default Network
Access”,单击“Edit”; 勾选“Allow CHAP”,其他参数使用缺省配置即可,单击“Save”
4) 添加用户。选择“Administration >
Identity Management > Identities > Users”,在右侧操
作区域单击“Add”,创建帐号“huasan”,密码为“Huasan123456”,单击
“Submit”。
用户重定向输入用户名和密码后,设备上portal用户上线成功
[H3C]dis p u a
Total portal users: 2
Username: huasan
AP name: ax3
Radio ID: 1
SSID: H3C_ise
Portal server: N/A
State: Online
VPN instance: N/A
MAC IP VLAN Interface
2431-544f-0a17 191.12.0.2 12 WLAN-BSS1/0/4
Authorization information:
DHCP IP pool: N/A
User profile: N/A
Session group profile: N/A
ACL number: 0 (inactive, OAuth)
Inbound CAR: N/A
Outbound CAR: N/A
Username: huasan
AP name: ax3
Radio ID: 1
SSID: H3C_ise
Portal server: N/A
State: Online
VPN instance: N/A
MAC IP VLAN Interface
e8e8-b79b-438d 191.12.0.1 12 WLAN-BSS1/0/4
Authorization information:
DHCP IP pool: N/A
User profile: N/A
Session group profile: N/A
ACL number: 0 (inactive, OAuth)
Inbound CAR: N/A
已经写了url为什么还要上传本地portal页面呢?
(0)
海外portal做法独特之处,虽然重定向了 但是填写账号密码的表单还是通过ac的本地页面去提交。
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
模板名字ise