H3C Technologies H3C SecPath F1000-E User Manual
H3C Technologies Safety
i
Table of Contents
Portal Configuration····················································································································································· 1
Portal Overview·································································································································································1
Introduction to Portal ················································································································································1
Introduction to Extended Portal Functions ··············································································································1
Portal System Components ······································································································································2
Portal Authentication Modes ···································································································································3
Layer 3 Portal Authentication Process ····················································································································4
Portal Configuration Task List···········································································································································6
Configuration Prerequisites ··············································································································································7
Specifying a Portal Server for Layer 3 Portal Authentication ·······················································································7
Enabling Layer 3 Portal Authentication···························································································································8
Controlling Access of Portal Users ··································································································································9
Configuring a Portal-Free Rule ································································································································9
Configuring an Authentication Subnet···················································································································9
Setting the Maximum Number of Online Portal Users ······················································································ 10
Specifying the Authentication Domain for Portal Users····················································································· 10
Configuring RADIUS Related Attributes ······················································································································· 11
Specifying a NAS ID for an Interface ················································································································· 11
Specifying NAS-Port-Type for an Interface ········································································································· 11
Specifying a NAS ID Profile for an Interface ····································································································· 12
Specifying the Source IP Address for Outgoing Portal Packets················································································· 12
Configuring Portal Detection Functions························································································································ 13
Configuring Detection of Online Portal Users ···································································································· 13
Configuring the Portal Server Detection Function ······························································································ 13
Configuring Portal User Information Synchronization······················································································· 15
Logging Off Portal Users ··············································································································································· 16
Displaying and Maintaining Portal ······························································································································ 16
Portal Configuration Examples ····································································································································· 17
Configuring Direct Portal Authentication ············································································································ 17
Configuring Re-DHCP Portal Authentication······································································································· 22
Configuring Layer 3 Portal Authentication·········································································································· 24
Configuring Direct Portal Authentication with Extended Functions ·································································· 26
Configuring Layer 3 Portal Authentication with Extended Functions ······························································· 31
Layer 3 Portal Authentication Across VPNs········································································································ 39
Troubleshooting Portal ··················································································································································· 41
Inconsistent Keys on the Access Device and the Portal Server········································································· 41
Incorrect Server Port Number on the Access Device ························································································· 41
Document Outline
- 01-Portal Configuration
- Portal Configuration
- Portal Overview
- Portal Configuration Task List
- Configuration Prerequisites
- Specifying a Portal Server for Layer 3 Portal Authentication
- Enabling Layer 3 Portal Authentication
- Controlling Access of Portal Users
- Configuring RADIUS Related Attributes
- Specifying the Source IP Address for Outgoing Portal Packets
- Configuring Portal Detection Functions
- Logging Off Portal Users
- Displaying and Maintaining Portal
- Portal Configuration Examples
- Configuring Direct Portal Authentication
- Configuring Re-DHCP Portal Authentication
- Configuring Layer 3 Portal Authentication
- Configuring Direct Portal Authentication with Extended Functions
- Configuring Re-DHCP Portal Authentication with Extended Functions
- Configuring Layer 3 Portal Authentication with Extended Functions
- Configuring Portal Server Detection and Portal User Information Synchronization
- Layer 3 Portal Authentication Across VPNs
- Troubleshooting Portal
- Portal Configuration
- 02-ALG Configuration
- 03-RSH Configuration
- 04-SSH2.0_Configuration
- SSH2.0 Configuration
- SSH2.0 Overview
- Configuring the Device as an SSH Server
- Configuring the Device as an SSH Client
- Displaying and Maintaining SSH
- SSH Server Configuration Examples
- SSH Client Configuration Examples
- SFTP Service
- SSH2.0 Configuration
- 05-SSL Configuration
- 06-Web Filtering Configuration
- 07-Public Key Configuration
- 08-Connection Limit Configuration
- Connection Limit Configuration
- 09-Firewall Configuration
- 10-IPsec Configuration
- IPsec Configuration
- IPsec Overview
- Configuring IPsec
- Implementing ACL-Based IPsec
- IPsec Configuration Task List
- Configuring ACLs
- Configuring an IPsec Proposal
- Configuring an IPsec Policy
- Applying an IPsec Policy Group to an Interface
- Enabling the Encryption Engine
- Enabling the IPsec Module Backup Function
- Configuring the IPsec Session Idle Timeout
- Enabling ACL Checking of De-Encapsulated IPsec Packets
- Configuring the IPsec Anti-Replay Function
- Configuring Packet Information Pre-Extraction
- Implementing Tunnel Interface-Based IPsec
- Configuring IPsec for IPv6 Routing Protocols
- Displaying and Maintaining IPsec
- IPsec Configuration Examples
- IKE Configuration
- IKE Overview
- IKE Configuration Task List
- Configuring a Name for the Local Security Gateway
- Configuring an IKE Proposal
- Configuring an IKE Peer
- Setting Keepalive Timers
- Setting the NAT Keepalive Timer
- Configuring a DPD
- Disabling Next Payload Field Checking
- Displaying and Maintaining IKE
- IKE Configuration Examples
- Troubleshooting IKE
- IPsec Configuration