H3C SR8800-F Configuration Manual page 72

Comware 7 user access
Hide thumbs Also See for SR8800-F:
Table of Contents

Advertisement

Authorization VPN instance—The device allows authenticated PPP and IPoE users in the
domain to access network resources in the authorization VPN.
Maximum number of multicast groups—The attribute restricts the maximum number of
multicast groups that an authenticated IPoE, portal, or PPP user can join concurrently.
User priority—The device uses the user priority to perform QoS priority mapping on user
packets, and then assigns the user packets to a queue based on the target priority. Packets in a
high-priority queue are preferentially scheduled when congestion occurs.
When you configure authorization attributes for an ISP domain, follow these restrictions and
guidelines:
The lowest committed information rate you can set is 8 kbps.
Do not configure an authorization VPN instance in the ISP domain if IPoE, portal, and PPPoE
users in the domain access the network through the SPC, CSPC, and CMPE-1104 cards. A
violation will prevent the device from performing accounting on ITA service traffic for the users.
Portal users might have both the preauthentication IP address pool and the authorization IP
address pool. The two DHCP address pools must both have the export-route keyword
specified or not specified in the gateway-list or network command. For more information about
DHCP address pools, see "Configuring DHCP."
You can use the dhcp server apply ip-pool or portal [ ipv6 ] pre-auth ip-pool command to
specify a DHCP address pool as the preauthentication IP address pool for portal users on an
interface. For more information about the dhcp server apply ip-pool, portal [ ipv6 ] pre-auth
ip-pool, gateway-list, and network commands, see User Access Command Reference.
The user group to be configured as an authorization user group must already exist. To avoid
mistakenly logging out online users, do not delete the authorization user group if the user group
has online users.
For IPoE users that perform Web authentication, authorization attributes can be configured in a
preauthentication domain to restrict user behaviors before the users pass authentication.
To configure authorization attributes for an ISP domain:
Step
1.
Enter system view.
2.
Enter ISP domain view.
Command
system-view
domain isp-name
56
Remarks
N/A
N/A

Advertisement

Table of Contents
loading

Table of Contents