FlexAuth Web Authentication Configuration

The following table applies to web authentication only.

Name, OID, and syntax

Access

Description

ruckusWebAuthTable

snSwitch.44.1.4.1

Syntax: SEQUENCE OF RuckusWebAuthEntry

None

Allows configuration of Web authentication for a specified VLAN. Web authentication is configured at the VLAN level, MAC authentication and 802.1X authentication which are configured at the port level.

An entry exists in this table for each configured VLAN with Web authentication.

ruckusWebAuthEntry

snSwitch.44.1.4.1.1

Syntax: RuckusWebAuthEntry

None

An entry of Web authentication configuration.

ruckusWebAuthVlan

snSwitch.44.1.4.1.1.1

Syntax: VlanId

None

Specifies the VLAN to which this configuration entry applies.

ruckusWebAuthEnable

snSwitch.44.1.4.1.1.2

Syntax: EnabledStatus

Read-only Specifies if Web authentication is enabled or disabled.
ruckusWebAuthMode

snSwitch.44.1.4.1.1.3

Syntax: INTEGER { none(1),

passcode(2),

password(3),

captivePortal(4) }

Read-only

Specifies the authentication mode used for authenticating the users.

  • none(1): No authentication is performed.
  • passcode(2): Passcode-based authentication, where the passcode can be configured statically or generated dynamically.
  • password(3): Username- or password-based authentication, where the local user database or external RADIUS server is used.
  • captivePortal(4): External captive portal is used through redirection.
ruckusWebAuthMethod

snSwitch.44.1.4.1.1.4

Syntax: INTEGER { radius(1),

local(2),

radiusLocal(3),

localRadius(4),

none(5) }

Read-only

Specifies the order for performing authentication when the authentication mode is configured as a password.

  • radius - RADIUS server for authentication
  • local - Local user DB for authentication
  • radiusLocal - RADIUS followed by Local User DB
  • localRadius - Local User DB followed by RADIUS
  • none - none of these methods.

The default value is none(5).

ruckusWebAuthMaxHosts

snSwitch.44.1.4.1.1.5

Syntax: Unsigned32 (0..8192)

Read-only

Specifies the maximum number of hosts allowed to be authenticated. The value of "0" means no limit.

The default value is "0".

ruckusWebAuthMaxAuthAttempts

snSwitch.44.1.4.1.1.6

Syntax: Unsigned32 (0..64)

Read-only

Specifies the maximum number of attempts allowed during the authentication cycle, after which the user is blocked for a configured amount of time before the next authentication attempt. The value of "0" means no limit.

The default value is 5.

ruckusWebAuthReauthTime

snSwitch.44.1.4.1.1.7

Syntax: Unsigned32 (0..128000)

Read-only

Specifies the re-authentication time, so the authenticated users can be periodically reauthenticated after the timeout specified through this object. The value of "0" means no limit.

The default value is 28800 seconds.

ruckusWebAuthCycleTime

snSwitch.44.1.4.1.1.8

Syntax: Unsigned32 (0..3600)

Read-only

Specifies the time of the authentication since the first attempted user authentication, after which the user is not allowed to authenticate and must reload the login page to start authentication. The value of "0" means no limit.

The default value is 600 seconds.

ruckusWebAuthBlockTime

snSwitch.44.1.4.1.1.9

Syntax: Unsigned32 (0..128000)

Read-only

Specifies the time for blocking the user when successive attempts have failed resulting in blocking the user. The value of "0" means the user is blocked permanently.

The default value is 90 seconds.

ruckusWebAuthMacAgeTime

snSwitch.44.1.4.1.1.10

Syntax: Unsigned32 (0..3600)

Read-only

Specifies time, which together with the mac-age-time of the switch is considered an inactive time of the authenticated host, after which the device is forced to re-authenticate.

The value can be "0", meaning no aging and the maximum can be up to the specified re-authentication time.

The default value is 3600.

ruckusWebAuthPasscode

snSwitch.44.1.4.1.1.11

Syntax: DisplayString

Read-only

Specifies the statically configured passcode used to authenticate when the passcode is used as the authentication method. The passcode must be in digits only, consisting of four passcodes, where each entry is separated by a space or a tab.

ruckusWebAuthLocalUserDb

snSwitch.44.1.4.1.1.12

Syntax: DisplayString

Read-only

Specifies the locally configured user database for use in authentication when the authentication method is password.

ruckusWebAuthSecureLogin

snSwitch.44.1.4.1.1.13

Syntax: EnabledStatus

Read-only Specifies whether or not HTTPS is used for authentication.

The default mode is enabled.

ruckusWebAuthAccounting

snSwitch.44.1.4.1.1.14

Syntax: EnabledStatus

Read-only Specifies whether accounting is enabled or disabled.

The default mode is disabled.

ruckusWebAuthCaptiveProfile

snSwitch.44.1.4.1.1.15

Syntax: DisplayString

Read-only

Specifies the name of the configured captive portal profile, which should be used for redirection if the authentication mode is configured as captivePortal.

ruckusWebAuthRedirectName

snSwitch.44.1.4.1.1.16

Syntax: DisplayString

Read-only

Specifies the name to be used for the URL when internal authentication is used during authentication for prompting a username or password from the users. Otherwise, the switch IP address is used. This must be a valid domain name for the switch.

ruckusWebAuthWebpageRemoveUserId

snSwitch.44.1.4.1.1.17

Syntax: EnabledStatus

Read-write Specifies if user-id field in the custom webauth login page is disabled or not, default value is disabled which means user-id field is displayed.
ruckusWebAuthWebpageUsernameLabel

snSwitch.44.1.4.1.1.18

Syntax: DisplayString

Read-write Specifies the name to be used for user-id label in the webauth login page.
ruckusWebAuthWebpagePasswordLabel

snSwitch.44.1.4.1.1.19

Syntax: DisplayString

Read-write Specifies the name to be used for password label in the webauth login page.
ruckusWebAuthUpLinkPort

snSwitch.44.1.4.1.1.20

Syntax: InterfaceIndexOrZero

Read-write Specifies the port to be used as uplink port in the network segmentation deployment.
ruckusWebAuthWebpageTop

snSwitch.44.1.4.1.1.21

Syntax: DisplayString

Read-write Specifies the name to be used for the top of webauth login page.
ruckusWebAuthWebpageBottom

snSwitch.44.1.4.1.1.22

Syntax: DisplayString

Read-write Specifies the name to be used for the bottom of webauth login page.
ruckusWebAuthWebpageTitle

snSwitch.44.1.4.1.1.23

Syntax: DisplayString

Read-write Specifies the name to be used for the title in webauth login page.
ruckusWebAuthWebpageLoginButton

snSwitch.44.1.4.1.1.24

Syntax: DisplayString

Read-write Specifies the name to be used for the login button in webauth login page.