![H3C SR8800-F Скачать руководство пользователя страница 329](http://html2.mh-extra.com/html/h3c/sr8800-f/sr8800-f_configuration-manual_4025863329.webp)
313
•
If a portal-enabled interface is enabled with the DHCP users feature of IPoE, you must specify
the source IP address in the portal-free rule. Make sure the specified source IP address is not
the same as any of the IP addresses that the DHCP server assigns to IPoE users.
For more information about enabling the DHCP users feature, see "
."
Configuring an IP-based portal-free rule
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Configure an
IPv4-based portal-free
rule.
portal free-rule
rule-number
{
destination
ip
{
ipv4-address
{
mask-length
|
mask
} |
any
} [
tcp
tcp-port-numbe
r |
udp
udp-port-number
] |
source
ip
{
ipv4-address
{
mask-length
|
mask
} |
any
} [
tcp
tcp-port-number
|
udp
udp-port-number
] } * [
interface
interface-type interface-number
]
By default, no IPv4-based
portal-free rule exists.
3.
Configure an
IPv6-based portal-free
rule.
portal free-rule
rule-number
{
destination
ipv6
{
ipv6-address
prefix-length
|
any
} [
tcp
tcp-port-numbe
r |
udp
udp-port-number
] |
source
ipv6
{
ipv6-address prefix-length
|
any
}
[
tcp
tcp-port-number
|
udp
udp-port-number
] } * [
interface
interface-type interface-number
]
By default, no IPv6-based
portal-free rule exists.
Configuring a source-based portal-free rule
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Configure a
source-based
portal-free rule.
portal free-rule
rule-number source
{
interface interface-type
interface-number
|
mac
mac-address
|
vlan
vlan-id
} *
By default, no source-based
portal-free rule exists.
The
vlan
vlan-id
option takes effect
only on portal users that access the
network through VLAN interfaces.
Configuring a destination-based portal-free rule
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Configure a
destination-based
portal-free rule.
portal
free-rule rule-number
destination
host-name
By default, no destination-based
portal-free rule exists.
Configuring an authentication source subnet
By configuring authentication source subnets, you specify that only HTTP or HTTPS packets from
users on the authentication source subnets can trigger portal authentication. If an unauthenticated
user is not on any authentication source subnet, the access device discards all the user's HTTP or
HTTPS packets that do not match any portal-free rule.