Web Authentication Configuration Tasks
Complete the following steps to configure Web Authentication on a device.
- Set up any global configuration required for the FastIron switch, RADIUS server, Web server and other servers.
- Configure the RADIUS server and other servers if Web Authentication will use a RADIUS
server. By default, Web Authentication uses a RADIUS server to authenticate host usernames
and passwords, unless it is configured to use a local user database.
device(config)# radius-server host 10.1.1.8 auth-port 1812 acct-port 1813 default key 2 $d3NpZ0BVXFpJ web-auth
Note: Remember the RADIUS key you entered. You will need this key when you configure your RADIUS server. - Configure Web Authentication to use secure (HTTPS) or non-secure (HTTP) login and
logout pages. By default, HTTPS is used.
device(config)# web-management HTTP device(config# vlan 10 device(config-vlan-10# webauth device(config-vlan-10-webauth# no secure-login
- Provide the switch with a certificate to enable Web Authentication using one of the
following methods:
If the secure Web server is used, in order to access a secure Web page, the Web server needs to provide a key. This key is exchanged using a certificate. A certificate is a digital document that is issued by a trusted source that can validate the authenticity of the certificate and the Web server that is presenting it. Therefore the switch must have a certificate for web authentication to work.
- Upload a certificate using the following global configuration command.
device(config)# ip ssl private-key-file tftp ip-addr key-filename
- Upload a certificate using the following global configuration command.
- Create a Web Authentication VLAN and enable Web Authentication on that VLAN.
- Configure the Web Authentication mode:
- Username and password: Blocks users from accessing the switch until they enter a valid username and password on a web login page.
- Passcode: Blocks users from accessing the switch until they enter a valid passcode on a web login page.
- captive-portal: Authenticates the users in a VLAN through external Web Authentication (Captive Portal user authentication) mode.
- None: Blocks users from accessing the switch until they press the Login button. A username and password or passcode is not required.
Refer to Web Authentication Mode Configuration.
- Configure other Web Authentication options (refer to Web Authentication Options).