1-9To do… Use the command… RemarksConfigure a portal-free ruleportal free-rule rule-number{ destination { any | ip{ ip-address mask{ mask-length | netmask } |any } } | source { any |[ interface interface-typeinterface-number | ip{ ip-address mask{ mask-length | mask } | any } |mac mac-address | vlanvlan-id ] * } } *Requiredz If you specify both a VLAN and an interface in a portal-free rule, the interface must belong to theVLAN.z You cannot configure two or more portal-free rules with the same filtering conditions. Otherwise,the system prompts that the rule already exists.z No matter whether portal authentication is enabled, you can only add or remove a portal-free rule,rather than modifying it.Configuring an Authentication SubnetBy configuring authentication subnets, you can allow portal authentication to be triggered by onlypackets from users on the authentication subnets. If a user does not initiate portal authentication beforeaccessing the external network and the user’s packets are neither matching the portal-free rules norfrom authentication subnets, the user packets will be discarded by the access device.Follow these steps to configure an authentication subnet:To do… Use the command… RemarksEnter system view system-view —Enter interface view interface interface-typeinterface-number —Configure an authenticationsubnetportal auth-networknetwork-address { mask-length| mask }OptionalBy default, the authenticationsubnet is 0.0.0.0/0, whichmeans that users with anysource IP addresses are to beauthenticated.