• 全部
  • 经验案例
  • 典型配置
  • 技术公告
  • FAQ
  • 漏洞说明
  • 全部
  • 全部
  • 大数据引擎
  • 知了引擎
产品线
搜索
取消
案例类型
发布者
是否解决
是否官方
时间
搜索引擎
匹配模式
高级搜索

华三本地portal认证苹果手机进不去,输入portal网址也进不去,安卓手机都可以进

2021-02-04提问
  • 0关注
  • 1收藏,3310浏览
粉丝:0人 关注:0人

问题描述:

<AC_WX3520H>dis current-configuration
#
version 7.1.064, Release 5435P02
#
sysname AC_WX3520H
#
wlan global-configuration
nas-id cm-0-1341956-210235A1JPB20A000057
#
telnet server enable
#
irf mac-address persistent timer
irf auto-update enable
irf auto-merge enable
irf member 1 priority 1
#
dhcp enable
#
password-recovery enable
#
vlan 1
#
vlan 200
#
vlan 301
#
vlan 500
#
vlan 504
#
vlan 553 to 555
#
irf-port 1
#
dhcp server ip-pool vlan500
gateway-list 172.16.0.254
network 172.16.0.0 mask 255.255.252.0
dns-list 114.114.114.114 8.8.8.8
expired day 0 hour 1
forbidden-ip 172.16.0.254
#
dhcp server ip-pool vlan504
gateway-list 172.16.4.254
network 172.16.0.0 mask 255.255.248.0
dns-list 114.114.114.114
expired day 0 hour 1
#
dhcp server ip-pool vlan553
gateway-list 172.16.253.254
network 172.16.253.0 mask 255.255.255.0
expired day 5
#
dhcp server ip-pool vlan554
#
wlan service-template cloud
ssid BYQDAG_Guest
vlan 504
user-isolation enable
portal enable method direct
portal domain cloud
portal apply web-server cloud
portal temp-pass period 20 enable
service-template enable
#
wlan service-template fangke
ssid BYQDAG_Guest
vlan 504
user-isolation enable
portal domain cloud
portal apply web-server fangke
portal temp-pass period 20 enable
#
wlan service-template neibu
ssid BYQDAG
vlan 500
user-isolation enable
portal enable method direct
portal domain portal
portal apply web-server newpt
service-template enable
#
interface NULL0
#
interface Vlan-interface1
ip address 192.168.0.100 255.255.255.0
#
interface Vlan-interface200
ip address dhcp-alloc
nat outbound
#
interface Vlan-interface301
#
interface Vlan-interface500
ip address 172.16.0.254 255.255.255.0
portal apply web-server newpt
#
interface Vlan-interface504
ip address 172.16.4.254 255.255.255.0
#
interface Vlan-interface553
ip address 172.16.253.254 255.255.255.0
#
interface Vlan-interface554
ip address 172.16.254.253 255.255.255.0
#
interface GigabitEthernet1/0/1
#
interface GigabitEthernet1/0/2
port access vlan 200
#
interface GigabitEthernet1/0/3
port link-type trunk
port trunk permit vlan all
#
interface GigabitEthernet1/0/4
#
interface GigabitEthernet1/0/5
#
interface GigabitEthernet1/0/6
#
interface GigabitEthernet1/0/7
#
interface GigabitEthernet1/0/8
#
interface Ten-GigabitEthernet1/0/9
#
interface Ten-GigabitEthernet1/0/10
#
scheduler logfile size 16
#
line class console
user-role network-admin
#
line class vty
user-role network-operator
#
line con 0
user-role network-admin
#
line vty 0 31
authentication-mode scheme
user-role network-operator
#
undo info-center enable
undo info-center logfile enable
#
domain cloud
authorization-attribute idle-cut 30 10240
authorization-attribute session-timeout 360
authentication portal none
authorization portal none
accounting portal none
#
domain portal
authorization-attribute idle-cut 15 1024
authentication portal local
authorization portal none
accounting portal none
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
password hash $h$6$7uuhR82xwf3LYeUo$Yr8I1T7YbnGAJKjS4MhbP+yVxnTAjOsgI1KEjsWfPMxYK34aHd5hiUCwRVdma3qxkDWqoIEsjIWygi
A+aAoQ+A==
service-type telnet http https
authorization-attribute user-role network-admin
#
local-user 123 class network
password cipher $c$3$GhBoHy1QTDlpv9UH0QPwvHJNVcwu1Gch5Q==
service-type portal
authorization-attribute user-role network-operator
#
local-user 123456 class network
password cipher $c$3$nlaUFqkuFpTSqH5O0M9F/Q3iBUHpXVCy2w==
service-type portal
authorization-attribute user-role network-operator
#
local-user test class network
password cipher $c$3$fmRcMzdZAzYs7j7pdouihXX6xJO51oKwQUDXwA==
access-limit 1024
service-type portal
authorization-attribute user-role network-operator
#
portal host-check enable
portal user log enable
portal free-rule 0 source ip any destination ip 172.16.0.254 255.255.255.255
portal free-rule 2 source ip any destination ip 172.16.253.254 255.255.255.255
portal free-rule 3 source ip any destination ip 172.16.4.254 255.255.255.255
portal free-rule 5 source ip any destination ip 8.8.8.8 255.255.255.255
portal free-rule 10 destination ip any udp 67
portal free-rule 15 destination ip any udp 68
portal free-rule 2346257224 destination open.weixin.qq.com
portal free-rule 2346257225 destination ip any tcp 5223
portal free-rule 2346257226 destination ip 114.114.114.114 255.255.255.255
portal free-rule 2346257227 destination ip any udp 53
portal free-rule 2346257228 destination ip any tcp 53
portal free-rule 2346257229 destination oasisauth.h3c.com
portal free-rule 2346257230 destination short.weixin.qq.com
portal free-rule 2346257231 destination mp.weixin.qq.com
portal free-rule 2346257232 destination long.weixin.qq.com
portal free-rule 2346257233 destination dns.weixin.qq.com
portal free-rule 2346257234 destination minorshort.weixin.qq.com
portal free-rule 2346257235 destination extshort.weixin.qq.com
portal free-rule 2346257236 destination szshort.weixin.qq.com
portal free-rule 2346257237 destination szlong.weixin.qq.com
portal free-rule 2346257238 destination szextshort.weixin.qq.com
portal free-rule 2346257239 destination isdspeed.qq.com
portal free-rule 2346257240 destination ***.***
portal free-rule 2346257241 destination long.open.weixin.qq.com
portal free-rule 2346257242 destination res.wx.qq.com
portal free-rule 2346257243 destination wifi.weixin.qq.com
portal safe-redirect enable
portal safe-redirect method get post
portal safe-redirect user-agent Android
portal safe-redirect user-agent CFNetwork
portal safe-redirect user-agent CaptiveNetworkSupport
portal safe-redirect user-agent MicroMessenger
portal safe-redirect user-agent Mozilla
portal safe-redirect user-agent WeChat
portal safe-redirect user-agent iPhone
portal safe-redirect user-agent micromessenger
#
portal web-server cloud
url http://oasisauth.h3c.com/portal/protocol
server-type oauth
if-match user-agent CaptiveNetworkSupport redirect-url http://oasisauth.h3c.com/generate_404
if-match user-agent Dalvik/2.1.0(Linux;U;Android7.0;HUAWEI redirect-url http://oasisauth.h3c.com/generate_404
if-match original-url http://10.168.168.168 temp-pass
if-match original-url http://captive.apple.com user-agent Mozilla temp-pass redirect-url http://oasisauth.h3c.com/
portal/protocol
if-match original-url ***.***/wifi/echo temp-pass redirect-url http://oasisauth.h3c.com/generate_404
if-match original-url http://www.apple.com user-agent Mozilla temp-pass redirect-url http://oasisauth.h3c.com/port
al/protocol
#
portal web-server fangke
url http://oasisauth.h3c.com/portal/protocol
server-type oauth
if-match user-agent CaptiveNetworkSupport redirect-url http://oasisauth.h3c.com/generate_404
if-match user-agent Dalvik/2.1.0(Linux;U;Android7.0;HUAWEI redirect-url http://oasisauth.h3c.com/generate_404
if-match original-url http://10.168.168.168 temp-pass
if-match original-url http://captive.apple.com user-agent Mozilla temp-pass redirect-url http://oasisauth.h3c.com/
portal/protocol
if-match original-url ***.***/wifi/echo temp-pass redirect-url http://oasisauth.h3c.com/generate_404
if-match original-url http://www.apple.com user-agent Mozilla temp-pass redirect-url http://oasisauth.h3c.com/port
al/protocol
#
portal web-server fangkee
url http://oasisauth.h3c.com/portal/protocol
server-type oauth
if-match user-agent CaptiveNetworkSupport redirect-url http://oasisauth.h3c.com/generate_404
if-match user-agent Dalvik/2.1.0(Linux;U;Android7.0;HUAWEI redirect-url http://oasisauth.h3c.com/generate_404
if-match original-url http://10.168.168.168 temp-pass
if-match original-url http://captive.apple.com user-agent Mozilla temp-pass redirect-url http://oasisauth.h3c.com/
portal/protocol
if-match original-url ***.***/wifi/echo temp-pass redirect-url http://oasisauth.h3c.com/generate_404
if-match original-url http://www.apple.com user-agent Mozilla temp-pass redirect-url http://oasisauth.h3c.com/port
al/protocol
#
portal web-server newpt
url http://172.16.0.254:8080/portal
server-type cmcc
url-parameter wlanuserip source-address
#
portal local-web-server http
tcp-port 8080
#
portal local-web-server https
#
ip http enable
ip https enable
#
portal mac-trigger-server cloud
binding-retry 2 interval 3
cloud-binding enable
#
wlan auto-ap enable
wlan auto-persistent enable
#
wlan ap-group default-group
vlan 1
ap-model WA5320-SI
radio 1
radio enable
service-template cloud vlan 504
service-template neibu vlan 500
radio 2
radio enable
service-template cloud vlan 504
service-template neibu vlan 500
gigabitethernet 1
#
wlan ap 0c3a-fa4c-a540 model WA5320-SI
serial-id 219801A1B3820BE00NZP
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-a620 model WA5320-SI
serial-id 219801A1B3820BE00NZX
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-a720 model WA5320-SI
serial-id 219801A1B3820BE00P05
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-a1e0 model WA5320-SI
serial-id 219801A1B3820BE00NYT
vlan 1
radio 1
radio enable
radio 2
radio enable
gigabitethernet 1
#
wlan ap 0c3a-fa4c-a9e0 model WA5320-SI
serial-id 219801A1B3820BE00P0W
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-aa20 model WA5320-SI
serial-id 219801A1B3820BE00P0Y
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-aa40 model WA5320-SI
serial-id 219801A1B3820BE00P0Z
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-aa60 model WA5320-SI
serial-id 219801A1B3820BE00P10
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-aa80 model WA5320-SI
serial-id 219801A1B3820BE00P11
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-aac0 model WA5320-SI
serial-id 219801A1B3820BE00P13
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-aae0 model WA5320-SI
serial-id 219801A1B3820BE00P14
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-ab00 model WA5320-SI
serial-id 219801A1B3820BE00P15
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-ab80 model WA5320-SI
serial-id 219801A1B3820BE00P19
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-ac40 model WA5320-SI
serial-id 219801A1B3820BE00P1H
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-aca0 model WA5320-SI
serial-id 219801A1B3820BE00P1L
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-aee0 model WA5320-SI
serial-id 219801A1B3820BE00P25
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-af20 model WA5320-SI
serial-id 219801A1B3820BE00P27
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-af60 model WA5320-SI
serial-id 219801A1B3820BE00P29
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b120 model WA5320-SI
serial-id 219801A1B3820BE00P2R
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b220 model WA5320-SI
serial-id 219801A1B3820BE00P30
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b440 model WA5320-SI
serial-id 219801A1B3820BE00P3K
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b460 model WA5320-SI
serial-id 219801A1B3820BE00P3L
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b500 model WA5320-SI
serial-id 219801A1B3820BE00P3R
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b540 model WA5320-SI
serial-id 219801A1B3820BE00P3T
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b560 model WA5320-SI
serial-id 219801A1B3820BE00P3V
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b580 model WA5320-SI
serial-id 219801A1B3820BE00P3W
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b600 model WA5320-SI
serial-id 219801A1B3820BE00P40
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b620 model WA5320-SI
serial-id 219801A1B3820BE00P41
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b640 model WA5320-SI
serial-id 219801A1B3820BE00P42
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b660 model WA5320-SI
serial-id 219801A1B3820BE00P43
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b680 model WA5320-SI
serial-id 219801A1B3820BE00P44
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b700 model WA5320-SI
serial-id 219801A1B3820BE00P48
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b720 model WA5320-SI
serial-id 219801A1B3820BE00P49
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b740 model WA5320-SI
serial-id 219801A1B3820BE00P4B
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b760 model WA5320-SI
serial-id 219801A1B3820BE00P4C
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b780 model WA5320-SI
serial-id 219801A1B3820BE00P4D
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b820 model WA5320-SI
serial-id 219801A1B3820BE00P4K
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b840 model WA5320-SI
serial-id 219801A1B3820BE00P4L
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b4e0 model WA5320-SI
serial-id 219801A1B3820BE00P3Q
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b5e0 model WA5320-SI
serial-id 219801A1B3820BE00P3Z
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b6e0 model WA5320-SI
serial-id 219801A1B3820BE00P47
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b7c0 model WA5320-SI
serial-id 219801A1B3820BE00P4G
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4c-b7e0 model WA5320-SI
serial-id 219801A1B3820BE00P4H
vlan 1
radio 1
radio 2
gigabitethernet 1
#
wlan ap 0c3a-fa4f-8100 model WA5320-SI
serial-id 219801A1B3820BE00W2J
vlan 1
radio 1
radio 2
gigabitethernet 1
#
cloud-management server domain oasis.h3c.com
#
return

组网及组网描述:


最佳答案

刚哥 九段
粉丝:21人 关注:13人

苹果获取地址后,下载个cloud net APP看一下到服务器的地址能不能ping通,若能通看一下是不是DNS解析有问题,若不能通,看看是不是有什么策略限制

2 个回答
粉丝:124人 关注:6人

您好,请知:

检查下苹果手机的是否能正常获取到IP地址、子网掩码、默认网关、DNS。

其次使用不加密看下是否能打开认证页面。

另外调整下DHCP内的DNS分配,修改为所接入的运营商的DNS看下。


苹果能获取到ip地址,但是进不去portal网址

zhiliao_tJceL3 发表时间:2021-02-04
粉丝:8人 关注:1人

试着在无线业务vlan里  把tcp mss值改小  看看有改善不

编辑答案

你正在编辑答案

如果你要对问题或其他回答进行点评或询问,请使用评论功能。

分享扩散:

提出建议

    +

亲~登录后才可以操作哦!

确定

亲~检测到您登陆的账号未在http://hclhub.h3c.com进行注册

注册后可访问此模块

跳转hclhub

你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作

举报

×

侵犯我的权益 >
对根叔社区有害的内容 >
辱骂、歧视、挑衅等(不友善)

侵犯我的权益

×

泄露了我的隐私 >
侵犯了我企业的权益 >
抄袭了我的内容 >
诽谤我 >
辱骂、歧视、挑衅等(不友善)
骚扰我

泄露了我的隐私

×

您好,当您发现根叔知了上有泄漏您隐私的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您认为哪些内容泄露了您的隐私?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)

侵犯了我企业的权益

×

您好,当您发现根叔知了上有关于您企业的造谣与诽谤、商业侵权等内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到 pub.zhiliao@h3c.com 邮箱,我们会在审核后尽快给您答复。
  • 1. 您举报的内容是什么?(请在邮件中列出您举报的内容和链接地址)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
  • 3. 是哪家企业?(营业执照,单位登记证明等证件)
  • 4. 您与该企业的关系是?(您是企业法人或被授权人,需提供企业委托授权书)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

抄袭了我的内容

×

原文链接或出处

诽谤我

×

您好,当您发现根叔知了上有诽谤您的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您举报的内容以及侵犯了您什么权益?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

对根叔社区有害的内容

×

垃圾广告信息
色情、暴力、血腥等违反法律法规的内容
政治敏感
不规范转载 >
辱骂、歧视、挑衅等(不友善)
骚扰我
诱导投票

不规范转载

×

举报说明