当前位置:网站首页>NGFW portal authentication experiment
NGFW portal authentication experiment
2022-07-24 00:07:00 【Bad bad -5】
Catalog
To configure Portal authentication
The topology

Experimental instructions
- Intranet allowed Web Gateway host uses firewall G1/0/0 Interface login management firewall
- Configure on the firewall SNAT,Client Use public address 202.1.1.1-202.1.1.5 Visit the Internet
- Intranet Client visit Telnet Server It needs to be done first Portal authentication , After certification , To allow Client Visit the Internet
Basic configuration
- Web The network management host uses a physical machine ,VMnet1 NIC IP The address is configured to 192.168.43.1/24, Gateway is 192.168.43.254

- Client Use VMware in Win10 virtual machine , The network card uses host only mode , Connect to VMnet1 NIC

- Cloud To configure

- Basic firewall configuration
- Configure interface IP Address , Gateway services that allow interfaces
- Configure the default route
int g1/0/1 ip ad 1.1.1.1 24 int g1/0/0 ip ad 192.168.43.254 24 service-manage http permit service-manage https permit service-manage ping permit
firewall zone trust add int g1/0/0 firewall zone untrust add int g1/0/1
ip rou 0.0.0.0 0 1.1.1.2 |
- Telnet Server Basic configuration
- Configure interface IP Address , Configure backhaul static routing
- To configure Telnet User password and user login permission of the service
int lo 0 ip ad 2.2.2.2 32 int g0/0/0 ip ad 1.1.1.2 24
ip rou 202.1.1.0 29 1.1.1.1
user-interface vty 0 4 set authentication password cipher [email protected] user privilege level 3
web-manager timeout 1440 // In the system view , To configure Web Login timeout |
Firewall configuration
- To configure NAT Address pool , And configuration NAT Strategy
nat address-group ISP mode pat section 0 202.1.1.1 202.1.1.5 nat-policy rule name SNAT source-zone trust destination-zone untrust source-address 192.168.43.140 mask 255.255.255.255 action source-nat address-group ISP |
- Configure security policy , release trust Area to untrust Regional Telnet service
security-policy rule name Telnet source-zone trust destination-zone untrust source-address 192.168.43.140 mask 255.255.255.255 service telnet action permit |
test
- stay Client Upper use telnet 2.2.2.2, Test whether you can login to Telnet Server
- View the session table entry of the firewall


- Client Normal access Tenlet Server
- The firewall is right Client The private network address of has been converted
To configure Portal authentication
- Web Log in to the firewall management page , Configure authentication policy

- New user group , Create a new user to belong to this user group


- Configure authentication options . The ports used can be configured 、 Whether the user's password needs to be modified after logging in 、Portal Authentication page customization and other functions

- Configuration allowed Portal Security policy of message passing through firewall
- Portal The default is TCP Of 8887 port



- Because the interface of the firewall returns to Client Of Portal Authentication page , The interface of firewall belongs to Local Regional , So the destination area is selected Local
test
- stay Client On , Use the browser to trigger HTTP Online behavior , Check to see if there is Portal Authentication page push

- Because there is no DNS Domain name resolution , So just use one IP Address , Visit , Trigger HTTP net flow
- Use http://1.1.1.1 Will push the login page of the firewall

- You can receive messages pushed by the firewall Portal Authentication page
- Use the created user , Log on to the test

- Login successful !
- Re in Client Try to login to Telnet Server

- Login successful !
- View the session table entries and online users on the firewall

- You can see Telnet Session table entry . Online user information , You can also see the login information of the user 、 Group to which you belong 、 Authentication method and other information
- Force users to offline on the firewall , Check whether you can still log in Telnet Server


- Login failed !
All of the above are original , If unknown or wrong , Please point out .
The author of this article : Bad
Link to this article :http://t.csdn.cn/cciNF
Copyright notice : All articles in this blog except special statement , All adopt CC BY-NC-SA 4.0 license agreement . Please contact the author to indicate the source and attach a link to this article !
边栏推荐
猜你喜欢

My meeting of OA project (query)

FPGA - SPI bus control flash (3) including code

Intel Intel realsense realistic depth camera self calibration operation steps explanation D400 series is applicable

太空射击第08课: 改进的碰撞

数据驱动之Excel读写

腾讯将关闭“幻核”,数字藏品领域发展是否面临阻力?

太空射击 第07课: 添加图形

JMeter中的自动转义处理

Redis cluster construction (cluster cluster mode, fragment cluster)

.NET下发同Outlook邮件格式以及表格的拼接
随机推荐
C language explanation series -- understanding of functions (2) how to use functions to exchange the values of two integer variables
多表查询之_外连接
Chapter 5: implementation of Web adapter
总结谋划明方向 凝心聚力开新局——和数软件对口援疆项目显成效
STM32 can initialization details
Create a linked list by head interpolation and output all elements
怎么开户买收益6%的理财产品呢?
What is restful verb
473-82(40、662、31、98、189)
Solution to the second game of 2022 Niuke multi school league
尝试新的方法
Longest increasing subsequence variant [deep understanding of the longest increasing sequence]
文本和图片的绘制、数据存储、localStorage、sessionStorage、cookie三者的区别
Mysql database foundation
权重分析——熵权法
Single target tracking - [correlation filtering] mosse:visual object tracking using adaptive correlation filters
How to open an account and buy financial products with 6% income?
Copy the customer service wechat, go to wechat to add, and make a call
2022年7月23日——mapper文件说明
pytorch中with torch.no_grad(): && model.eval()