295
If the ACL in the preauthentication domain does not exist or the ACL has no rules, the device does
not control user access. Users can access any network resources without passing portal
authentication.
Follow these guidelines when you configure a preauthentication ACL rule:
•
Do not specify a source address. If you specify a source address, users cannot trigger portal
authentication.
•
Do not set the destination address to
any
. If you set the destination address to
any
, all packets
will be permitted to pass and therefore users can access any resources before portal
authentication.
Examples
# Create the preauthentication domain
abc
for GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] portal pre-auth domain abc
Related commands
display portal
portal packet log enable
Use
portal packet log enable
to enable logging for portal protocol packets.
Use undo
portal packet log enable
to disable logging for portal protocol packets.
Syntax
portal packet log enable
undo portal packet log enable
Default
Portal protocol packet logging is disabled.
Views
System view
Predefined user roles
network-admin
Usage guidelines
This feature logs information about portal protocol packets, including the username, IP address,
authentication type, packet type, SSID, and AP MAC. For portal log messages to be sent correctly,
you must also configure the information center on the device. For more information about information
center configuration, see
Network Management and Monitoring Configuration Guide
.
Examples
# Enable logging for portal protocol packets.
<Sysname> system-view
[Sysname] portal packet log enable
Related commands
portal redirect log enable
portal user log enable
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...