Web Authentication Options
Web Authentication offers a number of other configuration options.
RADIUS Accounting for Web Authentication
When Web Authentication is enabled, you can
enable RADIUS accounting using the accounting command to record login
(start) and logout (stop) events per host. The information is sent to a RADIUS server.
Note
that packet/byte count is not supported.
Trusted Ports
You can configure certain ports of a Web
Authentication VLAN as trusted ports using the trust-port command. All
hosts connected to the trusted ports need not authenticate and are automatically allowed
access to the network.
Permanently Authenticated Hosts
Certain hosts, such as a DHCP server, gateways,
and printers, may need to be permanently authenticated. Typically, these hosts are
managed
by the network administrator and are considered to be authorized hosts. Some of these
hosts
(such as printers) may not have a web browser and will not be able to perform Web
Authentication. Such hosts can be permanently authenticated using the add mac command. You can set the
duration to specify how long the MAC address remain authenticated. The default is
the time
configured using the reauth-time command. To keep the host
permanently authenticated, set the duration to 0 so that the web authentication for the MAC
address does not expire.
Instead of just entering a duration for how long the MAC address remains authenticated, you can specify the MAC address to be added by the specified port that is a member of the VLAN.
IP Addresses and Domain Names Allowed During Web Authentication
You can create a list of pre-configured hosts and servers that are allowed access during Web Authentication. This capability is typically referred to as a walled garden. Depending on the Web Authentication processes followed by users, communication with more than one host or server may be required during authentication. A typical example would be when Web Authentication requires certificate exchanges with a specific host.
Web Authentication automatically allows DHCP or DNS packets, depending on the protocol used, and allows access to the Captive Portal server used for authentication. Any other sites that may be required can be configured as white-lists at the VLAN level. An IPv4 address with or without a sub-net mask or a fully qualified domain name (FQDN) can be configured as a Web Authentication white-list. Up to 100 white-lists can be configured for Web Authentication.
Re-authentication Period
After a successful authentication, a user
remains authenticated for a duration of time. At the end of this duration, the host
is
automatically logged off. The user must be re-authenticated again. The number of seconds
a
host remains authenticated before being logged off can be configured using the
reauth-time command.
Web Authentication Cycle
You can set a limit as to how many seconds before which the users have to be web-authenticated by defining a cycle time. This time begins at a user's first Login attempt on the Login page. If the user has not been authenticated successfully when this time expires, the user must enter a valid URL again to display the Web Authentication welcome page.
Limiting the Number of Web Authentication Attempts
You can set a limit on the number of times
a user enters an invalid username and password during the specified cycle time using
the
attempt-max-num command. If the user exceeds the limit, the user is
blocked for a duration of time, which is defined by the block duration command. Also, the
Web browser will be redirected to the exceeded allowable attempts web page.
Clearing Authenticated Hosts from the Web Authentication Table
You can clear dynamically authenticated
hosts from the Web Authentication table. All authenticated hosts in a Web Authentication
VLAN can be cleared using the clear
webauth vlan
vlan-id
authenticated-mac command. If you want to clear a particular host in a
Web Authentication VLAN, enter the clear webauth vlan
vlan-id
authenticated-mac
mac-address command.
Block Duration for Web Authentication Attempts
After users exceed the limit for Web
Authentication attempts, you can specify how many seconds users must wait before the
next
cycle of Web Authentication begins using the block duration command. Users
cannot attempt Web Authentication during this time. To unblock the MAC address, wait
until
the block duration timer expires or enter the clear webauth vlan
vlan-id
block-mac
mac-address command.
Manually Blocking a Specific Host
A host can be temporarily or permanently blocked
from attempting Web Authentication block mac
mac-address
duration
time command.
You can specify the duration from 0 through
128000 seconds. The default is the current value of the block duration command. To keep
the MAC address permanently blocked, set the duration to
0.
Limiting the Number of Authenticated Hosts
You can limit the number of hosts that are
authenticated at a time by entering the host-max-num command. You can
specify from 0 through 8192 hosts. The default value is 0, which means that there
is no
limit to the number of hosts that can be authenticated. The maximum of 8192 is the
maximum
number of MAC addresses the device supports. When the maximum number of hosts has
been
reached, the FastIron switch redirects any new host that has been authenticated successfully
to the Maximum Host web page.
Filtering DNS Queries
Many of the Web Authentication solutions
allow DNS queries to be forwarded from unauthenticated hosts. To eliminate the threat
of
forwarding DNS queries from unauthenticated hosts to unknown or untrusted servers
(also
known as domain-casting), you can restrict DNS queries from unauthenticated hosts
to be
forwarded explicitly to defined servers by defining DNS filters using the
dns-filter command. Any DNS query from an unauthenticated host to a
server that is not defined in a DNS filter is dropped. Only DNS queries from unauthenticated
hosts are affected by DNS filters; authenticated hosts are not. If the DNS filters
are not
defined, then any DNS queries can be made to any server. You can have up to four
DNS
filters and specify a number from 1 to 4 to identify the DNS filter.
You can specify the IP address and subnet mask of unauthenticated hosts that will be forwarded to the unknown or untrusted servers.
You can use a wildcard for the filter. The wildcard is in dotted-decimal notation (IP address) format. It is a four-part value, where each part is 8 bits (one byte) separated by dots, and each bit is a one or a zero. Each part is a number ranging from 0 through 255 (for example, 0.0.0.255). Zeros in the mask mean the packet source address must match the IP address. Ones mean any value matches.
Forcing Re-authentication When Ports Are Down
By default, the device checks the link state
of all ports that are members of the Web Authentication VLAN and if the state of all
the
ports is down, then the device forces all authenticated hosts to re-authenticate.
That is,
the port-down-authenticated-mac-cleanup command that enforces re-authentication of
all authenticated hosts when all the ports are down is enabled by default. However,
hosts
that were authenticated using the add mac command will remain authenticated; they are not affected by the
port-down-authenticated-mac-cleanup command.
Forcing Re-authentication After an Inactive Period
You can force Web Authentication hosts to
be re-authenticated if they have been inactive for a period of time. The inactive
duration
is calculated by adding the mac-age-time that has been configured for the device and the configured
authenticated-mac-age-time. (The mac-age-time command defines how
long a port address remains active in the address table.) If the authenticated host
is
inactive for the sum of these two values, the host is forced to be re-authenticated.
In the authenticated-mac-age-time
command, you can specify a value from 0 through the value entered for the reauth-time command. The default
is 3600.
Defining the Web Authorization Redirect Address
When a user enters a valid URL, the user is
redirected to the switch Web Authentication page and the welcome page is displayed.
By
default, the Web Authentication address returned to the browser is the IP address
of the
FastIron switch. To prevent the display of error messages saying that the certificate
does
not match the name of the site, you can change this address so that it matches the
name on
the security certificates using the webauth-redirect-address command.
Entering "my.domain.net" redirects the browser to https://my.domain.net/ when the user enters a valid URL on the web browser.
You can enter any value up to 64 alphanumeric characters for the string, but entering the name on the security certificate prevents the display of error messages saying that the security certificate does not match the name of the site.