120
Specifying an authentication domain for portal users
After you specify an authentication domain for portal users on an interface, the device uses the
authentication domain for authentication, authorization, and accounting (AAA) of all portal users on the
interface, ignoring the domain names carried in the usernames. This allows you to specify different
authentication domains for different interfaces as needed.
Follow these steps to specify an authentication domain for portal users on an interface:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter interface view
interface
interface-type
interface-number
—
Specify an authentication domain
for portal users on the interface
portal domain
domain-name
Required
By default, no authentication domain
is specified for portal users.
NOTE:
The device selects the authentication domain for a portal user on an interface in this order: the
authentication domain specified for the interface, the authentication domain carried in the username,
and the system default authentication domain. For information about the default authentication domain,
see the chapter “AAA configuration.”
Adding a web proxy server port number
NOTE:
Only Layer 2 portal authentication supports this feature.
By default, only HTTP requests from unauthenticated users to port 80 trigger portal authentication. If an
unauthenticated user uses a web proxy server and the port number of the proxy server is not 80, the
user’s HTTP requests cannot trigger portal authentication and will be dropped. To solve this problem,
configure the port numbers of the web proxy servers on the device.
If there are web servers that use non-80 port numbers on your network and users must pass portal
authentication before accessing the servers, you can also add proxy web server port numbers on the
device for the web servers so that HTTP requests to those web servers trigger portal authentication.
Follow these steps to add a web proxy server port number so that HTTP requests destined for this port
number trigger portal authentication:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Add a web proxy server port
number
portal web-proxy port
port-number
Required
By default, no web proxy server port
number is configured, and only HTTP
requests to port 80 trigger portal
authentication.