Configuring the portal server detection function – H3C Technologies H3C WX3000E Series Wireless Switches User Manual
Page 187
173
Configuring the portal server detection function
During portal authentication, if the communication between the access device and portal server is
broken off, new portal users will not be able to log on and the online portal users will not be able to log
off normally. To address this problem, the access device needs to be able to detect the reachability
changes of the portal server quickly and take corresponding actions to deal with the changes. For
example, once detecting that the portal server is unreachable, the access device will allow portal users
to access network resources without authentication. This function is referred to as portal authentication
bypass. It allows for flexible user access control.
With the portal server detection function, the device can detect the status of a specific portal server. The
specific configurations include:
1.
Detection methods (you can choose either or both)
{
Probing HTTP connections: The access device periodically sends TCP connection requests to
the HTTP service port of the portal servers configured on its interfaces. If the TCP connection
with a portal server can be established, the access device considers that the probe succeeds
(the HTTP service of the portal server is open and the portal server is reachable). If the TCP
connection cannot be established, the access device considers that the probe fails and the
portal server is unreachable.
{
Probing portal heartbeat packets: A portal server that supports the portal heartbeat function
(currently only the portal server of IMC supports this function) sends portal heartbeat packets to
portal access devices periodically. If an access device receives a portal heartbeat packet or an
authentication packet within a probe interval, the access device considers that the probe
succeeds and the portal server is reachable; otherwise, it considers that the probe fails and the
portal server is unreachable.
2.
Probe parameters
{
Probe interval: Interval at which probe attempts are made.
{
Maximum number of probe attempts: Maximum number of consecutive probe attempts
allowed. If the number of consecutive probes reaches this value, the access device considers
that the portal server is unreachable.
3.
Actions to be taken when the server reachability status changes (you can choose one or more)
{
Sending a trap message: When the status of a portal server changes, the access device sends
a trap message to the network management server (NMS). The trap message contains the
portal server name and the current state of the portal server.
{
Sending a log: When the status of a portal server changes, the access device sends a log
message. The log message indicates the portal server name and the current state and original
state of the portal server.
{
Disabling portal authentication—enabling portal authentication bypass: When the device
detects that a portal server is unreachable, it disables portal authentication on the interfaces
that use the portal server (allows all portal users on the interfaces to access network resources).
When the device receives from the portal server portal heartbeat packets or authentication
packets (such as logon requests and logout requests), it re-enables the portal authentication
function.
You can configure any combination of the configuration items described as needed, with respect to the
following:
•
If both detection methods are specified, a portal server is regarded as unreachable as long as one
detection method fails, and an unreachable portal server is regarded as recovered only when both
detection methods succeed.
- H3C WX5500E Series Access Controllers H3C WX3500E Series Access Controllers H3C WX2500E Series Access Controllers H3C WX6000 Series Access Controllers H3C WX5000 Series Access Controllers H3C LSWM1WCM10 Access Controller Module H3C LSUM3WCMD0 Access Controller Module H3C LSUM1WCME0 Access Controller Module H3C LSWM1WCM20 Access Controller Module H3C LSQM1WCMB0 Access Controller Module H3C LSRM1WCM2A1 Access Controller Module H3C LSBM1WCM2A0 Access Controller Module H3C WA3600 Series Access Points H3C WA2600 Series WLAN Access Points H3C S10500 Series Switches H3C S5800 Series Switches H3C S5820X Series Switches H3C S12500 Series Switches H3C S9500E Series Switches H3C MSR 5600 H3C MSR 50 H3C MSR 3600 H3C MSR 30 H3C MSR 2600 H3C MSR 20-2X[40] H3C MSR 20-1X H3C MSR 930 H3C MSR 900 H3C SR8800 H3C SR6600-X H3C SR6600 H3C SecPath F5020 H3C SecPath F5040 H3C VMSG VFW1000