Specifying An Auth-Fail Vlan For Portal Authentication - HP 3600 v2 Series Security Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

NOTE:
Only Layer 2 portal authentication supports this feature.
In scenarios where there are hubs, Layer 2 switches, or APs between users and the access devices, if an
authenticated user moves from the current access port to another Layer 2-portal-authentication-enabled
port of the device without logging off, the user cannot get online when the original port is still up. The
reason is that the original port is still maintaining the authentication information of the user and the
device does not permit such a user to get online from another port by default.
To solve the problem described above, enable support for portal user moving on the device. Then, when
a user moves from a port of the device to another, the device provides services in either of the following
ways:
If the original port is still up and the two ports belong to the same VLAN, the device allows the user
to continue to access the network without re-authentication, and uses the new port information for
user accounting.
If the original port is down or the two ports belong to different VLANs, the device removes the
authentication information of the user from the original port and authenticates the user on the new
port.
Follow these steps to enable support for portal user moving:
To do...
Enter system view
Enable support for portal user
moving
NOTE:
For a user with authorization information (such as authorized VLAN) configured, after the user moves
from a port to another, the device tries to assign the authorization information to the new port. If the
operation fails, the device deletes the user's information from the original port and re-authenticates the
user on the new port.
Specifying an Auth-Fail VLAN for portal
authentication
NOTE:
Only Layer 2 portal authentication supports this feature.
This task sets the Auth-Fail VLAN to be assigned to users failing portal authentication.
Before specifying an Auth-Fail VLAN, be sure to create the VLAN.
Follow these steps to specify an Auth-Fail VLAN for portal authentication:
To do...
Enter system view
Use the command...
system-view
portal move-mode auto
Use the command...
system-view
147
Remarks
Required
Disabled by default
Remarks

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

A3100-48 v2

Table of Contents