Go to Main Contents

:: Industry developments

Wireless terminals for Portal authentication system: not just the half of wireless

With reference to Portal certification, most people think of cell phones with wireless signals ejecting pages. But many of the cable ports also need to be managed: office space, meeting room portals, lab seats, front desk...

Your position:Home > Content Centre > Industry News > > Text

With reference to Portal certification, most people think of mobile phones with wireless signals popping pages. But many units have cable ports that need to be handled: office space, meeting room portals, laboratory seats, and temporary access to the front desk. These terminals may be fixed users or anyone can plug in. The authentication system is designed to support a single set of certificates for wireless access, both wired and wireless, which are very management-saving, but it is quite different from a purely wireless setting.

The cable scenes are different.

Users in wireless settings first authenticate signals and the access point is naturally a centralized control position. In cable settings, terminals plug-in directly enter the second level of the network, where controls are usually located on the connection switchboard, more dispersed and more sophisticated. So there is a line to answer the question: whether these access switches can be combined for interception and release. If they work together, authentication can be performed at port levels; if not, then it must consider controlling the confluence layer or separate management of this area.

How does Portal trigger on the wire?

Users open browsers to any address on cable terminals, access devices stop the visit and guide it to a certified page, users complete authentication on pages, and the device receives results and lets the port or address. The principle and wireless side are consistent, with differences in the location where triggers and releases will be performed. When equipment is not capable, it can also submit requests: the device sends terminal information to the platform and returns the result after the platform has judged that the device is released accordingly. This path is low for the device but is equally limited by reverse actions.

The real problem with the cable side is a lack of uniformity in the end.

Virtually all the terminals on the wireless side are shown with browsers, not necessarily wired. Office computers are fine, but some of the equipment is only running special programs, no browsers, and others are temporarily connected debugging devices. For these terminals, the way in which they play a page is not possible per se, requiring separate arrangements: either to set them up an uncertified but restricted area or to cover them by other access methods. So the cable design has to be done before cutting out end types, see which can walk page authentication, what cannot, and does not default that all plug-in devices will be able to pop pages.

What about the conference room and the temporary seat?

The conference room portal is the most typical dilemma. It can be easily accessed by visitors; it can also be controlled and no one can access it. It is common practice to assign such a location with an independent section, certified as simple as possible, for example by checking visitors' passwords or temporary documents from front desk, while severely limiting the scope of its accessibility. Certification is valid for meetings at long intervals and expires automatically.

The place of work is fixed, but not necessarily the person.

Some units have shared their jobs or are subject to frequent adjustments. In such cases, certification cannot be made solely by the port but also by a person who has changed seats and has access rights to follow them.

Do not lose information on the location of the network.

The most useful information when wired is blocked is often not the account number, but the location: which port of the switch is inserted in it. If there are only accounts and addresses on the authentication record, no port information, a check of an unusual terminal is made manually to flip the switch's address sheet, very slowly. So the interfaces are carried together with the exchange sign, port number, and stored in the authentication records. This requires that the corresponding entry be kept on the wireless side, as well as access point identification.

The terminal limit is set by the scenario.

A person can authenticate on a number of terminals at the same time, and this rule is considered separately in a wirelessly wired environment. Employees may use computers, mobile phones, flat boards, and there is a fixed mainframe on their workplace, which if restricted too much to die, will be interrupted by normal office; if limited too much, the account numbers are not shared. It is reasonable to first count the actual terminal distribution, look at the median and long tails, then set a ceiling, and leave an temporarily relaxed channel for exceptional situations that allows them to recover automatically.

We're going to have to split the renovations.

The stock-line network is usually more difficult to remodel than wireless because it involves a large number of access layers, hybrid models, and downscaling effects directly. It is more likely that one or two floors or one department will be selected first for piloting, with all the intercepts, releases, reverse actions, log fields being verified and then gradually rolled out. A full one-time switch, with an impact immediately magnified and cumbersome when a model does not perform differently.

Receiving and inspection covers two types of terminals

The list of acceptances and inspections does not contain only mobile phones. At least it must be: cable terminals plug-in to the Internet can eject pages and complete authentication; access is strategic after certification has been passed; managers actually break down the back end of the line; when pulling off and repluging is expected; and the terminal count on wireless and wired use the same account number is in accordance with rules. These pieces cover the most easily accessible segment of the wire side, so that this uniform access becomes real when running through, not just the wireless side.

When there's a wire, you don't have to go on Portal.

If the unit’s end is managed internally, fixed and has a mature port certification system, adding a further layer of Portal may be just more complex and yielding limited benefits. Whether or not to do so will be returned to the basic questions: whether there are any temporary people here who need to be traced back, whether the existing system can handle location information alone. The answer is no, and it does not have to be uniform for the sake of uniformity.

Access Program I'll be right back. Telephone counselling