R3721-F3210-F3171-HP High-End Firewalls Access Control Command Reference-6PW101

99
timeout period, and logs out any user in the domain whose traffic during the idle timeout period is less
than the specified minimum traffic.
Use undo idle-cut enable to restore the default.
By default, the function is disabled.
You can also set the idle timeout period on the server to make the server log out users whose traffic during
the idle timeout period is less than 10240 bytes, but your setting on the server takes effect only when you
disable the idle cut function on the firewall.
Related commands: domain.
Examples
# Enable the idle cut function and set the idle timeout period to 50 minutes and the traffic threshold to
1024 bytes for ISP domain test.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] idle-cut enable 50 1024
ip pool
Syntax
ip pool pool-number low-ip-address [ high-ip-address ]
undo ip pool pool-number
View
ISP domain view
Default level
2: System level
Parameters
pool-number: Address pool number, in the range of 0 to 99.
low-ip-address and high-ip-address: Start and end IP addresses of the address pool. Up to 1024
addresses are allowed for an address pool. If you do not specify the end IP address, there is only one IP
address in the pool, namely the start IP address.
Description
Use ip pool to configure an address pool for assigning addresses to PPP users.
Use undo ip pool to delete an address pool.
By default, no IP address pool is configured for PPP users.
You can also configure an address pool for PPP users in system view. An IP address pool configured in
system view is used to assign IP addresses to PPP users who do not need to be authenticated. To specify
the address pool used for assigning an IP address to the peer device, use the remote address command
in interface view.
An IP address pool configured in ISP domain view is used to assign IP addresses to the ISP domain's PPP
users who must be authenticated. Configure IP address pools for ISP domains in scenarios where an
interface serves a great amount of PPP users but the address resources are inadequate. For example, an
Ethernet interface running PPPoE can accommodate up to 4096 users. However, only one address pool
with up to 1024 addresses can be configured on its virtual template (VT). This is obviously far from what