119
Controlling access of portal users
Configuring a portal-free rule
A portal-free rule allows specified users to access specified external websites without portal
authentication.
For Layer 2 portal authentication, you can configure only a portal-free rule that is from any source address
to any or a specified destination address. If you configure a portal-free rule that is from any source
address to a specified destination address, users can access the specified address directly, without being
redirected to the portal authentication page for portal authentication. Usually, you can configure the IP
address of a server that provides certain services (such as software upgrading service) as the destination
IP address of a portal-free rule, so that Layer 2 portal authentication users can access the services without
portal authentication.
Follow these steps to configure a portal-free rule:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Configure a portal-free rule
portal free-rule
rule-number
{
destination
{
any
|
ip
{
ip-
address
mask
{
mask-length
|
netmask
} |
any
} } } *
Required
NOTE:
You cannot configure two or more portal-free rules with the same filtering criteria. Otherwise, the system prompts
that the rule already exists.
No matter whether portal authentication is enabled or not, you can only add or remove a portal-free rule. You
cannot modify it.
Setting the maximum number of online portal users
You can use this feature to control the total number of online portal users in the system.
Follow these steps to set the maximum number of online portal users allowed in the system:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Set the maximum number of
online portal users
portal
max-user
max-number
Required
1000 by default.
NOTE:
The maximum number of online portal users that is assigned by the switch depends on the ACL resources of the
switch.
If the maximum number of online portal users specified in the command is less than that of the current online
portal users, the command can be executed successfully and will not impact the online portal users, but the
system will not allow new portal users to log on until the number drops down below the limit.