152
Specifying a preauthentication domain
The preauthentication domain takes effect only on portal users with IP addresses obtained through
DHCP or DHCPv6.
After you configure a preauthentication domain on a portal-enabled interface, the device authorizes
users on the interface as follows:
1.
After an unauthenticated user obtains an IP address, the user is assigned authorization
attributes (such as ACL and user profile) configured for the preauthentication domain.
An unauthenticated user who is authorized with the authorization attributes in a
preauthentication domain is called a preauthentication user.
2.
After the user passes portal authentication, the user is assigned new authorization attributes
from the AAA server.
3.
After the user goes offline, the user is reassigned the authorization attributes in the
preauthentication domain.
The preauthentication domain does not take effect on interfaces enabled with cross-subnet portal
authentication.
Make sure you specify an existing ISP domain as a preauthentication domain. If the specified ISP
domain does not exist, the device might operate incorrectly.
You must delete a preauthentication domain (by using the
undo
portal
[
ipv6
]
pre-auth
domain
command) and reconfigure it in the following situations:
•
You create the ISP domain after specifying it as the preauthentication domain.
•
You delete the specified ISP domain and then re-create it.
To specify a preauthentication domain:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Specify a preauthentication
domain.
portal
[
ipv6
]
pre-auth
domain
domain-name
By default, no preauthentication
domain is specified on an
interface.
Specifying a preauthentication IP address pool for portal
users
You must specify a preauthentication IP address pool on a portal-enabled interface in the following
situation:
•
Portal users access the network through a subinterface of the portal-enabled interface.
•
The subinterface does not have an IP address.
•
Portal users need to obtain IP addresses through DHCP.
After a user connects to a portal-enabled interface, the user uses an IP address for portal
authentication according to the following rules:
•
If the interface is configured with a preauthentication IP address pool, the user uses the
following IP address:
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...