1-7
Task
Remarks
Basic Portal Configuration
Required
Configuring a Portal-Free Rule
Optional
Configuring an Authentication Subnet
Optional
Specifying the Source IP Address for Portal Packets to Be Sent
Optional
Logging out Users
Optional
Specifying a Mandatory Authentication Domain
Optional
Specifying a NAS ID Profile for an Interface
Optional
Setting the Maximum Number of Online Portal Users
Optional
Basic Portal Configuration
Configuration Prerequisites
The portal feature provides a solution for user authentication and security authentication. However, the
portal feature cannot implement this solution by itself. Currently, RADIUS authentication needs to be
configured on the access device to cooperate with the portal feature to complete user authentication.
The prerequisites for portal authentication are as follows:
z
The portal-enabled interfaces of the access device are configured with valid IP addresses or have
obtained valid IP addresses through DHCP.
z
The portal server and the RADIUS server have been installed and configured properly.
z
With re-DHCP authentication, the invalid IP address check function of DHCP relay is enabled on
the access device, and the DHCP server is installed and configured properly.
z
With RADIUS authentication, usernames and passwords of the users are configured on the
RADIUS server, and the RADIUS client configurations are performed on the access device. For
information about RADIUS client configuration, refer to
AAA Configuration
in the
Security Volume
.
z
To implement extended portal functions, you need install and configure the security policy server
and ensure that the ACLs configured on the access device correspond to those specified for
restricted resources and unrestricted resources on the security policy server respectively. For
information about security policy server configuration on the access device, refer to
AAA
Configuration
in the
Security Volume
.
z
For configuration about the security policy server, refer to
iMC EAD Security Policy Help
.
z
The ACL for restricted resources and that for unrestricted resources correspond to isolation ACL
and security ACL on the security policy server respectively.
z
You can modify the authorized ACL on the access device. However, the new ACL takes effect only
for portal users logging on after the modification.
Summary of Contents for S7902E
Page 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1 ...
Page 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist ...
Page 598: ...ii ...
Page 1757: ...4 9 ...
Page 1770: ...6 4 ...
Page 2017: ...2 11 Figure 2 3 SFTP client interface ...
Page 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002 ...