R3303-HP 6600/HSR6600 Routers Security Configuration Guide

iv
Configuring portal stateful failover ····························································································································· 138
Specifying an autoredirection URL for authenticated portal users ·········································································· 140
Configuring portal detection functions ······················································································································· 141
Configuring online Layer 3 portal user detection ···························································································· 141
Configuring the portal server detection function ······························································································ 141
Configuring portal user information synchronization ······················································································ 143
Logging off portal users ··············································································································································· 144
Displaying and maintaining portal ···························································································································· 144
Portal configuration examples ···································································································································· 145
Configuring direct portal authentication ··········································································································· 145
Configuring re-DHCP portal authentication ······································································································ 149
Configuring cross-subnet portal authentication ································································································ 151
Configuring direct portal authentication with extended functions·································································· 153
Configuring re-DHCP portal authentication with extended functions ···························································· 155
Configuring cross-subnet portal authentication with extended functions ······················································· 158
Configuring portal stateful failover(6600/HSR6600) ····················································································· 160
Configuring portal server detection and portal user information synchronization ······································· 167
Cross-subnet portal authentication across VPNs ······························································································ 172
Troubleshooting portal ················································································································································· 174
Inconsistent keys on the access device and the portal server ········································································· 174
Incorrect server port number on the access device ·························································································· 175
Configuring port security ········································································································································ 176
Overview ······································································································································································· 176
Configuring port security ···································································································································· 176
Port security modes ············································································································································· 177
Working with guest VLAN and Auth-Fail VLAN ······························································································ 179
Configuration task list ·················································································································································· 179
Enabling port security ·················································································································································· 180
Setting port security's limit on the number of MAC addresses on a port······························································· 180
Setting the port security mode ···································································································································· 181
Configuration prerequisites ································································································································ 181
Configuration procedure ···································································································································· 181
Configuring port security features ······························································································································ 182
Configuring NTK ················································································································································· 182
Configuring intrusion protection ························································································································ 182
Enabling port security traps ································································································································ 183
Configuring secure MAC addresses ·························································································································· 183
Configuration prerequisites ································································································································ 184
Configuration procedure ···································································································································· 184
Ignoring authorization information from the server ·································································································· 185
Displaying and maintaining port security ·················································································································· 186
Port security configuration examples ························································································································· 186
Configuring the autoLearn mode ······················································································································· 186
Configuring the userLoginWithOUI mode ········································································································ 188
Configuring the macAddressElseUserLoginSecure mode ················································································ 193
Troubleshooting port security ······································································································································ 196
Cannot set the port security mode ····················································································································· 196
Cannot configure secure MAC addresses ········································································································ 196
Cannot change port security mode when a user is online ·············································································· 197
Configuring a user profile ······································································································································ 198
Overview ······································································································································································· 198
User profile configuration task list ······························································································································ 198
Creating a user profile ················································································································································ 198