H3C S9500 Series Operation Manual page 1232

Routing switches
Hide thumbs Also See for S9500 Series:
Table of Contents

Advertisement

Operation Manual – Portal
H3C S9500 Series Routing Switches
Caution:
To use the Portal service, network address translation (NAT) devices cannot exist
among
authentication/accounting servers.
The operating mode of the port where the online user resides cannot be changed.
Do not change the port (on the switch) connecting to the Portal users freely. The
online users of the original port will be inactive for some time (defaults to 5 minutes)
before they are active in the new port.
1.1.4 Portal Authentication Procedure
Portal authentication procedure on H3C series switches is:
When the switch receives the login user's HTTP packets for the first time, it will
judge whether this user is a Portal user at first. For Portal users, the switch allows
the users to access only the contents of the specified website servers (the Portal
server and the authentication-free addresses).
For the HTTP packets of the Portal user to access other websites, the switch will
redirect them to the Portal server in the way of TCP cheat.
The Portal server provides a Web interface for the user to input username and
password. The input username and password are forwarded to the switch through
the Portal server.
The switch sends the username and password to the authentication server for
authentication. The switch allows the user to access Internet only after the user
passes the authentication, and then the switch will not redirect HTTP packets of
this user.
After the user passes the authentication, the switch checks whether there is any
security policy for the user. If not, it allows the user to access the Internet.
Otherwise, the client, the switch, and the security policy server communicate to
perform security authentication of the user, and the security policy server
authorizes the user to access resources depending on the security authentication
result. If the user passes the security authentication, the user can access the
unrestricted resources, and if the user fails the security authentication, the user
can access only the restricted resources.
authentication
clients,
access
devices,
1-3
Chapter 1 Portal Configuration
Portal
servers
and

Advertisement

Table of Contents
loading

Table of Contents