373
Layer3 source network:
IP address Prefix length
Destination authenticate subnet:
IP address Prefix length
A user can perform portal authentication through a Web page. Before passing the authentication, the
user can access only the authentication page
http://2.2.2.1:2331/portal
and all Web requests will be
redirected to the authentication page. After passing the authentication, the user can access other
network resources.
# After the user passes authentication, use the following command to display information about the
portal user.
[Router] display portal user interface gigabitethernet 1/0/2
Total portal users: 1
Username: abc
Portal server: newpt
State: Online
VPN instance: N/A
MAC IP VLAN Interface
0015-e9a6-7cfe 2.2.2.2 -- GigabitEthernet1/0/2
Authorization information:
IP pool: N/A
User profile: N/A
Session group profile: N/A
ACL: N/A
Inbound CAR: N/A
Outbound CAR: N/A
Inbound priority: N/A
Outbound priority: N/A
Example: Configuring MAC-based quick portal authentication
Network configuration
As shown in
, the host accesses the network through a router. The host is assigned a
public IP address either manually or through DHCP. A portal server acts as a portal authentication
server, a portal Web server, and a MAC binding server. A RADIUS server acts as the
authentication/accounting server.
Configure direct portal authentication, so the host can access only the portal Web server before
passing the authentication and can access other network resources after passing the authentication.