Authentication Commands
4-131
4
Example
Web Authentication
Web authentication allows stations to authenticate and access the network in
situations where 802.1X or Network Access authentication are infeasible or
impractical. The web authentication feature allows unauthenticated hosts to request
and receive a DHCP assigned IP address and perform DNS queries. All other traffic,
except for http protocol traffic, is blocked. The switch intercepts http protocol traffic
and redirects it to a switch-generated webpage that facilitates username and
password authentication via RADIUS. Once authentication is successful, the web
browser is forwarded on to the originally requested web page. Successful
authentication is valid for all hosts connected to the port.
Notes: 1.
MAC authentication, web authentication, 802.1X, and port security cannot be
configured together on the same port. Only one security mechanism can be
applied.
2.
RADIUS authentication must be activated and configured properly for the
web authentication feature to work properly. (See “Configuring Local/Remote
Logon Authentication” on page 3-48)
3.
Web authentication cannot be configured on trunk ports.
Console#show network-access mac-address-table
---- ----------------- --------------- --------- -------------------------
Port MAC-Address RADIUS-Server Attribute Time
---- ----------------- --------------- --------- -------------------------
1/1 00-00-01-02-03-04 172.155.120.17 Static 00d06h32m50s
1/1 00-00-01-02-03-05 172.155.120.17 Dynamic 00d06h33m20s
1/1 00-00-01-02-03-06 172.155.120.17 Static 00d06h35m10s
1/3 00-00-01-02-03-07 172.155.120.17 Dynamic 00d06h34m20s
Console#
Table 4-37 Web Authentication
Command
Function
Mode
Page
web-auth
login-attempts
Defines the limit for failed web authentication login
attempts
GC
4-132
web-auth
login-fail-page-url
Defines the external URL to which a host is directed after
a failed web authentication attempt
GC
4-132
web-auth
login-page-url
Defines the external URL to which a host is directed to
complete web authentication
GC
4-133
web-auth
login-success-page-url
Defines the external URL to which a host is directed after
a successful web authentication
GC
4-133
web-auth
quiet-period
Defines the amount of time to wait after the limit for failed
login attempts is exceeded.
GC
4-134
web-auth
session-timeout
Defines the amount of time a session remains valid
GC
4-134
web-auth
system-auth-control
Enables web authentication globally for the switch
GC
4-135
Summary of Contents for 6128PL2
Page 2: ......
Page 8: ...viii ...
Page 26: ...Contents xviii ...
Page 30: ...Tables xxii ...
Page 52: ...Initial Configuration 2 10 2 ...
Page 308: ...Configuring the Switch 3 256 3 ...
Page 473: ...SNMP Commands 4 165 4 ...
Page 644: ...Command Line Interface 4 336 4 ...
Page 648: ...Software Specifications A 4 A ...
Page 663: ......