General Security Measures
4-159
4
Web Authentication
Web authentication allows stations to authenticate and access the network in
situations where 802.1X or Network Access authentication methods are infeasible or
impractical. The web authentication feature allows unauthenticated hosts to request
and receive a DHCP assigned IP address and perform DNS queries. All other traffic,
except for http protocol traffic, is blocked. The switch intercepts http protocol traffic
and redirects it to a switch-generated web page that facilitates user name and
password authentication via RADIUS. Once authentication is successful, the web
browser is forwarded on to the originally requested web page. Successful
authentication is valid for all hosts connected to the port.
Notes: 1.
RADIUS authentication must be activated and configured properly for the
web authentication feature to work properly. (See “Configuring Local/Remote
Logon Authentication” on page 3-59)
2.
Web authentication cannot be configured on trunk ports.
web-auth login-attempts
This command defines the limit for failed web authentication login attempts. After the
limit is reached, the switch refuses further login attempts until the quiet time expires.
Use the
no
form to restore the default.
Syntax
web-auth login-attempts
count
no web-auth login-attempts
count
- The limit of allowed failed login attempts. (Range: 1-3)
Table 4-44 Web Authentication
Command
Function
Mode
Page
web-auth login-attempts
Defines the limit for failed web authentication login
attempts
GC
web-auth quiet-period
Defines the amount of time to wait after the limit for
failed login attempts is exceeded.
GC
web-auth session-timeout
Defines the amount of time a session remains valid
GC
web-auth system-auth-control
Enables web authentication globally for the switch
GC
web-auth
Enables web authentication for an interface
IC
web-auth re-authenticate (Port) Ends all web authentication sessions on the port and
forces the users to re-authenticate
PE
web-auth re-authenticate (IP)
Ends the web authentication session associated with
the designated IP and forces the user to
re-authenticate
PE
show web-auth
Displays global web authentication parameters
PE
show web-auth interface
Displays interface-specific web authentication
parameters and statistics
PE
show web-auth summary
Displays a summary of web authentication port
parameters and statistics
PE
Содержание iES4024GP
Страница 1: ...iES4028F 4028FP 4024GP ...
Страница 2: ...iES4028F iES4028FP iES4024GP E082008 ST R03 149100041800A 149100040200A 149100041700A 149100000020A ...
Страница 4: ...iv This page is intentionally left blank ...
Страница 10: ...x This page is intentionally left blank ...
Страница 28: ...Contents xxviii This page is intentionally left blank ...
Страница 32: ...Tables xxxii This page is intentionally left blank ...
Страница 46: ...Introduction 1 10 1 This page is intentionally left blank ...
Страница 336: ...Configuring the Switch 3 280 3 This page is intentionally left blank ...
Страница 688: ...Command Line Interface 4 352 4 This page is intentionally left blank ...
Страница 702: ...Glossary Glossary 8 This page is intentionally left blank ...
Страница 710: ...Index 8 Index This page is intentionally left blank ...
Страница 711: ...This page is intentionally left blank ...
Страница 712: ...iES4028F 4028FP 4024GP ...