SGS-6341-Series User Manual

Table Of Contents
52.3 Web Portal Authentication Typical Example
Figure 52-1: Web portal typical application scene
In the above figure, pc1 is end-user, there is http browser in it, but no 802.1x authentication
client, pc1 wants to access the network through web portal authentication.
Switch1 is the accessing device, it configures accounting server’s address and port as
RADIUS server’s IP and port, and enable the accounting function. Ethernet 1/2 connects to
pc1, the port enables web portal authentication, and configure the redirection address and port
as portal server’s IP and port, so ethernet 1/2 forbids all flows except dhcp/dns/arp packets.
Switch2 is the aggregation switch. Ethernet1/2 connects to radius server while ethernet1/3
connects to portal server. The address of radius server is 192.168.40.100 while the address of
portal server is 192.168.40.99. Ethernet1/4 connects to DHCP server while ethernet1/5
connects to DNS server. Ethernet1/6 is trunk port and connects to ethernet1/4 of switch1.
The configuration of the common web portal authentication is as follows:
Switch(config)#interface vlan 1
Switch(config-if-vlan1)#ip address 192.168.40.50 255.255.255.0
Switch(config)#webportal enable
52-141
User’s Manual of SGS-6341 series