366State: OnlineVPN instance: vpn3MAC IP VLAN Interface0000-0000-0000 3.3.0.1 -- GigabitEthernet1/0/1Authorization information:DHCP IP pool: N/AUser profile: N/ASession group profile: N/AACL: N/AInbound CAR: N/AOutbound CAR: N/AInbound priority: N/AOutbound priority: N/AExample: Configuring direct portal authentication with apreauthentication policyNetwork configurationAs shown in Figure 127, the host is directly connected to the router (the access device). The host isassigned a public IP address through DHCP. A portal server acts as both a portal authenticationserver and a portal Web server. A RADIUS server acts as the authentication/accounting server.Configure direct portal authentication, so the host can access only subnet 192.168.0.0/24 beforepassing the authentication and access other network resources after passing the authentication.Figure 127 Network diagramConfiguration prerequisites• Configure IP addresses for the host, router, and servers as shown in Figure 127 and make surethey can reach each other.• Configure the RADIUS server correctly to provide authentication and accounting functions.ProcedurePerform the following tasks on the router.1. Configure a preauthentication IP address pool:# Configure DHCP address pool pre to assign IP addresses and other configurationparameters to clients on subnet 2.2.2.0/24. system-view[Router] dhcp server ip-pool pre2.2.2.2/24Gateway: 2.2.2.1/24RouterHostGE1/0/22.2.2.1/24GE1/0/1192.168.0.100/24Portal server192.168.0.111/24RADIUS server192.168.0.112/24