
Operation Manual – Web Authentication
H3C S5600 Series Ethernet Switches
Chapter 1 Web Authentication Configuration
1-3
Caution:
z
Before enabling global Web authentication, you should first set the IP address of a
Web authentication server.
z
Web authentication cannot be enabled when one of the following features is
enabled, and vice versa: 802.1x, MAC authentication, port security, port
aggregation and IRF.
z
You can make Web authentication settings on individual ports before Web
authentication is enabled globally, but they will not take effect. The Web
authentication settings on ports take effect immediately once you enable Web
authentication globally.
z
A Web authentication client and the switch with Web authentication enabled must
be able to communicate at the network layer so that the Web authentication page
can be displayed on the Web authentication client.
z
Web authentication is mutually exclusive with functions that depend on ACLs such
as IP filtering, ARP intrusion detection, QoS, and port binding.
z
After a user gets online in shared access method, if you configure an
authentication-free user whose IP address and MAC address are the same as those
of the online user, the online user will be forced to get offline.
1.3 Displaying and Maintaining Web Authentication
To do…
Use the command…
Remarks
Display global and port Web
authentication configuration
information
display web-authentication
configuration
Display information about
specified or all online
Web-authentication users.
display web-authentication
connection
{
all
|
interface
interface-type interface-number
|
user-name
user-name
}
Available in
any view
1.4 Web Authentication Configuration Example
I. Network requirements
As shown in
Figure 1-1
, a user connects to the Ethernet switch through port
GigabitEthernet 1/0/1.
z
Configure the DHCP server so that users can obtain IP addresses from it.
z
Configure Web authentication on GigabitEthernet 1/0/1 to control the access of
the user to the Internet.