Extreme Networks 200 Series User Manual

Page 80

Advertising
background image

78

Summit 200 Series Switch Installation and User Guide

Managing the Switch

using a number for the adapter following the ipconfig command. You can find the adapter
number using the command

ipconfig/all

.

At this point, the client will have its temporary IP address. In this example, the client should have
obtained the an IP address in the range 198.162.32.20 - 198.162.32.80.

NOTE

The idea of explicit release/renew is required to bring the network login client machine in the same
subnet as the connected VLAN. In Campus Mode using web-based authentication, this requirement is
mandatory after every logout and before login again as the port moves back and forth between the
temporary and permanent VLANs. On other hand in ISP Mode, release/renew of IP address is not
required, as the network login client machine stays in the same subnet as the network login VLAN. In
ISP mode, when the network login client connects for the first time, it has to make sure that the
machine IP address is in the same subnet as the VLAN to which it is connected.

5

Bring up the browser and enter any URL as

http://www.123.net

or

http://1.2.3.4

or switch IP

address as http://<IP address>/login (where IP address could be either temporary or Permanent
VLAN Interface for Campus Mode). URL redirection redirects any URL and IP address to the
network login page. This is significant where security matters most, as no knowledge of VLAN
interfaces is required to be provided to network login users, as they can login using a URL or IP
address.

A page opens with a link for Network login.

6

Click the network login link.

A dialog box opens requesting a username and password.

7

Enter the username and password configured on the RADIUS server.

After the user has successfully logged in, the user is redirected to the URL configured on the
RADIUS server.

During the user login process, the following takes place:

Authentication is done through the RADIUS server.

After successful authentication, the connection information configured on the RADIUS server is
returned to the switch:

the permanent VLAN

the URL to be redirected to (optional)

the URL description (optional)

The port is moved to the permanent VLAN.

You can verify this using the

show vlan

command. For more information on the

show vlan

command, see “Displaying VLAN Settings” on page 104.

After a successful login is achieved, there are several ways that a port can return to a non-authenticated,
non-forwarding state:

The user successfully logs out using the logout web browser window.

The link from the user to the switch’s port is lost.

An administrator changes the port state.

Advertising