326
Step Command
Remarks
8.
(Optional.) Specify the type
of the MAC binding server
server-type
{
cmcc
|
imc
}
By default, the type of a MAC
binding server is IMC.
9.
(Optional.) Specify the
version of the portal protocol.
version
version-number
By default, the version of the
portal protocol is 1.
10.
(Optional.) Specify the
timeout the device waits for
portal authentication to
complete after receiving the
MAC binding query
response.
authentication-timeout
minutes
By default, the portal
authentication timeout time is 3
minutes.
11.
(Optional.) Set the aging time
for MAC-trigger entries.
aging-time
seconds
By default, the aging time for
MAC-trigger entries is 300
seconds.
Specifying a MAC binding server on an interface
After a MAC binding server is specified on an interface, the device can implement MAC-based quick
portal authentication for portal users on the interface.
To specify a MAC binding server on an interface:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
The interface must be a Layer 3
interface.
3.
Specify a MAC binding
server on the interface.
portal apply mac-trigger-server
server-name
By default, no MAC binding server
is specified on an interface.
Configuring portal HTTP attack defense
About portal HTTP attack defense
Use this feature to avoid high resource usage caused by excessive HTTP requests from
unauthenticated portal users.
This feature counts the number of HTTP requests to be redirected on a per destination IP address
basis. If the number of HTTP requests for a destination IP address reaches the blocking threshold
within a statistical interval, the device starts a blocking timer for the IP address. Before the blocking
timer expires, the device discards all HTTP requests destined for the IP address.
You can set the maximum number of destination IP addresses for which the device can perform
portal HTTP attack defense.
Procedure
To configure portal HTTP attack defense:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable portal HTTP attack
defense.
portal http-defense enable
By default, portal HTTP attack
defense is disabled.