102
ESR Series Routers Operation Manual
esr(config-if-gi)#
service-policy dynamic upstream
esr(config-if-gi)#
exit
esr(config)#
ip route 0.0.0.0/0 203.0.113.1
Configure port in direction to the SoftWLC server:
esr (config)#
interface gigabitethernet 1/0/24
esr (config-if-gi)#
security-zone dmz
esr (config-if-gi)#
ip address 192.0.2.1/24
esr (config-if-gi)#
exit
Configure port for Wi-Fi access point connection:
esr(config)#
bridge 2
esr(config-bridge)#
security-zone trusted
esr(config-bridge)#
ip address 192.168.0.254/24
esr(config-bridge)#
ip helper-address 192.0.2.20
esr(config-bridge)#
service-subscriber-control object-group users
esr(config-bridge)#
location ssid1
esr(config-bridge)#
enable
esr(config-bridge)#
exit
esr(config)#
interface gigabitethernet 1/0/2.2000
esr(config-subif)#
bridge-group 1
esr(config-subif)#
exit
esr(config)#
interface gigabitethernet 1/0/2
esr(config-if-gi)#
service-policy dynamic downstream
esr (config-if-gi)#
exit
Customer connection must be implemented through subinterfaces to bridges. Selection of
tariff plan depends on Location parameter (see bridge 2 configuration).
The module which is control AAA operations is based on eltex-radius and available by SoftWLC IP
address. Numbers of ports for authentication and accounting in the example below are the default values
for SoftWLC.
Define parameters for interaction with the module:
esr(config)#
radius-server host 192.0.2.20
esr(config-radius-server)#
key ascii-text password
esr(config-radius-server)#
auth-port 31812
esr (config-radius-server)#
acct-port 31813
esr (config-radius-server)#
exit
Create AAA profile:
esr(config)#
aaa radius-profile RADIUS
esr(config-aaa-radius-profile)#
radius-server host 192.0.2.20
esr(config-aaa-radius-profile)#
exit
Specify parameters for access to DAS (Direct-attached storage) server:
esr(config)#
object-group network server
esr(config-object-group-network)#
ip address-range 192.0.2.20
esr(config-object-group-network)#
exit
esr(config)#
das-server CoA
esr(config-das-server)#
key ascii-text password
esr(config-das-server)#
port 3799
esr(config-das-server)#
clients object-group server
esr(config-das-server)#
exit
esr(config)#
aaa das-profile CoA
esr(config-aaa-das-profile)#
das-server CoA
esr(config-aaa-das-profile)#
exit