- Table of Contents
-
- H3C Access Points Comware 7 Configuration Examples-6W102
- 00-Preface
- 01-H3C Access Points WPA2-PSK Encryption Configuration Examples (V7)
- 02-H3C Access Points Client Rate Limiting Configuration Examples (V7)
- 03-H3C Access Points NAT Configuration Examples (V7)
- 04-H3C Access Points PPPoE Configuration Examples (V7)
- 05-H3C Access Points Mesh WDS Configuration Examples (V7)
- 06-H3C Access Points Local MAC Authentication (IPv6) Configuration Examples (V7)
- 07-H3C Access Points IPv6 Configuration Examples (V7)
- 08-H3C Access Points Layer 2 IPv6 Multicast Configuration Examples (V7)
- 09-H3C Access Points Interoperation of Fat APs and Switch for WLAN Access and Roaming Configuration Examples (V7)
- 10-H3C Access Points Remote 802.1X Authentication Configuration Examples (V7)
- 11-H3C Access Points Remote MAC Authentication Configuration Examples (V7)
- Related Documents
-
Title | Size | Download |
---|---|---|
06-H3C Access Points Local MAC Authentication (IPv6) Configuration Examples (V7) | 70.16 KB |
|
H3C Access Points |
Comware 7 Local MAC Authentication (IPv6) |
Configuration Examples |
|
Copyright © 2022 New H3C Technologies Co., Ltd. All rights reserved.
No part of this manual may be reproduced or transmitted in any form or by any means without prior written consent of New H3C Technologies Co., Ltd.
Except for the trademarks of New H3C Technologies Co., Ltd., any trademarks that may be mentioned in this document are the property of their respective owners.
The information in this document is subject to change without notice.
Introduction
The following information provides an example to configure local MAC authentication for control of access to an IPv6 wireless network.
Prerequisites
The following information applies to Comware 7-based access points. Procedures and information in the examples might be slightly different depending on the software or hardware version of the access points.
The configuration examples were created and verified in a lab environment, and all the devices were started with the factory default configuration. When you are working on a live network, make sure you understand the potential impact of every command on your network.
The following information is provided based on the assumption that you have basic knowledge of MAC authentication, WLAN authentication, and WLAN access.
Example: Configuring local MAC authentication for clients (IPv6)
Network configuration
As shown in Figure 1:
· The clients access the WLAN through the AP. The clients are in VLAN 100.
· The AP obtains an IPv6 address for its uplink interface from the DHCPv6 server on the network.
· The AP acts as a DHCPv6 server to assign IPv6 addresses to the clients.
Configure the AP to perform local MAC authentication to control the network access of clients. The MAC address of each client is used as both the username and password for MAC authentication. The MAC addresses are in hexadecimal notation without hyphens, and letters are in lower case.
Procedures
Configuring the AP
1. Configure AP interfaces:
# Create VLAN 100 and VLAN-interface 100, and assign an IPv6 address to the VLAN interface.
<AP> system-view
[AP] vlan 100
[AP-vlan100] quit
[AP] interface vlan-interface 100
[AP-Vlan-interface100] ipv6 address 3001::1 96
[AP-Vlan-interface100] quit
# Configure uplink interface VLAN-interface 10 to obtain an IPv6 address through DHCPv6.
[AP] interface vlan-interface 1
[AP-Vlan-interface1] ipv6 address dhcp-alloc
[AP-Vlan-interface1] quit
2. Configure the DHCPv6 service:
# Create a DHCPv6 address pool named 100 and add subnet 3001::2/96 to the DHCPv6 address pool for assignment of IPv6 addresses to the clients.
[AP] ipv6 dhcp pool 100
[AP-dhcp-pool-100] network 3001::2/96
[AP-dhcp-pool-100] quit
# Enable the DHCPv6 server on VLAN interface 100 and apply DHCPv6 address pool 100 to the VLAN interface.
[AP] interface vlan-interface 100
[AP-Vlan-interface100] ipv6 dhcp select server
[AP-Vlan-interface100] ipv6 dhcp server apply pool 100
[AP-Vlan-interface100] ipv6 nd autoconfig managed-address-flag
[AP-Vlan-interface100] ipv6 nd autoconfig other-flag
[AP-Vlan-interface100] undo ipv6 nd ra halt
[AP-Vlan-interface100] quit
3. Create ISP domain local-mac and configure local authentication for LAN users in the ISP domain.
[AP] domain local-mac
[AP-isp-local-mac] authentication lan-access local
[AP-isp-local-mac] quit
4. Create a network access user, set the username and password to 38295a409589 (the MAC address of the client), and specify the LAN access service for the user.
[AP] local-user 38295a409589 class network
[AP-luser-network-38295a409589] password simple 38295a409589
[AP-luser-network-38295a409589] service-type lan-access
[AP-luser-network-38295a409589] quit
5. Use the MAC address of each user as both the username and password for MAC authentication. The MAC addresses are in hexadecimal notation without hyphens, and letters are in lower case. (The configuration is the default settings. This step is optional.)
[AP] mac-authentication user-name-format mac-address without-hyphen lowercase
6. Configure a wireless service:
# Create service template 1 and enter its view.
[AP] wlan service-template 1
# Set the SSID of service template 1 to service.
[AP-wlan-st-service] ssid service
# Set the VLAN of the service template to VLAN 100.
[AP-wlan-st-service] vlan 100
[AP-wlan-st-service] client-security authentication-mode mac
# Specify ISP domain local-mac as the MAC authentication domain.
[AP-wlan-st-service] mac-authentication domain local-mac
# Enable the service template.
[AP-wlan-st-service] service-template enable
# Enable snooping ND packets and enable snooping DHCPv6 packets.
[AP-wlan-st-service] client ipv6-snooping nd-learning enable
[AP-wlan-st-service] client ipv6-snooping dhcpv6-learning enable
[AP-wlan-st-service] quit
# Enter the view of WLAN-Radio 1/0/1.
[AP] interface wlan-radio 1/0/1
# Bind service template 1 to interface WLAN-Radio 1/0/1.
[AP-WLAN-Radio1/0/1] service-template 1
[AP-WLAN-Radio1/0/1] quit
Verifying the configuration
# Access the WLAN from the client. Verify that the client can access the WLAN after passing MAC authentication. (Details not shown.)
# Verify that the client has come online in VLAN 100 on the AP.
[AP] display wlan client ipv6
MAC address AP name IPv6 address VLAN
3829-5a40-9589 fatap 3001::5 100
|
NOTE: The name of the AP to which a client associates is fixed at fatap. |
Related documentation
· Network Connectivity Configuration Guide in H3C Access Points Configuration Guides
· Network Connectivity Command Reference in H3C Access Points Command References
· User Access and Authentication Configuration Guide in H3C Access Points Configuration Guides
· User Access and Authentication Command Reference in H3C Access Points Command References
· WLAN Access Configuration Guide in H3C Access Points Configuration Guides
· WLAN Access Command Reference in H3C Access Points Command References