145
Do not delete a portal authentication server in use. Otherwise, users authenticated by that server
cannot log out normally.
To configure a portal authentication server:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a portal
authentication server, and
enter its view.
portal server server-name
By default, no portal
authentication servers exist.
3.
Specify the IP address of
the portal authentication
server.
•
To specify an IPv4 portal server:
ip ipv4-address
[
vpn-instance
ipv4-vpn-instance-name
] [
key
{
cipher
|
simple
}
string
]
•
To specify an IPv6 portal server:
ipv6
ipv6-address
[
vpn-instance
ipv6-vpn-instance-name
]
[
key
{
cipher
|
simple
}
string
]
Specify an IPv4 portal
authentication server or an
IPv6 authentication portal
server.
By default, no portal
authentication server is
specified.
4.
(Optional.) Set the
destination UDP port
number used by the
device to send unsolicited
portal packets to the
portal authentication
server.
port
port-number
By default, the UDP port
number is 50100.
This port number must be the
same as the listening port
number specified on the portal
authentication server.
5.
(Optional.) Specify the
portal authentication
server type.
server-type
imc
By default, the portal
authentication server type is
IMC.
Configuring a portal Web server
The device supports multiple portal Web servers.
Perform this task to configure the following parameters for a portal Web server:
•
VPN instance of the portal Web server.
•
URL of the portal Web server.
•
Parameters carried in the URL when the device redirects the URL to users.
•
Portal Web server type, which must be the same as the server type the device actually uses.
•
The captive-pass feature.
With this feature enabled, the device does not automatically push the portal authentication
page to iOS devices and some Android devices when they are connected to the network. The
device pushes the portal authentication page only when the user accesses the Internet by using
a browser.
•
URL redirection match rule.
A URL redirection match rule matches HTTP requests by user-requested URL or User-Agent
information, and redirects the matching HTTP requests to the specified redirection URL.
For a user to successfully access a redirection URL, configure a portal-free rule to allow HTTP
requests destined for the redirection URL to pass. For information about configuring portal-free
rules, see the
portal free-rule
command.
The
url
command redirects all HTTP or HTTPS requests from unauthenticated users to the portal
Web server for authentication. The
if-match
command allows for flexible URL redirection by
redirecting specific HTTP or HTTPS requests to specific redirection URLs. If both commands are
configured for a portal Web server, the
if-match
command takes priority to perform URL redirection.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...