56
•
Authorization VPN instance
—The device allows authenticated PPP and IPoE users in the
domain to access network resources in the authorization VPN.
•
Maximum number of multicast groups
—The attribute restricts the maximum number of
multicast groups that an authenticated IPoE, portal, or PPP user can join concurrently.
•
User
priority
—The device uses the user priority to perform QoS priority mapping on user
packets, and then assigns the user packets to a queue based on the target priority. Packets in a
high-priority queue are preferentially scheduled when congestion occurs.
When you configure authorization attributes for an ISP domain, follow these restrictions and
guidelines:
•
The lowest committed information rate you can set is 8 kbps.
•
Do not configure an authorization VPN instance in the ISP domain if IPoE, portal, and PPPoE
users in the domain access the network through the SPC, CSPC, and CMPE-1104 cards. A
violation will prevent the device from performing accounting on ITA service traffic for the users.
•
Portal users might have both the preauthentication IP address pool and the authorization IP
address pool. The two DHCP address pools must both have the
export-route
keyword
specified or not specified in the
gateway-list
or
network
command. For more information about
DHCP address pools, see "Configuring DHCP."
You can use the
dhcp server apply ip-pool
or
portal
[
ipv6
]
pre-auth ip-pool
command to
specify a DHCP address pool as the preauthentication IP address pool for portal users on an
interface. For more information about the
dhcp server apply ip-pool
,
portal
[
ipv6
]
pre-auth
ip-pool
,
gateway-list
, and
network
commands, see
User Access Command Reference
.
•
The user group to be configured as an authorization user group must already exist. To avoid
mistakenly logging out online users, do not delete the authorization user group if the user group
has online users.
•
For IPoE users that perform Web authentication, authorization attributes can be configured in a
preauthentication domain to restrict user behaviors before the users pass authentication.
To configure authorization attributes for an ISP domain:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter ISP domain view.
domain
isp-name
N/A