Got it

Portal authentication for only some end users

Created: Apr 29, 2020 12:09:53Latest reply: Apr 29, 2020 12:17:39 201 2 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hello all,

We configured DHCP on S6730S to assign IP to users. After obtaining IP addresses, users need to pass portal authentication to access the network. The portal authentication configuration is as follows: 


#

radius-server template rd1

 radius-server shared-key cipher %^%#Q75cNQ6IF(e#L4WMxP~%^7'u17,]D87GO{"[o]`D%^%#

 radius-server authentication 192.168.2.30 1812 weight 80

#

web-auth-server abc                                                             

 server-ip 192.168.2.20                                                         

 port 50200                                                                     

 shared-key cipher %^%#t:hJ@gD7<+G&,"Y}Y[VP4\foQ&og/Gg(,J4#\!gD%^%#                         

 url http://192.168.2.20:8080/webagent      

#

aaa

 authentication-scheme abc

  authentication-mode radius

 domain isp1

  authentication-scheme abc

  radius-server rd1

#

interface Vlanif10                                                              

 web-auth-server abc direct  

#


Now we hope that some specific users can access the Internet without authentication. How do I configure this? Thank you!

Featured Answers
Popeye_Wang
Admin Created Apr 29, 2020 12:17:39

Hello,

You need to bind the IP address in the address pool to the MAC address to ensure that the terminals that do not need to be authenticated obtain the same IP address each time they access the network. Then, run the free rule command to configure the ACL to permit these terminals based on the source IP address. In this way, these terminals can access the network without authentication.

1. Assign a fixed IP address to the terminal. 

<HUAWEI> system-view

[HUAWEI] interface vlanif 100

[HUAWEI-Vlanif100] dhcp server static-bind ip-address 10.1.1.100 mac-address x-x-e4c0

2. Configure a free rule. 

NAC unified mode: 

[HUAWEI] authentication free-rule 1 destination any source ip 10.1.1.100 mask 32

Traditional mode:

[HUAWEI] portal free-rule 1 destination any source ip 10.1.1.100 mask 32


I hope this helps.

View more
  • x
  • convention:

EsraBilgin
EsraBilgin Created Apr 29, 2020 13:00:30 (0) (0)
It is useful information  
All Answers

Hello,

You need to bind the IP address in the address pool to the MAC address to ensure that the terminals that do not need to be authenticated obtain the same IP address each time they access the network. Then, run the free rule command to configure the ACL to permit these terminals based on the source IP address. In this way, these terminals can access the network without authentication.

1. Assign a fixed IP address to the terminal. 

<HUAWEI> system-view

[HUAWEI] interface vlanif 100

[HUAWEI-Vlanif100] dhcp server static-bind ip-address 10.1.1.100 mac-address x-x-e4c0

2. Configure a free rule. 

NAC unified mode: 

[HUAWEI] authentication free-rule 1 destination any source ip 10.1.1.100 mask 32

Traditional mode:

[HUAWEI] portal free-rule 1 destination any source ip 10.1.1.100 mask 32


I hope this helps.

View more
  • x
  • convention:

EsraBilgin
EsraBilgin Created Apr 29, 2020 13:00:30 (0) (0)
It is useful information  

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.