Configuring an
Authentication Subnet
Forcing a User to Log
Out
To do...
Enter system view
Configure a
portal-authentication
-free rule
n
If both a VLAN and an interface are configured in an authentication-free rule,
■
the interface must belong to the VLAN.
You cannot configure two or more portal-free rules with the same filtering
■
conditions. Otherwise, the system prompts that the rule already exists.
With an authentication subnet configured, only packets from the users whose IP
addresses are within this authentication subnet trigger a forced portal
authentication. If the IP addresses of users, for whom a forced authentication will
be performed, neither satisfy the authentication-free rule nor fall within the
authentication subnet, the packets are discarded.
Follow these steps to configure an authentication subnet:
To do...
Enter system view
Enter interface view
Configure an authentication
subnet
n
Configuration of an authentication subnet is only applicable for Layer-3 portal
authentication. The authentication subnet in the direct authentication mode
includes any source IP address, while the authentication subnet in the re-DHCP
authentication mode is the private subnet determined by the private IP address of
the interface.
By forcing a user with the specified IP address to log out, you can terminate the
authentication for the user or delete the user even if the user passes
authentication.
Follow these steps to force a user to log out:
To do...
Enter system view
Configuring an Authentication Subnet
Use the command...
system-view
portal free-rule rule-number { destination
{ any | ip { ip-address mask { mask-length |
netmask } | any } } | source { any | [ interface
interface-type interface-number | ip
{ ip-address mask { mask-length | mask } |
any } | mac mac-address | vlan vlan-id ] * } } *
Use the command...
system-view
interface interface-type
interface-number
portal auth-network
network-address
{ mask-length | mask }
Use the command...
system-view
1859
Remarks
-
Required
Support for the mac,
interface, and vlan
arguments in the
command varies with
devices.
Remarks
-
-
Optional
By default, the IP address of
the authentication subnet is
0.0.0.0/0, which indicates
that any source IP address will
be authenticated.
Remarks
-
Need help?
Do you have a question about the MSR 50 Series and is the answer not in the manual?