Portal Overview
269
accesses. That is to say, Layer-3-protocol-enabled network devices cannot exist
between the user and the access devices.
■
The Layer 3 Portal authentication method does not check MAC addresses of
the user, so the security performance is reduced. . You are not recommended
to use the Layer 3 Portal authentication method in occasions requiring high
security performance.
Portal
Authentication-free
Users and Free IP
Addresses
Authentication-free users
Authentication-free users are users that can access Internet without Portal
authentication. In the network practice, you can configure network devices
attached to the switch or several servers as authentication-free users, so that they
can access Internet without authentication.
The information about authentication-free users includes IP addresses, MAC
addresses, and the connected switch ports and VLANs. Only the users who match
all the information can access Internet without authentication.
Free IP addresses
Free IP addresses are IP addresses that the user can access unrestrictedly. Free IP
addresses can be the IP addresses of DNS servers or the IP addresses that ISP
provides to access free websites. All users can access these free IP addresses
unrestrictedly.
ARP Packet Handshake
between the User PC
and the Switch
When authentications are performed in the Direct method or ReDHCP method,
the switch handshakes with the user PC through ARP packets after the user has
passed Portal authentication. If the switch finds the handshake abnormal, it will
cut the connection with the user actively and notice the Portal server about this
case.
c
CAUTION:
■
When the Portal user is online, DHCP Relay Security Check cannot be
configured.
■
If you want to configure DHCP Relay Security Check, you must enable it when
configuring Portal.
Portal Rate Limit
Function
The Portal rate limit function is used together with the bandwidth limit service that
the CAMS server provides. The bandwidth limit service is that you can specify the
bandwidth for each user when you are configuring the service for each user on
the CAMS server.
The principle of Portal rate limit is as follows: when the switch receives the
bandwidth limit rules for Portal users from the CAMS server, the switch will limit
the traffic on the specified upload interface, that is to say, the switch will perform
bandwidth control for the upload rates of Portal users.
n
■
An upload interface is the interface to connect the switch with the upstream
network devices.
■
The system supports only one upload interface for rate limit.
Summary of Contents for Switch 8807
Page 14: ......
Page 32: ...32 CHAPTER 2 COMMAND LINE INTERFACE...
Page 50: ...50 CHAPTER 5 MANAGEMENT INTERFACE CONFIGURATION...
Page 54: ...54 CHAPTER 6 CONFIGURATION FILE MANAGEMENT...
Page 64: ...64 CHAPTER 8 SUPER VLAN CONFIGURATION...
Page 70: ...70 CHAPTER 9 ISOLATE USER VLAN CONFIGURATION...
Page 78: ...78 CHAPTER 10 IP ADDRESS CONFIGURATION...
Page 82: ...82 CHAPTER 11 IP PERFORMANCE CONFIGURATION flag ACK window 16079...
Page 100: ...100 CHAPTER 13 ETHERNET PORT CONFIGURATION...
Page 114: ...114 CHAPTER 15 PORT ISOLATION CONFIGURATION...
Page 158: ...158 CHAPTER 18 DIGEST SNOOPING CONFIGURATION...
Page 162: ...162 CHAPTER 19 FAST TRANSITION...
Page 219: ......
Page 220: ...220 CHAPTER 24 VLAN ACL CONFIGURATION...
Page 234: ...234 CHAPTER 25 802 1X CONFIGURATION...
Page 284: ...284 CHAPTER 28 IP ROUTING PROTOCOL OVERVIEW...
Page 290: ...290 CHAPTER 29 STATIC ROUTE CONFIGURATION...
Page 338: ...338 CHAPTER 31 OSPF CONFIGURATION...
Page 392: ...392 CHAPTER 33 BGP CONFIGURATION...
Page 404: ...404 CHAPTER 34 IP ROUTING POLICY CONFIGURATION...
Page 406: ...406 CHAPTER 35 ROUTE CAPACITY CONFIGURATION...
Page 408: ...408 CHAPTER 36 RECURSIVE ROUTING CONFIGURATION...
Page 416: ...416 CHAPTER 37 IP MULTICAST OVERVIEW...
Page 430: ...430 CHAPTER 39 IGMP SNOOPING CONFIGURATION...
Page 454: ...454 CHAPTER 42 IGMP CONFIGURATION...
Page 462: ...462 CHAPTER 43 PIM DM CONFIGURATION...
Page 506: ...506 CHAPTER 46 MBGP MULTICAST EXTENSION CONFIGURATION...
Page 528: ...528 CHAPTER 48 MPLS BASIC CAPABILITY CONFIGURATION...
Page 632: ...632 CHAPTER 51 MPLS VLL...
Page 652: ...652 CHAPTER 52 VPLS CONFIGURATION...
Page 666: ...666 CHAPTER 53 VRRP CONFIGURATION...
Page 680: ...680 CHAPTER 56 ARP TABLE SIZE CONFIGURATION...
Page 718: ...718 CHAPTER 59 NETSTREAM CONFIGURATION...
Page 728: ...728 CHAPTER 61 POE CONFIGURATION...
Page 736: ...736 CHAPTER 63 UDP HELPER CONFIGURATION...
Page 746: ...746 CHAPTER 64 SNMP CONFIGURATION...
Page 792: ...792 CHAPTER 68 FILE SYSTEM MANAGEMENT...
Page 800: ...800 CHAPTER 69 DEVICE MANAGEMENT...
Page 810: ...810 CHAPTER 70 FTP TFTP CONFIGURATION...
Page 840: ...840 CHAPTER 72 SYSTEM MAINTENANCE AND DEBUGGING...
Page 844: ...844 CHAPTER 74 PACKET STATISTICS CONFIGURATION...
Page 846: ...846 CHAPTER 75 ETHERNET PORT LOOPBACK DETECTION...
Page 860: ...860 CHAPTER 76 QINQ CONFIGURATION...
Page 866: ...866 CHAPTER 77 NQA CONFIGURATION...
Page 876: ...876 CHAPTER 78 PASSWORD CONTROL CONFIGURATION...