Configuring Web Authentication

Before you configure Web Authentication, configure the global AAA authentication method list.

device(config)# aaa authentication dot1x default radius

This command defines the global AAA method list for network access control. Without this command, Web Authentication does not function.

Complete the following steps to configure Web Authentication on a device.

  1. Enter the global configuration mode.
    device# configure terminal
    
  2. Set up any global configuration required for the FastIron switch, RADIUS server, Web server and other servers.
    • Assign an IP address to a virtual interface (VE) for each VLAN on which Web Authentication will be enabled.
    device(config)# vlan 10
    device(config-vlan-10)# untagged e 1/1/1 to 1/1/10
    device(config-vlan-10)# interface ve10
    device(config-vif-10)# ip address 10.1.1.101/24
  3. Configure the RADIUS server and other servers if Web Authentication will use a RADIUS server. By default, Web Authentication uses a RADIUS server to authenticate host usernames and passwords, unless it is configured to use a local user database.
    device(config)# radius-server host 10.1.1.8 auth-port 1812 acct-port 1813 default key 2 $d3NpZ0BVXFpJ web-auth 
    
    
    Note: Remember the RADIUS key you entered. You will need this key when you configure your RADIUS server.
  4. Create a Web Authentication VLAN.
    device(config)# vlan 10
    device(config-vlan-10)# webauth
    FastIron devices support a maximum of two Web Authentication VLANs.
  5. (Optional) Configure Web Authentication to use secure (HTTPS) or non-secure (HTTP) login and logout pages.
    Web management access over HTTPS is enabled by default. For TPM-enabled devices, TPM certificates are available by default to establish encrypted communication between the server and client. For more information about digital certificates for web access, refer ICX Digital Certificates.

    To enable the non-secure web server on the FastIron switch, enter the following commands.

    device(config)# web-management HTTP
    device(config)# vlan 10
    device(config-vlan-10)# webauth
    device(config-vlan-10-webauth)# no secure-login
    

    To enable the secure web server on the FastIron switch, enter the following commands.

    device(config)# web-management HTTPS
    device(config)# vlan 10
    device(config-vlan-10)# webauth
    device(config-vlan-10-webauth)# secure-login
  6. Enable Web Authentication on the VLAN.
    device(config-vlan-10-webauth)# enable
    

    When the Web Authentication is enabled, the CLI changes to the Web Authentication configuration mode. In the example, VLAN 10 requires hosts to be authenticated using Web Authentication before they can forward traffic.

  7. (Optional) Web Authentication cannot be enabled if global web-management is disabled. Attempting to enable web authentication displays the following error message:
    device(config-vlan-10-webauth)# enable
    Error - Web management is disabled. Enable web management first to configure WebAuth.
  8. (Optional) Re-enable web-managment before enabling the web authentication. When global web-management is re‑enabled, HTTPS becomes enabled by default.

    Note: When a device connects to RUCKUS ONE or SmartZone, the web-management disable command is automatically configured and the following syslog will be disabled, but the condition is webauth should not be enabled. If webauth is enabled then the web-management disable command cannot be configured.

    Syslog: May 18 15:24:46:I:MGMT Agent: webui is disabled on manager connection
    device(config-vlan-10-webauth)# no web-management disable
    device(config-vlan-10-webauth)# enable
  9. (Optional) When web authentication is enabled, either the HTTPS or HTTP must remain active to provide authentication. If only HTTPS is currently enabled and you attempt to disable it, the system will throw the following error message.
    device(config-vlan-10-webauth)# no web-management https
    Error - Cannot disable HTTPS: both HTTP and HTTPS would be disabled but WebAuth is enabled. Disable WebAuth first.
  10. (Optional) The following error meesage is displayed when global web-management is disabled while webauth is enabled:
    device(config-vlan-10-webauth)# web-management disable
    Web disable will disable both HTTP and HTTPS. This command may take some time. Do you want to proceed?(enter 'y' or 'n'): y
    Error - Cannot disable web-management: WebAuth is enabled. Disable WebAuth first.
  11. (Optional) When global web-management is already disabled, configuring web-auth is not permitted and results in an error.
    SYSLOG: <14> Mar 02 16:39:46 Router CLI CMD: "enable" by cli user from console
    Error - Web management is disabled. Enable web management first to configure WebAuth.
  12. Configure the Web Authentication mode:
    • Username and password: Blocks users from accessing the device until they enter a valid username and password on a web login page. By default "username-password" is the authentication method. For more information, refer to Using Local User Databases.
    • Passcode: Blocks users from accessing the device until they enter a valid passcode on a web login page. For more information, refer to Passcodes for User Authentication.
    • captive-portal: Authenticates the users in a VLAN through external Web Authentication (Captive Portal user authentication) mode. For more information, refer to Configuring Captive Portal (External Web Authentication)
    • None: Blocks users from accessing the device until they press the Login button. A username and password or passcode is not required. For more information, refer to Automatic Authentication.
  13. Configure other Web Authentication options (refer to Web Authentication Options).