Configuring Web Authentication
Complete the following steps to configure Web Authentication on a device.
- Enter the global configuration mode.
- Set up any global configuration required for the FastIron switch, RADIUS server, Web server and other servers.
- Configure the RADIUS server and other servers if Web Authentication will use a RADIUS
server. By default, Web Authentication uses a RADIUS server to authenticate host usernames
and passwords, unless it is configured to use a local user database.
device(config)# radius-server host 10.1.1.8 auth-port 1812 acct-port 1813 default key 2 $d3NpZ0BVXFpJ web-auth
Note: Remember the RADIUS key you entered. You will need this key when you configure your RADIUS server. - Create a Web Authentication VLAN.
- (Optional) Configure Web
Authentication to use secure (HTTPS) or non-secure (HTTP) login and logout
pages. Web management access over HTTPS is enabled by default. For TPM-enabled devices, TPM certificates are available by default to establish encrypted communication between the server and client. For more information about digital certificates for web access, refer ICX Digital Certificates.
device(config)# web-management HTTP device(config)# vlan 10 device(config-vlan-10)# webauth device(config-vlan-10-webauth)# no secure-login
- Enable Web Authentication on the VLAN.
- Configure the Web Authentication mode:
- Username and password: Blocks users from accessing the device until they enter a valid username and password on a web login page. By default "username-password" is the authentication method. For more information, refer to Using Local User Databases.
- Passcode: Blocks users from accessing the device until they enter a valid passcode on a web login page. For more information, refer to Passcodes for User Authentication.
- captive-portal: Authenticates the users in a VLAN through external Web Authentication (Captive Portal user authentication) mode. For more information, refer to Configuring Captive Portal (External Web Authentication)
- None: Blocks users from accessing the device until they press the Login button. A username and password or passcode is not required. For more information, refer to Automatic Authentication.
- Configure other Web Authentication options (refer to Web Authentication Options).