show webauth

Displays Web Authentication configuration details.
Syntax
show webauth [ allowed-list | authenticating-list | blocked-list | vlan vlan-id [ passcode | webpage ] ]
Parameters
allowed-list
Displays a list of hosts that are currently authenticated.
authenticating-list
Displays a list of hosts that are trying to authenticate.
blocked-list
Displays a list of hosts that are currently blocked from any Web Authentication attempt.
vlanvlan-id
Displays Web Authentication details on a specific VLAN.
passcode
Displays current dynamic passcode details.
webpage
Displays what text has been configured for Web Authentication pages.
Modes

User EXEC mode

Usage Guidelines

The show webauth command by itself displays information for all VLANs on which Web Authentication is enabled.

The show webauth command displays the following information:

Field Description for show webauth Command Output

Field

Description

WEB AUTHENTICATION (VLAN #)

Identifies the VLAN on which Web Authentication is enabled.

attempt-max-num

The maximum number of Web Authentication attempts during a cycle.

host-max-num

The maximum number of users that can be authenticated at one time.

block duration

The number of seconds a user who failed Web Authentication must wait before attempting to be authenticated.

cycle-time

The number of seconds in one Web Authentication cycle.

port-down-authenticated-mac-cleanup

Whether this option is enabled or disabled. If enabled, all authenticated users are de-authenticated if all the ports in the VLAN go down.

reauth-time

The number of seconds an authenticated user remains authenticated. Once this timer expires, the user must re-authenticate.

authenticated-mac-age-time

If a user is inactive, the number of seconds a user has before the user-associated MAC address is aged out. The user will be forced to re-authenticate.

webauth-redirect-address

Displays a redirect address if one has been configured; otherwise, displays 0 (the default).

dns-filter

Shows the definition of any DNS filter that has been set.

white-list ID

Displays any white-lists configured for sites or servers allowed Web Authentication access, including white-list ID and IP address or FQDN.

authentication mode

The authentication mode:

  • username and password (default)
  • passcode
  • captive-portal
  • none

Also displays configuration details for the authentication mode.

RADIUS accounting

Whether RADIUS accounting is enabled or disabled.

Trusted port list

The statically configured trusted ports of the Web Authentication VLAN.

Secure login (HTTPS)

Whether HTTPS is enabled or disabled.

Web Page Customizations

The current configuration for the text that appears on the Web Authentication pages. Either "Custom Text" or "Default Text" displays for each page type:

  • "Custom Text" means the message for the page has been customized. The custom text is also displayed.
  • "Default Text" means the default message that ships with the FastIron switch is used.

The actual text on the Web Authentication pages can be displayed using the show webauth vlan <vlan-id> webpage command.

Host statistics

The authentication status and the number of hosts in each state.

The show webauth vlan command displays the following information.

Output field Description
WEB AUTHENTICATION (VLAN #) Identifies the VLAN on which Web Authentication is enabled.
attempt-max-num The maximum number of Web Authentication attempts during a cycle.
host-max-num The maximum number of users that can be authenticated at one time.
block duration The number of seconds a user who failed Web Authentication must wait before attempting to be authenticated.
cycle-time The number of seconds in one Web Authentication cycle.
port-down-authenticated-mac-cleanup Indicates if this option is enabled or disabled. If enabled, all authenticated users are deauthenticated if all the ports in the VLAN go down.
reauth-time The number of seconds an authenticated user remains authenticated. Once this timer expires, the user must reauthenticate.
authenticated-mac-age-time If a user is inactive, this time shows how many seconds a user has before the user-associated MAC address is aged out. The user will be forced to reauthenticate.

webauth-redirect-address

Displays a redirect address if one has been configured; otherwise, displays 0 (the default).
dns-filter Shows the definition of any DNS filter that has been set.

white-list ID

Displays any white-lists configured for sites or servers allowed Web Authentication access, including white-list ID and IP address or FQDN.
authentication mode The authentication mode: username and password (default), passcode, captive-portal, or none. Also displays configuration details for the authentication mode.
RADIUS accounting Whether RADIUS accounting is enabled or disabled.
Trusted port list The statically-configured trusted ports of the Web Authentication VLAN.
Secure login (HTTPS) Whether HTTPS is enabled or disabled.
Host statistics The authentication status and the number of hosts in each state.

The show webauth allowed-list command displays the following information:

Output field Description
VLAN #: Web Authentication The ID of the VLAN on which Web Authentication is enabled.
Web Authenticated List MAC Address The MAC addresses that have been authenticated.
AuthMode The client is authenticated using internal server or external server.
User Name The authenticated username.
Configuration Static/Dynamic If the MAC address was dynamically (passed Web Authentication) or statically (added to the authenticated list using the add mac command) authenticated.
Authenticated Duration HH:MM:SS The remainder of time the MAC address will remain authenticated.
Dynamic ACL The dynamically assigned ACL.

The show webauth authenticating-list command displays the following information:

Output field Description
VLAN #: Web Authentication The ID of the VLAN on which Web Authentication is enabled.
MAC Address The MAC addresses that are trying to be authenticated.
AuthMode The client is authenticated using internal server or external server.
User Name The User Name associated with the MAC address.
# of Failed Attempts Number of authentication attempts that have failed.
Cycle Time Remaining The remaining time the user has to be authenticated before the current authentication cycle expires. Once it expires, the user must enter a valid URL again to display the Web Authentication Welcome page.

The show webauth blocked-list command displays the following information:

Output field Description
VLAN #: Web Authentication The ID of the VLAN on which Web Authentication is enabled.
Web Block List MAC Address The MAC addresses that have been blocked from Web Authentication.
AuthMode The client is authenticated using internal server or external server.
User Name The username associated with the MAC address.
Configuration Static/Dynamic If the MAC address was dynamically or statically blocked. The block mac command statically blocks MAC addresses.
Block Duration Remaining The remaining time the MAC address has before the user with that MAC address can attempt Web Authentication.
Examples

The following example displays sample output of the show webauth allowed-list command.

device# show webauth allowed-list
=============================================================================
VLAN 3: Web Authentication, Mode: I = Internal E = External
-------------------------------------------------------------------------------------
Web Authenticated List                Configuration   Authenticated Duration  Dynamic
MAC Address       User Name   mode    Static/Dynamic  HH:MM:SS                ACL 
-------------------------------------------------------------------------------------
000c.2973.a42b    ruckus      E       D               1 day, 11:33:16         acl1
1222.0a15.f045    super       E       D               1 day, 11:32:51         acl1  
1222.0a15.f044    foundry     E       D               1 day, 11:32:48         acl1  
1222.0a15.f043    ruckus      E       D               1 day, 11:32:47         acl1  
1222.0a15.f042    spirent     E       D               1 day, 11:32:4          acl1 

The following example displays sample output of the show webauth authenticating-list command.

device# show webauth authenticating-list
==========================================================================
VLAN 3: Web Authentication, AuthMode: I=Internal E=External 
---------------------------------------------------------------------------
Web Authenticating List             # of Failed  Cycle Time Remaining
MAC Address        User Name  mode  Attempts     HH:MM:SS
---------------------------------------------------------------------------
000c.2973.a42b     N/A        E     0            00:01:36          

The following example displays sample output of the show webauth blocked-list command.

device# show webauth blocked-list
=============================================================================
VLAN 3: Web Authentication, AuthMode: I=Internal E=External 
-------------------------------------------------------------------------------
Block List                       Configuration mode  Block Duration Remaining
MAC Address     User Name  mode  Static/Dynamic
-------------------------------------------------------------------------------
000c.2973.a42b  User1      E     D                   00:00:04 

The following example displays sample output of the show webauth vlanvlan-id passcode command.

device# show webauth vlan 25 passcode
Current Passcode : 1389
This passcode is valid for 35089 seconds

The following is a sample output of the show webauthvlanvlan-idwebpage command.

device# show webauth vlan 25 webpage
===================================================
Web Page Customizations (VLAN 25):
  Top (Header): Default Text
    "<h3>Welcome to Ruckus Networks Web Authentication Homepage</h3>"
  Bottom (Footer): Custom Text
    "Copyright 2009 SNL"
  Title: Default Text
    "Web Authentication"
  Login Button: Custom Text
    "Sign On"
  Web Page Logo: blogo.gif
    align: left (Default)
  Web Page Terms and Conditions: policy1.txt
History
Release version Command history
08.0.40 The output was modified to include "mode" and "Dynamic ACL" fields.
09.0.00 The output was modified to include white-list fields and to exclude Web Page customization fields.
09.0.10 The output was modified to include webauth page label configuration and other customization fields.