this is my config so far, it kinda works, most of the times, but sometimes it does not, especially if i use firefox. chrome works, but it still needs some refinament.
@chenhui , that link does not work, i do not have permission to acces it.
[V200R009C00SPC500]
#
ipv6
#
authentication-profile name default_authen_profile
authentication-profile name dot1x_authen_profile
authentication-profile name mac_authen_profile
authentication-profile name portal_authen_profile
authentication-profile name dot1xmac_authen_profile
authentication-profile name multi_authen_profile
#
dns resolve
dns server 8.8.8.8
dns server 8.8.4.4
dns proxy enable
#
dhcp enable
#
radius-server template default
#
pki realm default
#
ssl policy default_policy type server
pki-realm default
version tls1.0 tls1.1
ciphersuite rsa_aes_128_cbc_sha
#
acl name GigabitEthernet0/0/0 2997
rule 5 permit
acl name GigabitEthernet0/0/4 2999
rule 5 permit
#
ike proposal default
encryption-algorithm aes-256
dh group14
authentication-algorithm sha2-256
authentication-method pre-share
integrity-algorithm hmac-sha2-256
prf hmac-sha2-256
#
free-rule-template name default_free_rule
#
portal-access-profile name portal_access_profile
#
aaa
authentication-scheme default
authentication-scheme radius
authentication-mode radius
authorization-scheme default
accounting-scheme default
domain default
authentication-scheme default
domain default_admin
authentication-scheme default
local-user admin password irreversible-cipher $$$$$$$$$$$$$$$$$
local-user admin privilege level 15
local-user admin service-type http
#
web
set fast-configuration state disable
#
firewall zone Local
#
firewall defend syn-flood enable
firewall defend udp-flood enable
firewall defend icmp-flood enable
#
nat alg dns enable
nat alg ftp enable
nat alg rtsp enable
nat alg sip enable
nat alg pptp enable
#
interface Vlanif1
ip address 10.10.10.1 255.255.255.0
dhcp select interface
dhcp server excluded-ip-address 10.10.10.2 10.10.10.22
dhcp server dns-list 10.10.10.1
#
interface Eth-Trunk1
mode manual load-balance
load-balance src-dst-mac
#
interface Ethernet0/0/0
#
interface GigabitEthernet0/0/0
undo portswitch
description isp1-169
tcp adjust-mss 1200
nat outbound 2997
qos car inbound cir 600000 cbs 112800000 pbs 187800000 green pass yellow pass red discard
qos car outbound cir 400000 cbs 75200000 pbs 125200000 green pass yellow pass red discard
ip address dhcp-alloc
#
interface GigabitEthernet0/0/1
eth-trunk 1
#
interface GigabitEthernet0/0/2
eth-trunk 1
#
interface GigabitEthernet0/0/3
port hybrid untagged vlan 1
#
interface GigabitEthernet0/0/4
description isp2-168
tcp adjust-mss 1200
nat outbound 2999
qos car inbound cir 500000 cbs 94000000 pbs 156500000 green pass yellow pass red discard
qos car outbound cir 300000 cbs 56400000 pbs 93900000 green pass yellow pass red discard
ip address dhcp-alloc
#
interface GigabitEthernet0/0/5
description VirtualPort
#
interface Cellular0/0/0
#
interface Cellular0/0/1
#
interface NULL0
#
snmp-agent local-engineid $$$$$$$$$$$$$
#
set web login-style simple
http secure-server ssl-policy default_policy
http server enable
http secure-server enable
#
ip route-static 0.0.0.0 255.255.255.0 GigabitEthernet0/0/0 192.169.1.1 description to-isp1
ip route-static 0.0.0.0 255.255.255.0 GigabitEthernet0/0/4 192.168.1.1 preference 80 description to-isp2
#
fib regularly-refresh disable
#
user-interface con 0
user-interface vty 0
authentication-mode aaa
user privilege level 15
user-interface vty 1 4
#
wlan
wmm-profile name wmmf id 0
traffic-profile name traf id 0
security-profile name secf id 0
radio-profile name radiof id 0
wmm-profile id 0
radio-profile name arwebradio id 1
wmm-profile id 0
#
interface Wlan-Radio0/0/0
#
dot1x-access-profile name dot1x_access_profile
#
mac-access-profile name mac_access_profile
#
ops
#
autostart
#
secelog
#
return