Configuring Web Authentication
Before you configure Web Authentication, configure the global AAA authentication method list.
device(config)# aaa authentication dot1x default radius
This command defines the global AAA method list for network access control. Without this command, Web Authentication does not function.
Complete the following steps to configure Web Authentication on a device.
- Enter the global configuration mode.
- Set up any global configuration required for the FastIron switch, RADIUS server, Web server and other servers.
- Configure the RADIUS server and other servers if Web Authentication will use a RADIUS
server. By default, Web Authentication uses a RADIUS server to authenticate host usernames
and passwords, unless it is configured to use a local user database.
device(config)# radius-server host 10.1.1.8 auth-port 1812 acct-port 1813 default key 2 $d3NpZ0BVXFpJ web-auth
Note: Remember the RADIUS key you entered. You will need this key when you configure your RADIUS server. - Create a Web Authentication VLAN.
- (Optional) Configure Web
Authentication to use secure (HTTPS) or non-secure (HTTP) login and logout
pages. Web management access over HTTPS is enabled by default. For TPM-enabled devices, TPM certificates are available by default to establish encrypted communication between the server and client. For more information about digital certificates for web access, refer ICX Digital Certificates.
device(config)# web-management HTTP device(config)# vlan 10 device(config-vlan-10)# webauth device(config-vlan-10-webauth)# no secure-login
- Enable Web Authentication on the VLAN.
- (Optional) Web Authentication cannot be enabled if global web-management is disabled. Attempting to enable web authentication displays the following error message:
- (Optional) Re-enable web-managment before enabling the web authentication. When
global web-management is re‑enabled, HTTPS becomes enabled by default.
Note: When a device connects to RUCKUS ONE or SmartZone, the
web-management disablecommand is automatically configured and the following syslog will be disabled, but the condition is webauth should not be enabled. If webauth is enabled then theweb-management disablecommand cannot be configured.Syslog: May 18 15:24:46:I:MGMT Agent: webui is disabled on manager connection
- (Optional) When web authentication is enabled, either the HTTPS or HTTP must remain active to provide authentication. If only HTTPS is currently enabled and you attempt to disable it, the system will throw the following error message.
- (Optional) The following error meesage is displayed when global web-management is disabled while webauth is enabled:
- (Optional) When global web-management is already disabled, configuring web-auth is not permitted and results in an error.
- Configure the Web Authentication mode:
- Username and password: Blocks users from accessing the device until they enter a valid username and password on a web login page. By default "username-password" is the authentication method. For more information, refer to Using Local User Databases.
- Passcode: Blocks users from accessing the device until they enter a valid passcode on a web login page. For more information, refer to Passcodes for User Authentication.
- captive-portal: Authenticates the users in a VLAN through external Web Authentication (Captive Portal user authentication) mode. For more information, refer to Configuring Captive Portal (External Web Authentication)
- None: Blocks users from accessing the device until they press the Login button. A username and password or passcode is not required. For more information, refer to Automatic Authentication.
- Configure other Web Authentication options (refer to Web Authentication Options).