Configuring An Auth-Fail Vlan; Configuring Web Authentication To Support Web Proxy - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

Step
3.
Enable online Web
authentication user
detection.

Configuring an Auth-Fail VLAN

Perform this task to allow authentication failed Web authentication users to access resources in the
Auth-Fail VLAN.
When you configure an Auth-Fail VLAN, follow these restrictions and guidelines:
To make the Auth-Fail VLAN take effect, you must also enable MAC-based VLAN on the
interface, and set the subnet of the Auth-Fail VLAN as the Web authentication-free subnet.
Because MAC-based VLAN takes effect only on Hybrid ports, Auth-Fail VLAN also takes effect
only on Hybrid ports.
If a VLAN is specified as the super VLAN, do not configure the VLAN as an Auth-Fail VLAN of
an interface. If a VLAN is specified as an Auth-Fail VLAN of an interface, do not configure the
VLAN as a super VLAN.
Do not delete the VLAN that has been configured as an Auth-Fail VLAN. To delete this VLAN,
first cancel the Auth-Fail VLAN configuration by using undo web-auth auth-fail vlan
command.
To configure an Auth-Fail VLAN:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure an Auth-Fail
VLAN.
Configuring Web authentication to support Web
proxy
By default, proxied HTTP requests cannot trigger Web authentication but are silently dropped. To
allow such HTTP requests to trigger Web authentication, specify the port numbers of the Web proxy
servers on the device.
If a user's browser uses the Web Proxy Auto-Discovery (WPAD) protocol to discover Web proxy
servers, you must perform the following tasks:
Add the port numbers of the Web proxy servers on the device.
Configure authentication-free rules to allow user packets destined for the IP address of the
WPAD server to pass without authentication.
For Web authentication to support Web proxy:
You must add the port numbers of the Web proxy servers on the device.
Users must make sure their browsers that use a Web proxy server do not use the proxy server
for the listening IP address of the local portal Web server. Thus, HTTP packets that the Web
authentication user sends to the local portal Web server are not sent to the Web proxy server.
Command
interface-number
web-auth offline-detect interval
interval
Command
system-view
interface interface-type
interface-number
web-auth auth-fail vlan
authfail-vlan-id
506
Remarks
By default, online Web
authentication user detection is
disabled.
Remarks
N/A
N/A
By default, no Auth-Fail VLAN
exists.

Advertisement

Table of Contents
loading

Table of Contents