R0106-HP MSR Router Series Security Command Reference(V7)
176
mask-length: Specifies the subnet mask length of the IPv4 address, in the range of 0 to 32.
mask: Specifies the subnet mask in dotted decimal format.
Usage guidelines
With IPv4 authentication source subnets configured, only packets from IPv4 users on the authentication
source subnets can trigger portal authentication. If an unauthenticated IPv4 user is not on any
authentication source subnet, the access device discards all the user's packets that do not match any
portal-free rule.
If you do not specify the ipv4-network-address argument in the undo portal layer3 source command, this
command deletes all IPv4 portal authentication source subnets on the interface.
Only cross-subnet authentication supports authentication source subnets.
If you configure both an authentication source subnet and an authentication destination subnet on an
interface, only the authentication destination subnet takes effect.
Examples
# Configure an IPv4 portal authentication source subnet of 10.10.10.0/24 on interface GigabitEthernet
2/1/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 2/1/1
[Sysname–GigabitEthernet2/1/1] portal layer3 source 10.10.10.0 24
Related commands
• display portal interface
• portal free-all except destination
portal max-user
Use portal max-user to set the maximum number of total portal users allowed in the system.
Use undo portal max-user to restore the default.
Syntax
portal max-user max-number
undo portal max-user
Default
The total number of portal users allowed in the system is not limited.
Views
System view
Predefined user roles
network-admin
Parameters
max-number: Specifies the maximum number of total portal users in the range of 1 to 4294967295.
Usage guidelines
If you configure the maximum total number smaller than the number of current portal users on the device,
this command still takes effect. The online users are not affected by this command, but the system forbids
new portal users to log in.










