Configuring An Authentication Source Subnet - HPE FlexNetwork 5510 HI Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

Step
2.
Configure
IPv4-based portal-free
rule.
3.
Configure
IPv6-based portal-free
rule.
To configure a source-based portal-free rule:
Step
1.
Enter system view.
2.
Configure
source-based
portal-free rule.

Configuring an authentication source subnet

By configuring authentication source subnets, you specify that only HTTP packets from users on the
authentication source subnets can trigger portal authentication. If an unauthenticated user is not on
any authentication source subnet, the access device discards all the user's HTTP packets that do not
match any portal-free rule.
When you configure a portal authentication source subnet, follow these restrictions and guidelines:
Authentication source subnets apply only to cross-subnet portal authentication.
In direct or re-DHCP portal authentication mode, a portal user and its access interface
(portal-enabled) are on the same subnet. It is not necessary to specify the subnet as the
authentication source subnet. If the specified authentication source subnet is different from the
access subnet of the users, the users will fail the portal authentication.
In direct mode, the access device regards the authentication source subnet as any source
IP address.
Command
portal
free-rule
destination
ip
{
{ mask-length | mask } | any } [ tcp
an
tcp-port-number
udp-port-number
{ ip-address { mask-length | mask } |
any } [ tcp tcp-port-number | udp
udp-port-number ] } *
portal
free-rule
{ destination ipv6 { ipv6-address
prefix-length
|
an
tcp-port-number
udp-port-number ] | source ipv6
{ ipv6-address prefix-length | any }
tcp
[
tcp-port-number
udp-port-number ] } *
Command
system-view
portal free-rule rule-number source
a
{
interface
interface-number | mac mac-address |
vlan vlan-id } *
133
Remarks
rule-number
{
ip-address
|
udp
By
]
|
source
ip
portal-free rule exists.
rule-number
any
}
[
tcp
|
udp
By
portal-free rule exists.
udp
|
Remarks
N/A
By
portal-free rule exists.
interface-type
If you specify both a VLAN and an
interface, the interface must belong
to
portal-free rule does not take effect.
default,
no
IPv4-based
default,
no
IPv6-based
default,
no
source-based
the
VLAN.
Otherwise,
the

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the FlexNetwork 5510 HI Series and is the answer not in the manual?

Subscribe to Our Youtube Channel

Table of Contents

Save PDF