Configuring Passcode Authentication
The following steps configure the device to use the passcode authentication mode.
- Complete the configuration steps described in Configuring Web Authentication.
- Create static passcodes.
- Enable passcode authentication.
This command enables Web Authentication to use dynamically created passcodes to authenticate users in the VLAN. If the configuration includes static passcodes, they are used in conjunction with dynamically created passcodes.
- (Optional) Configure the length
of dynamically generated passcodes. By default, dynamically generated passcodes are 4 digits in length; for example, 0123. If desired, you can increase the passcode length to up to 16 digits.
- (Optional) Configure one of the
following passcode refresh methods:
- Configure the duration of
time (in minutes) after which passcodes must be
refreshed.
device(config-vlan-10-webauth)# auth-mode passcode refresh-type duration 4320
- Configure the time of day
at which the passcodes must be refreshed.
device(config-vlan-10-webauth)# auth-mode passcode refresh-type time 6:00
By default, passcodes will be refreshed at 00:00 (12:00 midnight). You can configure up to 24 refresh periods in a 24-hour period. Each must be at least five minutes apart. - Configure the duration of
time (in minutes) after which passcodes must be
refreshed.
- (Optional) Configure a grace period for an expired passcode.
- (Optional) Delete all expired passcodes that are currently in the grace period.
- (Optional) Disable and re-enable passcode log. A Syslog message and SNMP trap message are generated every time a new passcode is generated and passcode authentication is attempted,. This is the default behavior. If desired, you can disable passcode-related Syslog messages or SNMP trap messages, or both.
- (Optional) Retransmit the current passcode to a Syslog message or SNMP trap. The switch retransmits the current passcode only. Passcodes that are in the grace period are not sent.
- (Optional) Manually refresh the passcode.