Configuration Guide Configuring Web Authentication
CMCC WLAN Service Portal Specification, which gains highly industry support, enables various vendors to develop
compatible products.
Ruijie iPortal Web Authentication
In Ruijie iPortal Web Authentication, the NAS integrates Webpage interaction of the portal server and partial authentication
interaction of the RADIUS server. The NAS has a default authentication page suite. It can be customized according to the
configuration described in this manual. Then, download the configured page suite to the storage medium of the NAS for
effect.
Version Comparison
Authentication roles:
Client: Its functions are the same among the three types of Web authentication.
NAS: In Ruijie First-Generation Web Authentication, the NAS implements only URL redirection and exchanges user
login/logout notifications with the portal server. In Ruijie Second-Generation Web Authentication, the NAS is
responsible for redirecting and authenticating users as well as notifying the portal server of authentication results. In
Ruijie iPortal Web authentication, the NAS integrates multiple functions including the URL redirection, Webpage
interaction, and authentication.
Portal server: In Ruijie First-Generation Web Authentication, the portal server is responsible for interaction with clients
through Webpages, authenticating users, and notifying the NAS of authentication results. In Ruijie Second-Generation
Web Authentication, the portal server is responsible for interacting with clients through Webpages, notifying the NAS of
users' authentication information, and receiving authentication results from the NAS. In Ruijie iPortal Web
Authentication, the portal server is built into the NAS and provides simplified functions, mainly responsible for Web page
interaction with clients.
RADIUS server: Its functions are the same among the three types of Web authentication.
Authentication process:
In Ruijie Second-Generation Web Authentication, the authentication and accounting functions are transferred from the
portal server to the NAS.
Because authentication proceeds on the NAS, the second-generation NAS does not need to wait for the authentication
results notified by the portal server as the first generation.
Ruijie iPortal Web Authentication simplifies and integrates the features of the first- and second- generation portal
servers into the NAS.
Logout process:
In Ruijie First-Generation Web Authentication, a logout action may be triggered by a notification from the portal server,
or traffic detection or port status detection performed by the NAS. In Ruijie Second-Generation Web Authentication, a
logout action may be triggered by a notification from the portal server, a kickout notification from the RADIUS server, or
traffic detection or port status detection performed by the NAS. In Ruijie iPortal Web Authentication, a logout action may
be triggered by the voluntary logout of a user through clicking the Logout button on the online page, a kickout
notification from the RADIUS server, or traffic detection or port status detection performed by the NAS.