white-list (Web Authentication)

Adds IPv4 or FQDN addresses allowed access during authentication along with the required Captive-Portal server, DNS servers, or DHCP servers.
Syntax
white-list ID { FQDN | ip-address/mask }
no white-list ID
no white-list ID { FQDN | ip-address/mask }
Command Default

Depending on the protocol used, DNS and DHCP packets along with the Captive Portal server are allowed access, but no pre-configured servers or hosts are allowed access for Web Authentication.

Parameters
ID
Decimal number that identifies a specific white-list. Must be in the range 1 through 100.
FQDN
The fully qualified domain name for a permitted server (ASCII string).
ipv4 address
An IPv4 address for a permitted server, in the form A.B.C.D./L (where L is the network mask) or A.B.C.D x.x.x.x (where x.x.x.x is the subnet mask). A specific IP address can be entered with a subnet mask.
Modes

Web Authentication configuration sub-mode under a specific VLAN

Usage Guidelines

The no form of the white-list command followed the ID or by the ID and a previously specified address removes the specified address from the set of servers and hosts permitted during Web Authentication.

Web Authentication can be configured only at the VLAN level.

Up to 100 Web Authentication white-lists can be configured.

Configured white-lists are displayed in show webauth and show running-config vlan command output.

Examples

The following example configures three Web Authentication white-lists: an FQDN (www.commscope.com), an IPv4 subnet, and an IPv4 server address and confirms their configuration with the show webauth and show running-config vlan commands.

device# configure terminal
device(config)# vlan 300
device(config-vlan-300)# webauth
device(config-vlan-300-webauth)# white-list 10 www.commscope.com
White-list server address 104.18.14.129 resolved
device(config-vlan-300-webauth)# white-list 30 192.168.0.1/24
device(config-vlan-300-webauth)# white-list 35 192.168.12.2
Incomplete command.
device(config-vlan-300-webauth)# white-list 35 192.168.12.2 0.0.0.255

device(config-vlan-300-webauth)# show webauth vlan 300
=============================================================================
WEB AUTHENTICATION (VLAN 300): Disable (Default)
attempt-max-num: 5 (Default)
host-max-num: 0 (Default)
block duration: 90 (Default)
cycle-time: 600 (Default)
port-down-authenticated-mac-cleanup: Enable (Default)
reauth-time: 60
authenticated-mac-age-time: 3600 (Default)
webauth-redirect-address: none (Default)
dns-filter: Disable (Default)
white-list 10 104.18.14.129
white-list 30 192.168.0.1 0.0.0.255
white-list 35 192.168.12.2 0.0.0.255
white-list 60 10.177.17.67 0.0.0.127
authentication mode: captive portal
Radius accounting: Enable (Default)
Trusted port list: ether 3/1/4, lag 1
Secure Login (HTTPS): Enable (Default)
Host statistics:
Number of hosts dynamically authenticated: 0
Number of hosts statically authenticated: 0
Number of hosts dynamically blocked: 0
Number of hosts statically blocked: 0
Number of hosts authenticating: 0

device(config-vlan-300-webauth)# show running-config vlan
30 vlan VLAN running-config section

device(config-vlan-300-webauth)# show running-config vlan 300
vlan 300 by port
tagged ethe 3/1/48 lag 1
untagged ethe 1/1/23
router-interface ve 300
webauth
captive-portal profile captive_profile1
reauth-time 60
white-list 10 104.18.14.129
white-list 30 192.168.0.1 0.0.0.255
white-list 35 192.168.12.2 0.0.0.255
white-list 60 10.177.17.67 0.0.0.127
auth-mode passcode length 16
auth-mode passcode static 1234
auth-mode captive-portal
trust-port lag 1
!
History
Release version Command history
9.0.00 This command was introduced.