H3C S5500-EI Series Security Configuration Manual page 12

Hide thumbs Also See for S5500-EI Series:
Table of Contents

Advertisement

Layer 3 portal authentication process (available only on the S5500-EI series) ············································ 138
Portal stateful failover (available only on the S5500-EI series) ······································································ 141
Portal authentication across VPNs (available only on the S5500-EI series) ················································· 143
Portal configuration task list ········································································································································ 143
Configuration prerequisites ········································································································································· 145
Specifying the portal server ········································································································································ 145
Specifying the local portal server for Layer 2 portal authentication ······························································ 145
Configuring the local portal server ···························································································································· 146
Customizing authentication pages ···················································································································· 147
Configuring the local portal server ···················································································································· 150
Enabling portal authentication ···································································································································· 150
Enabling Layer 2 portal authentication ············································································································· 150
Enabling Layer 3 portal authentication (available only on the S5500-EI series) ········································· 151
Controlling access of portal users ······························································································································ 152
Configuring a portal-free rule····························································································································· 152
Configuring an authentication source subnet (available only on the S5500-EI series) ······························· 153
Setting the maximum number of online portal users ························································································ 154
Specifying an authentication domain for portal users ····················································································· 154
Configuring Layer 2 portal authentication to support Web proxy ································································· 155
Enabling support for portal user moving ·········································································································· 155
Specifying an Auth-Fail VLAN for portal authentication ·························································································· 156
Configuring RADIUS related attributes ······················································································································ 156
Specifying NAS-Port-Type for an interface ······································································································· 156
Specifying a NAS ID profile for an interface ··································································································· 157
Configuring portal stateful failover (available only on the S5500-EI series) ························································· 158
Specifying an auto redirection URL for authenticated portal users ········································································· 160
Configuring portal detection functions ······················································································································· 160
Configuring online Layer 2 portal user detection ···························································································· 160
Logging off portal users ··············································································································································· 163
Displaying and maintaining portal ···························································································································· 163
Portal configuration examples ···································································································································· 164
Configuring direct portal authentication ··········································································································· 164
Configuring re-DHCP portal authentication ······································································································ 169
Configuring cross-subnet portal authentication ································································································ 171
Configuring direct portal authentication with extended functions·································································· 173
Configuring re-DHCP portal authentication with extended functions ···························································· 175
Configuring cross-subnet portal authentication with extended functions ······················································· 177
Configuring portal stateful failover ···················································································································· 179
Configuring portal server detection and portal user information synchronization ······································· 187
Configuring Layer 2 portal authentication ········································································································ 192
Troubleshooting portal ················································································································································· 196
Inconsistent keys on the access device and the portal server ········································································· 196
Incorrect server port number on the access device ·························································································· 196
Configuring triple authentication ··························································································································· 198
Overview ······································································································································································· 198
Triple authentication mechanism ······················································································································· 198
Using triple authentication with other features ································································································· 199
Configuring triple authentication ································································································································ 199
Triple authentication configuration examples ··········································································································· 200
Triple authentication basic function configuration example ··········································································· 200
iv
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5500-si series

Table of Contents