Got it

Configuring Built-in Portal local Authentication

Latest reply: Dec 20, 2021 14:00:02 737 5 8 0 0


 Configuring Built-in Portal Authentication

[Problem Analysis]

Answer customer problem

[Root Cause] 

Answer customer problem

[Solution Description]

  • #
               sysname AC
              #                                                                                    
               http secure-server ssl-policy      default_policy                                             
               http server enable
              #
              portal local-server ip 10.23.100.3
              portal local-server https ssl-policy default_policy port 20000
              #
              vlan batch 100 to 101
              #
              authentication-profile name wlan-net
               portal-access-profile      wlan-net
               free-rule-template      default_free_rule
               authentication-scheme      wlan-net
              #
              dhcp enable
              #                                                                                    
              pki realm abc                                                                        
               pki import-certificate local      realm abc pem filename abc_local.pem
               pki import-certificate ca      realm abc pem filename abc_ca.pem
               pki import rsa-key-pair key1      pem privatekey.pem password Huawei@123
              #                                                                                    
              ssl policy default_policy type server                                                     
               pki-realm abc                                                                       
               version tls1.0 tls1.1      tls1.2                                                        
               ciphersuite rsa_aes_128_sha256      rsa_aes_256_sha256 
              #
              free-rule-template name default_free_rule
               free-rule 1 destination ip      8.8.8.8 mask 255.255.255.255
              #
              portal-access-profile name wlan-net
               portal local-server      enable
              #
              aaa
               authentication-scheme      wlan-net
               #
              interface Vlanif100
               ip address 10.23.100.1      255.255.255.0
               dhcp select interface
              #
              interface GigabitEthernet0/0/1
               port link-type trunk
               port trunk allow-pass vlan 100      to 101
              #
              interface LoopBack1
               ip address 10.23.100.3      255.255.255.0
              #
              ip route-static 0.0.0.0 0.0.0.0 10.23.101.2
              #
              capwap source interface vlanif100
              #
              wlan
               security-profile name wlan-net
               ssid-profile name      wlan-net
                ssid wlan-net
               vap-profile name      wlan-net
                forward-mode tunnel
                service-vlan vlan-id      101
                ssid-profile wlan-net
                security-profile      wlan-net
                authentication-profile      wlan-net        
               regulatory-domain-profile name      default
               ap-group name ap-group1
                radio 0
                 vap-profile wlan-net wlan      1           
                radio 1
                 vap-profile wlan-net wlan      1
               ap-id 0 type-id 35 ap-mac      60de-4476-e360 ap-sn 210235554710CB000042
                ap-name area_1
                ap-group ap-group1
              #
              return

<http://support.huawei.com/enterprise/en/doc/EDOC1000154079?section=j02g&topicName=example-for-configuring-built-in-portal-authentication-for-local-users>


  • x
  • convention:

•No ACK mechanism is provided for multicast packet transmission on air interfaces. In addition, wireless links are unstable. To ensure stable transmission of multicast packets, they are usually sent at low rates. If a large number of such multicast packets are sent from the network side, the air interfaces may be congested. You are advised to configure multicast packet suppression to reduce impact of a large number of low-rate multicast packets on the wireless network. Exercise caution when configuring the rate limit; otherwise, the multicast services may be affected
View more
  • x
  • convention:

hello author , thanks your sharing , but i think if you can explain what's mean and function of the key commands when you configuring the built-in portal , i can understand it better .
and what's different built-in and built-out ?
View more
  • x
  • convention:

Portal authentication is also called web authentication. For S series switches (except the S1700), Portal authentication can be classified into built-in Portal authentication and external Portal authentication.
View more
  • x
  • convention:

Good. Thanks your sharing
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.