![H3C SR8800-F Configuration Manual Download Page 332](http://html2.mh-extra.com/html/h3c/sr8800-f/sr8800-f_configuration-manual_4025863332.webp)
316
Step Command
Remarks
3.
Enable strict checking on
portal authorization
information.
portal authorization
{
acl
|
user-profile
}
strict-checking
By default, strict checking on
portal authentication information
is disabled on an interface. In this
case, the portal users stay online
even when the authorized ACLs
or user profiles do not exist or fail
to be deployed.
Allowing only users with DHCP-assigned IP addresses to
pass portal authentication
To ensure that only users with valid IP addresses access the network, enable this feature on an
interface. This feature allows only users with DHCP-assigned IP addresses to pass portal
authentication. Users with static IP addresses cannot pass portal authentication to get online.
Restrictions and guidelines
When you configure this feature, follow these restrictions and guidelines:
•
To ensure that IPv6 users can pass portal authentication when only users with DHCP-assigned
IP addresses to pass portal authentication, disable the temporary IPv6 address feature on
terminal devices. Otherwise, IPv6 users will use temporary IPv6 addresses to access the IPv6
network and will fail portal authentication.
•
This configuration does not affect the online portal users.
Procedure
To allow only users with DHCP-assigned IP addresses to pass portal authentication:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Allow only users with
DHCP-assigned IP
addresses to pass portal
authentication.
portal
[
ipv6
]
user-dhcp-only
By default, both users with IP
addresses obtained through
DHCP and users with static IP
addresses can pass
authentication to come online.
Configuring support of Web proxy for portal authentication
About the support of Web proxy for portal authentication
To allow HTTP requests proxied by a Web proxy server to trigger portal authentication, specify the
TCP port number of the Web proxy server on the device. If a Web proxy server port is not specified
on the device, HTTP requests proxied by the Web proxy server are dropped, and portal
authentication cannot be triggered.
Restrictions and guidelines
If a user's browser uses the Web Proxy Auto-Discovery (WPAD) protocol to discover Web proxy
servers, you must perform the following tasks on the device:
•
Specify port numbers of the Web proxy servers.