Procedures For Portal Authentication - Huawei Quidway S3500 Series Operation Manual

Hide thumbs Also See for Quidway S3500 Series:
Table of Contents

Advertisement

Operation Manual - Security
Quidway S3500 Series Ethernet Switches
Authentication client: A web-based browser using HTTP/HTTPS (hypertext
transfer protocol/secure HTTP). Before users pass the authentication, all HTTP
requests are sent to the Portal server.
Access device: Sends by force the HTTP request from the authentication client to
the Portal server unconditionally before users pass the authentication. The access
device communicates with the authentication/accounting server to implement
authentication and accounting. The access device in this manual refers to
Quidway S3552G, S3552P, S3528G and S3528P switches.
Portal server: A web server, which users can access using the standard web
browser. The Portal server provides free portal services and the web-based
authentication interface. The access device and Portal server interact to
authenticate the client. Internet content providers (ICPs) can use the Portal server
to provide users with the information about their required sites.
Authentication/Accounting server: Implements authentication and accounting. The
access device and the authentication/accounting server communicate through the
remote authentication dial-in user service (RADIUS) protocol.
Note:
When you use Portal services, no network address translation (NAT) devices can exist
among
authentication/accounting servers.

2.1.3 Procedures for Portal Authentication

On the Quidway series switches, the procedures for Portal authentication are as
follows:
When receiving HTTP packets from a login user for the first time, the switch first
determines whether this login user is Portal user. If the user is Portal user, the
switch only allows the user to access the contents of the special sites (Portal
servers and configured free access addresses).
When receiving the HTTP packets from a Portal user for access to other sites, the
switches redirect the packets to the Portal server by TCP spoofing.
The Portal server provides web pages for the user to enter the username and
password, which are forwarded to the switch through the Portal server.
The switch sends the user name and password to the authentication server for
authentication. The user is allowed to access the Internet only after authentication.
From then on, the switch no longer redirects the HTTP packets from the user.
authentication
clients,
Huawei Technologies Proprietary
access
devices,
2-2
Chapter 2 Portal Configuration
Portal
servers
and

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents