48
Step Command
Remarks
nonexistent domains.
Configuring ISP domain attributes
In an ISP domain, you can configure the following attributes:
•
Domain
status
—By placing the ISP domain in active or blocked state, you allow or deny
network service requests from users in the domain.
•
Authorization
attributes
—The device assigns the authorization attributes in the ISP domain to
the authenticated users who do not receive these attributes from the server. However, if the idle
cut attribute is configured in the ISP domain, the device assigns the attribute to the
authenticated users. If no idle cut attribute is configured in the ISP domain, the device uses the
idle cut attribute assigned by the server. The device supports the following authorization
attributes:
{
Authorization ACL
—The device restricts authenticated users to access only the network
resources permitted by the ACL. For portal users, the authorization ACL can be configured
in a preauthentication domain to authorize access to network resources before users pass
authentication.
{
Authorization CAR action
—The attribute controls the traffic flow of authenticated users.
For portal users, the authorization CAR action can be configured in a preauthentication
domain to control traffic flow before users pass authentication.
{
Idle cut
—It enables the device to check the traffic of each online user at the specified
direction in the domain at the idle timeout interval. The device logs out any users in the
domain whose total traffic in the idle timeout period at the specified direction is less than the
specified minimum traffic.
{
IPv4 address pool
—The device assigns IPv4 addresses from the pool to authenticated
users in the domain.
{
Default authorization user profile
—When a user passes authentication, it typically
obtains an authorization user profile from the local or remote server. If the user does not
obtain any user profile, the device authorizes the default user profile of the ISP domain to
the user. The device will restrict the user's behavior based on the profile. For portal users,
the authorization user profile can be configured in a preauthentication domain to restrict
user behaviors before users pass authentication.
{
IPv6 address pool
—The device assigns IPv6 addresses from the pool to authenticated
users in the domain.
{
Redirect URL
—The device redirects users in the domain to the URL after they pass
authentication.
{
Authorization user group
—Authenticated users in the domain obtain all attributes of the
user group.
{
Maximum number of multicast groups
—The attribute restricts the maximum number of
multicast groups that an authenticated user can join concurrently.
•
User online duration including idle cut period
—If a user goes offline due to connection
failure or malfunction, its online duration sent to the server includes the idle cut period or portal
user online detection period. The online duration that is generated on the server is longer than
the actual online duration of the user.
An ISP domain attribute applies to all users in the domain.
To configure ISP domain attributes:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
Summary of Contents for FlexFabric 5940 SERIES
Page 251: ...238 ...