Configuration Guide
WEB Authentication Configuration
25) Scenario 2: The Portal Server detects the user
’s logout and informs the access device (through
portal protocol) and informs the user with a logout page.
26) In the above two scenarios, the Portal Server will send a stop-accounting request to the Radius
Server and notify the Radius Server that the user has logged out.
Protocol Specifications
For HTTP redirection related features, refer to HTTP 1.1 protocol (RFC1945).
For radius authentication related features, refer to RFC 2865 and RFC 2866).
The communication protocol between the device and the Portal server is private.
Comparisons among Web Authentication Mechanisms
Authentication roles:
Client: the same in function.
Access device: In Ruijie first generation web authentication mechanism, the access device is only
responsible to redirect and receive the notification from Portal Server about whether the user can
access network. In Ruijie second generation web authentication mechanism, the access device is
responsible for redirection, user authentication, and notification to portal server whether the
authentication is successful or not. In Ruijie built-in portal authentication mechanism, the access
device is responsible for redirection, forwarding of authentication page and other web-pages, and
serves as the RADIUS client in user authentication.
Portal Server: In Ruijie first generation web authentication mechanism, the Portal Server is only
responsible for the webpage interaction with client, user authentication and the notification of access
device about whether the user can access network. In Ruijie second generation web authentication
mechanism, the Portal Server is responsible for the webpage interaction with the client, notification of
access device about user's authentication information, and reception of access device's notification of
user's authentication result. In Ruijie built-in portal authentication mechanism, the portal module is
embedded in the access device and is mainly responsible for webpage interaction.
Radius Server: the same in function.
Authentication procedures:
Ruijie second generation web authentication mechanism enables the migration of the
authentication from Portal Server to the access device.
In Ruijie second generation web authentication mechanism, since the authentication takes places
on the access device, there is no need to wait for the notification from Portal Server about whether
the user can access network.
Ruijie built-in portal authentication mechanism simplifies the role of the portal server in the first
generation and the second generation authentication mechanism. This role is now supported by the
access device.
Logout procedures
In Ruijie first generation web authentication mechanism, the stop-accounting message is initiated
by the Portal Server. In Ruijie second generation web authentication mechanism, the
Summary of Contents for RG-S2900G-E Series
Page 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Page 91: ...Configuration Guide Configuring PoE Configuration ...
Page 133: ...Configuration Guide EEE Configuration ...
Page 319: ...Configuration Guide QinQ Configuration ...
Page 408: ......
Page 409: ...IP Routing Configuration 1 Static Route Configuration ...
Page 412: ......
Page 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Page 757: ......
Page 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Page 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Page 901: ...Configuration Guide ERSPAN Configuration ...
Page 902: ...Web based Configuration 1 Web based Configuration ...