Web authentication requires a user who wants to access the network to enter the username and password on the authentication page of a web authentication server for authentication. Fast authentication is an authentication mode in which a user accesses the authentication page of a web authentication server for authentication, without entering the username and password.
When configuring web authentication or fast authentication, you need the following parameters:
IP address and VPN instance of the server
Port number of the server
Shared key of the server
Whether the NetEngine 8000 F reports its own IP address to the server
Portal protocol version, listening port number, and source interface sending portal packets
Pages to which users are redirected
Mandatory web authentication enables the NetEngine 8000 F to redirect the access request of a user to a specified web server when the user accesses an unauthorized address before being authenticated, facilitating user authentication.
The error code and message returned by the device to the portal server if web users switch from the pre-authentication domain to the authentication domain and the number of users using the same account has reached the upper limit is configured.
This function is mutually exclusive with the secondary address assignment enabled using the reallocate-ip-address command.
Web authentication users are considered unauthorized users before they are authenticated. Therefore, they cannot obtain IP addresses or access the web authentication server.
This means web authentication cannot be performed on web authentication users. To resolve this problem, all unauthenticated web authentication users are assigned to a default domain configured on an interface. This default domain is called the default pre-authentication domain. Unauthenticated web authentication users can obtain IP addresses from the default pre-authentication domain and access the web authentication server through the authorities granted to the default pre-authentication domain for web authentication.
The configuration is committed.