分类: 系统运维
2008-05-20 20:47:38
CISCO 7401ASR,SSG+SESM,作WEB PORTAL,实现宽带用户web认证。
拓朴见附图:
border=0>
SESM配置成RADIUS模式,但利用第三方RADIUS,例中RADIUS利用merit 3.6B。
[page]
*********************************************************
7401中SSG配置:
version 12.3
aaa authentication ppp default group radius
aaa authorization network default group radius
aaa accounting network default start-stop group radius
aaa session-id common
ip subnet-zero
ssg enable
ssg accounting interval 300
ssg default-network 192.168.3.10 255.255.255.255
ssg service-password servicecisco
ssg radius-helper auth-port 1812 acct-port 1812
ssg radius-helper key cisco
ssg maxservice 20
ssg auto-logoff icmp interval 30 packet 3 timeout 600
ssg bind service internet GigabitEthernet0/0
ssg bind service Internet GigabitEthernet0/0
ssg open-garden opengarden-dns
ssg qos police user
ssg qos police session
!
ssg port-map
destination range 8080 to 8080 ip 192.168.3.10
source ip Loopback0
!
ssg tcp-redirect
network-list LAN
network 10.0.0.0 255.255.255.0
!
port-list web
port 80
port 8080
port 443
!
server-group cap
server 192.168.3.10 8080
!
redirect port-list web to cap
redirect unauthorized-service destination network-list LAN to cap
!
server-group redirect
server 192.168.3.10 8090
!
redirect unauthenticated-user to redirect
!
redirect unauthorized-service to cap
redirect captivate initial default group cap duration 10
ssg service-search-order local remote
!
local-profile opengarden-dns
attribute 26 9 251 "D192.168.4.1"
attribute 26 9 251 "R192.168.4.1;255.255.255.255"
attribute 26 9 251 "Idns-server"
interface Loopback0
ip address 192.168.0.1 255.255.255.255
!
interface GigabitEthernet0/0
description TO 6501
ip address 192.168.254.1 255.255.255.252
ip ospf cost 10
duplex full
speed 1000
media-type gbic
no negotiation auto
ssg direction uplink
!
interface GigabitEthernet0/1
description TO L3-switch
ip address 192.168.254.5 255.255.255.252
ip ospf cost 10
duplex full
speed 100
media-type rj45
ssg direction downlink
!
ip radius source-interface Loopback0
radius-server host 192.168.4.10 auth-port 1812 acct-port 1813
radius-server timeout 30
radius-server deadtime 1
radius-server key 7 104D000A0618
radius-server vsa send accounting
radius-server vsa send authentication
**************************************************************
SESM安装记录:
SESM安装为命令行模式:
# ./sesm_sol.bin -console
InstallShield Wizard
...................................
...................................
...................................
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
Welcome to the InstallShield Wizard for Cisco SESM 3.2(2)
The InstallShield Wizard will install Cisco SESM 3.2(2) on your computer.
To continue, choose Next.
Cisco Subscriber Edge Services Manager
Cisco Systems Inc.
Build: 3.2(2)
Java Home (bundled JRE):
Java Version: 1.4.2
Press 1 for Next, 3 to Cancel or 4 to Redisplay [1]
-------------------------------------------------------------------------------
Select one of the evaluation options or the licensed option. A license number
is required for deploying SESM in a production environment. An evaluation
version requires no license number, has no expiry date and includes the same
functionality as a licensed product.
Is this an evaluation copy for RADIUS mode (y/n) [n] y
Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]
-------------------------------------------------------------------------------
Please select the type of installation that you require.
[ ] 1 - Typical
The program will be installed with the suggested configuration.
Recommended for most users.
[X] 2 - Custom
The program will be installed with the features you choose. This is the
only option that allows installation of the Captive Portal application.
[ ] 3 - Demo
Install only those components necessary to run in Demo Mode and set the
default configuration to be Demo Mode.
To select an item enter its number, or 0 when you are finished: [0]
Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]
-------------------------------------------------------------------------------
Select the features for "Cisco SESM 3.2(2)" you would like to install:
Cisco SESM 3.2(2)
To select/deselect a feature or to view its children, type its number:
1. [x] Web Applications
2. [x] RDP
3. [x] SPE
4. [x] CDAT Services and Subscriber Management
5. [x] Application Management
6. [x] Jetty
7. [ ] Captive Portal
8. [x] Tools
9. [ ] Web Services Gateway
Other options:
0. Continue installing
Enter command [0] 2
Select the features for "Cisco SESM 3.2(2)" you would like to install:
Cisco SESM 3.2(2)
To select/deselect a feature or to view its children, type its number:
1. [x] Web Applications
2. [ ] RDP
3. [x] SPE
4. [x] CDAT Services and Subscriber Management
5. [x] Application Management
6. [x] Jetty
7. [ ] Captive Portal
8. [x] Tools
9. [ ] Web Services Gateway
Other options:
0. Continue installing
Enter command [0] 3
Select the features for "Cisco SESM 3.2(2)" you would like to install:
Cisco SESM 3.2(2)
To select/deselect a feature or to view its children, type its number:
1. [x] Web Applications
2. [ ] RDP
3. [ ] SPE
4. [x] CDAT Services and Subscriber Management
5. [x] Application Management
6. [x] Jetty
7. [ ] Captive Portal
8. [x] Tools
9. [ ] Web Services Gateway
Other options:
0. Continue installing
Enter command [0] 4
Select the features for "Cisco SESM 3.2(2)" you would like to install:
Cisco SESM 3.2(2)
To select/deselect a feature or to view its children, type its number:
1. [x] Web Applications
2. [ ] RDP
3. [ ] SPE
4. [ ] CDAT Services and Subscriber Management
5. [x] Application Management
6. [x] Jetty
7. [ ] Captive Portal
8. [x] Tools
9. [ ] Web Services Gateway
Other options:
0. Continue installing
Enter command [0] 7
Select the features for "Cisco SESM 3.2(2)" you would like to install:
Cisco SESM 3.2(2)
To select/deselect a feature or to view its children, type its number:
1. [x] Web Applications
2. [ ] RDP
3. [ ] SPE
4. [ ] CDAT Services and Subscriber Management
5. [x] Application Management
6. [x] Jetty
7. [x] Captive Portal
8. [x] Tools
9. [ ] Web Services Gateway
Other options:
0. Continue installing
Enter command [0] 8
Select the features for "Cisco SESM 3.2(2)" you would like to install:
Cisco SESM 3.2(2)
To select/deselect a feature or to view its children, type its number:
1. [x] Web Applications
2. [ ] RDP
3. [ ] SPE
4. [ ] CDAT Services and Subscriber Management
5. [x] Application Management
6. [x] Jetty
7. [x] Captive Portal
8. [ ] Tools
9. [ ] Web Services Gateway
Other options:
0. Continue installing
Enter command [0]
Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
Configuration and Deployment
This should be the IP address or hostname of the host on which the application
will run. Do not use localhost.
Web Application Host [sesm-webserver] 192.168.3.10
This should be the port number on which the web server will listen.
Web Application Port Number [8080]
Configure SESM for use with SSG. This option should be selected for RADIUS
mode.
SSG Deployment Option [True]
Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]
-------------------------------------------------------------------------------
Enter details about the SSG
The port number on which the SSG listens for Radius requests
Port Number [1812]
The shared secret needed to communicate with the SSG
Shared Secret [cisco]
Indicates the number of bits used for the port bundle/host key mechanism. A
value of zero indicates that the SSG does not use the port bundle/host key
mechanism, in which case the next panel will ask you for further details about
one SSG. Further SSGs can be configured manually following this installation by
editing .../'web app name'/config/'web app'.xml.
Port Bundle Size [0] 4
Press 1 for Next, 2 for Previous, 3 to Cancel or 4 to Redisplay [1]
-------------------------------------------------------------------------------
AAA Server Details
This should be set to the IP address or host name of the primary AAA server
Primary IP [sesm-webserver] 192.168.4.10
This should be set to the port number of the primary AAA server
Primary Port [
附:SESM安装记录是将终端捕捉下来的文本,当然去掉了部分不必的文字。
如果你有过一次安装经验,就清楚是什么的了。
这个记录主要是说明SESM安装为RADIUS模式需要安装哪些模块,安装时配置哪些内容。
当然,安装好后也可以在相应的配置文档中修改。
详细全套官方SESM3.20文档见这里: