333
Troubleshooting portal
Inconsistent keys on the access device and the portal server
Symptom
When a user is forced to access the portal server, the portal server displays a blank Web page,
rather than the portal authentication page or an error message.
Analysis
The keys on the access device and those on the portal server are not configured consistently,
causing CHAP message exchange failure. As a result, the portal server does not display the
authentication page.
Solution
1. Use the display portal server command to display the key for the portal server on the access
device and view the key for the access device on the portal server.
2. Use the portal server command to modify the key on the access device or modify the key for
the access device on the portal server to ensure key consistency.
Incorrect server port number on the access device
Symptom
You cannot use the portal delete-user command on the access device to log out a portal user, but
the portal user can log out by clicking the Disconnect button on the portal authentication client.
Analysis
When you execute the portal delete-user command on the access device to log out a user, the
access device sends an unsolicited logout notification message to the portal authentication server.
The destination port number in the logout notification is the listening port number of the portal
authentication server configured on the access device. If this listening port number is not the actual
listening port number configured on the server, the server cannot receive the notification. As a result,
the server does not log out the user.
When a user uses the Disconnect button on the authentication client to log out, the portal
authentication server sends an unsolicited logout request message to the access device. The
access device uses the source port in the logout request as the destination port in the logout ACK
message. As a result, the portal authentication server can definitely receive the logout ACK message
and log out the user.
Solution
1. Use the display portal server command to display the listening port of the portal
authentication server configured on the access device.
2. Use the portal server command in system view to change the listening port number to the
actual listening port of the portal authentication server.