Web Authentication Options

Web Authentication offers a number of other configuration options.

RADIUS Accounting for Web Authentication

When Web Authentication is enabled, you can enable RADIUS accounting using the accounting command to record login (start) and logout (stop) events per host. The information is sent to a RADIUS server. Note that packet/byte count is not supported.

Trusted Ports

You can configure certain ports of a Web Authentication VLAN as trusted ports using the trust-port command. All hosts connected to the trusted ports need not authenticate and are automatically allowed access to the network.

Permanently Authenticated Hosts

Certain hosts, such as a DHCP server, gateways, and printers, may need to be permanently authenticated. Typically, these hosts are managed by the network administrator and are considered to be authorized hosts. Some of these hosts (such as printers) may not have a web browser and will not be able to perform Web Authentication. Such hosts can be permanently authenticated using the add mac command. You can set the duration to specify how long the MAC address remain authenticated. The default is the time configured using the reauth-time command. To keep the host permanently authenticated, set the duration to 0 so that the web authentication for the MAC address does not expire.

Instead of just entering a duration for how long the MAC address remains authenticated, you can specify the MAC address to be added by the specified port that is a member of the VLAN.

Note: If a MAC address is statically configured, it will not be dynamically configured on any port.

IP Addresses and Domain Names Allowed During Web Authentication

You can create a list of pre-configured hosts and servers that are allowed access during Web Authentication. This capability is typically referred to as a walled garden. Depending on the Web Authentication processes followed by users, communication with more than one host or server may be required during authentication. A typical example would be when Web Authentication requires certificate exchanges with a specific host.

Web Authentication automatically allows DHCP or DNS packets, depending on the protocol used, and allows access to the Captive Portal server used for authentication. Any other sites that may be required can be configured as white-lists at the VLAN level. An IPv4 address with or without a sub-net mask or a fully qualified domain name (FQDN) can be configured as a Web Authentication white-list. Up to 100 white-lists can be configured for Web Authentication.

Re-authentication Period

After a successful authentication, a user remains authenticated for a duration of time. At the end of this duration, the host is automatically logged off. The user must be re-authenticated again. The number of seconds a host remains authenticated before being logged off can be configured using the reauth-time command.

Web Authentication Cycle

You can set a limit as to how many seconds before which the users have to be web-authenticated by defining a cycle time. This time begins at a user's first Login attempt on the Login page. If the user has not been authenticated successfully when this time expires, the user must enter a valid URL again to display the Web Authentication welcome page.

Limiting the Number of Web Authentication Attempts

You can set a limit on the number of times a user enters an invalid username and password during the specified cycle time using the attempt-max-num command. If the user exceeds the limit, the user is blocked for a duration of time, which is defined by the block duration command. Also, the Web browser will be redirected to the exceeded allowable attempts web page.

Clearing Authenticated Hosts from the Web Authentication Table

You can clear dynamically authenticated hosts from the Web Authentication table. All authenticated hosts in a Web Authentication VLAN can be cleared using the clear webauth vlan vlan-id authenticated-mac command. If you want to clear a particular host in a Web Authentication VLAN, enter the clear webauth vlan vlan-id authenticated-mac mac-address command.

Block Duration for Web Authentication Attempts

After users exceed the limit for Web Authentication attempts, you can specify how many seconds users must wait before the next cycle of Web Authentication begins using the block duration command. Users cannot attempt Web Authentication during this time. To unblock the MAC address, wait until the block duration timer expires or enter the clear webauth vlan vlan-id block-mac mac-address command.

Manually Blocking a Specific Host

A host can be temporarily or permanently blocked from attempting Web Authentication block mac mac-address duration time command.

You can specify the duration from 0 through 128000 seconds. The default is the current value of the block duration command. To keep the MAC address permanently blocked, set the duration to 0.

Limiting the Number of Authenticated Hosts

You can limit the number of hosts that are authenticated at a time by entering the host-max-num command. You can specify from 0 through 8192 hosts. The default value is 0, which means that there is no limit to the number of hosts that can be authenticated. The maximum of 8192 is the maximum number of MAC addresses the device supports. When the maximum number of hosts has been reached, the FastIron switch redirects any new host that has been authenticated successfully to the Maximum Host web page.

Filtering DNS Queries

Many of the Web Authentication solutions allow DNS queries to be forwarded from unauthenticated hosts. To eliminate the threat of forwarding DNS queries from unauthenticated hosts to unknown or untrusted servers (also known as domain-casting), you can restrict DNS queries from unauthenticated hosts to be forwarded explicitly to defined servers by defining DNS filters using the dns-filter command. Any DNS query from an unauthenticated host to a server that is not defined in a DNS filter is dropped. Only DNS queries from unauthenticated hosts are affected by DNS filters; authenticated hosts are not. If the DNS filters are not defined, then any DNS queries can be made to any server. You can have up to four DNS filters and specify a number from 1 to 4 to identify the DNS filter.

You can specify the IP address and subnet mask of unauthenticated hosts that will be forwarded to the unknown or untrusted servers.

You can use a wildcard for the filter. The wildcard is in dotted-decimal notation (IP address) format. It is a four-part value, where each part is 8 bits (one byte) separated by dots, and each bit is a one or a zero. Each part is a number ranging from 0 through 255 (for example, 0.0.0.255). Zeros in the mask mean the packet source address must match the IP address. Ones mean any value matches.

Forcing Re-authentication When Ports Are Down

By default, the device checks the link state of all ports that are members of the Web Authentication VLAN and if the state of all the ports is down, then the device forces all authenticated hosts to re-authenticate. That is, the port-down-authenticated-mac-cleanup command that enforces re-authentication of all authenticated hosts when all the ports are down is enabled by default. However, hosts that were authenticated using the add mac command will remain authenticated; they are not affected by the port-down-authenticated-mac-cleanup command.

Forcing Re-authentication After an Inactive Period

You can force Web Authentication hosts to be re-authenticated if they have been inactive for a period of time. The inactive duration is calculated by adding the mac-age-time that has been configured for the device and the configured authenticated-mac-age-time. (The mac-age-time command defines how long a port address remains active in the address table.) If the authenticated host is inactive for the sum of these two values, the host is forced to be re-authenticated.

In the authenticated-mac-age-time command, you can specify a value from 0 through the value entered for the reauth-time command. The default is 3600.

Defining the Web Authorization Redirect Address

When a user enters a valid URL, the user is redirected to the switch Web Authentication page and the welcome page is displayed. By default, the Web Authentication address returned to the browser is the IP address of the FastIron switch. To prevent the display of error messages saying that the certificate does not match the name of the site, you can change this address so that it matches the name on the security certificates using the webauth-redirect-address command.

Entering "my.domain.net" redirects the browser to https://my.domain.net/ when the user enters a valid URL on the web browser.

You can enter any value up to 64 alphanumeric characters for the string, but entering the name on the security certificate prevents the display of error messages saying that the security certificate does not match the name of the site.