141
To solve the problem described above, enable support for portal user moving on the device. Then, when
a user moves from a port of the device to another, the device provides services in either of the following
ways:
•
If the original port is still up and the two ports belong to the same VLAN, the device allows the user
to continue to access the network without re-authentication, and uses the new port information for
user accounting.
•
If the original port is down or the two ports belong to different VLANs, the device removes the
authentication information of the user from the original port and authenticates the user on the new
port.
To enable support for portal user moving:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable support for portal
user moving.
portal move-mode auto
Disabled by default
For a user with authorization information (such as authorized VLAN) configured, after the user moves
from a port to another, the switch tries to assign the authorization information to the new port. If the
operation fails, the switch deletes the user's information from the original port and re-authenticates the
user on the new port.
Specifying an Auth-Fail VLAN for portal
authentication
Only Layer 2 portal authentication supports this feature.
This task sets the Auth-Fail VLAN to be assigned to users failing portal authentication. You can specify
different Auth-Fail VLANs for portal authentication on different ports. A port can be specified with only
one Auth-Fail VLAN for portal authentication.
Before specifying an Auth-Fail VLAN, be sure to create the VLAN.
To specify an Auth-Fail VLAN for portal authentication:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
3.
Specify an Auth-Fail VLAN for
portal authentication on the
port.
portal auth-fail vlan
authfail-vlan-id
Not specified by default
After you specify an Auth-Fail VLAN for portal authentication on a port, you must also enable the
MAC-based VLAN function on the port to make the specified Auth-Fail VLAN take effect. For information
about MAC VLAN, see
Layer 2—LAN Switching Configuration Guide
.