280
If firewall policies on the access device filter out ICMPv6 packets, ICMPv6 detection might fail and
result in the logout of portal users. Make sure the access device does not block ICMPv6 packets
before you enable ICMPv6 detection on an interface.
Examples
# Enable online detection of IPv6 portal users on VLAN-interface 100. Configure the detection type
as
ND
, the maximum number of detection attempts as
5
, the detection interval as
10
seconds, and
the user idle timeout as
300
seconds.
<Sysname> system-view
[Sysname] interface vlan-interface 100
[Sysname–Vlan-interface100] portal ipv6 user-detect type nd retry 5 interval 10 idle 300
Related commands
display portal
portal layer3 source
Use
portal
layer3
source
to configure an IPv4 portal authentication source subnet.
Use
undo portal
layer3
source
to delete IPv4 portal authentication source subnets.
Syntax
portal layer3 source ipv4-network-address
{
mask-length
|
mask
}
undo portal layer3 source
[
ipv4-network-address
]
Default
No IPv4 portal authentication source subnet is configured. Portal users from any IPv4 subnet must
pass portal authentication.
Views
Interface view
Predefined user roles
network-admin
mdc-admin
Parameters
ipv4-network-address
: Specifies an IPv4 portal authentication source subnet address.
mask-length
: Specifies the subnet mask length of the IPv4 address, in the range of 0 to 32.
mask
: Specifies the subnet mask in dotted decimal format.
Usage guidelines
With IPv4 authentication source subnets configured, only packets from IPv4 users on the
authentication source subnets can trigger portal authentication. If an unauthenticated IPv4 user is
not on any authentication source subnet, the access device discards all the user's packets that do
not match any portal-free rule.
If you do not specify the
ipv4-network-address
argument in the
undo portal
layer3
source
command, this command deletes all IPv4 portal authentication source subnets on the interface.
Only cross-subnet authentication supports authentication source subnets.
If you configure both an authentication source subnet and an authentication destination subnet on an
interface, only the authentication destination subnet takes effect.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...