289
Other outgoing packets on the interface are dropped.
Examples
# Enable outgoing packets filtering on VLAN-interface 20.
<Sysname> system-view
[Sysname] interface vlan-interface 20
[Sysname–Vlan-interface20] portal outbound-filter enable
portal pre-auth domain
Use
portal
[
ipv6
]
pre-auth
domain
to specify a preauthentication domain for portal users.
Use
undo portal
[
ipv6
]
pre-auth
domain
to restore the default.
Syntax
portal
[
ipv6
]
pre-auth domain domain-name
undo portal
[
ipv6
]
pre-auth domain
Default
No preauthentication domain for portal users is specified for portal users.
Views
Interface view
Predefined user roles
network-admin
mdc-admin
Parameters
ipv6
: Specifies IPv6 portal users. Do not specify this keyword for IPv4 portal users.
domain-name
: Specifies an existing ISP domain by its name, a case-insensitive string of 1 to 255
characters. The string cannot contain the following characters: slashes (/), backslashes (\), vertical
bars (|), quotation marks ("), colons (:), asterisks (*), question marks (?), left angle brackets (<), right
angle brackets (>), and at signs (@).
Usage guidelines
After you configure a preauthentication domain on a portal-enabled interface, the device authorizes
users on the interface as follows:
1.
After an unauthenticated user obtains an IP address, the user is assigned authorization
attributes (such as ACL) configured for the preauthentication domain.
An unauthenticated user who is authorized the authorization attributes in a preauthentication
domain is called a preauthentication user.
2.
After the user passes portal authentication, the user is assigned new authorization attributes
from the AAA server.
3.
After the user goes offline, the user is reassigned the authorization attributes in the
preauthentication domain.
The preauthentication domain takes effect only on portal users with IP addresses assigned by DHCP
or DHCPv6.
Make sure you specify an existing ISP domain as a preauthentication domain. If the specified ISP
domain does not exist, the device might operate incorrectly.
You must delete a preauthentication domain (by using the
undo
portal
[
ipv6
]
pre-auth
domain
command) and reconfigure it in the following situations:
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...