305
Usage guidelines
If the device receives no packets from a portal user within the configured idle time, the device detects
the user's online status as follows:
•
ICMP detection
—Sends ICMP requests to the user at configurable intervals to detect the user
status.
If the device receives a reply within the maximum number of detection attempts, it considers
that the user is online and stops sending detection packets. Then the device resets the idle
timer and repeats the detection process when the timer expires.
If the device receives no reply after the maximum number of detection attempts, the device
logs out the user.
•
ARP detection
—Sends ARP requests to the user and detects the ARP entry status of the user
at configurable intervals.
If the ARP entry of the user is refreshed within the maximum number of detection attempts,
the device considers that the user is online and stops detecting the user's ARP entry. Then
the device resets the idle timer and repeats the detection process when the timer expires.
If the ARP entry of the user is not refreshed after the maximum number of detection
attempts, the device logs out the user.
Direct authentication and re-DHCP authentication support both ARP detection and ICMP detection.
Cross-subnet authentication only supports ICMP detection.
If firewall policies on the access device filter out ICMP packets, ICMP detection might fail and result
in the logout of portal users. Make sure the access device does not block ICMP packets before you
enable ICMP detection on an interface.
Examples
# Enable online detection of IPv4 portal users on GigabitEthernet 1/0/1. Configure the detection type
as
ICMP
, the maximum number of detection attempts as
5
, the detection interval as
10
seconds, and
the user idle timeout as
300
seconds.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname–GigabitEthernet1/0/1] portal user-detect type icmp retry 5 interval 10 idle 300
Related commands
display portal
portal user-dhcp-only
Use
portal user-dhcp-only
to enable portal authentication only for users with IP addresses
obtained through DHCP.
Use
undo portal user-dhcp-only
to disable portal authentication only for users with IP addresses
obtained through DHCP.
Syntax
Interface view:
portal
[
ipv6
]
user-dhcp-only
undo portal
[
ipv6
]
user-dhcp-only
Service template view:
portal user-dhcp-only
undo portal user-dhcp-only
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...