Configuring Web Access

Perform the following steps to enable web access over HTTP, configure web session parameters, and restrict web access to a device.

  1. Enter global configuration mode.
    device# configure terminal
  2. (Optional) Enable web management for HTTP access.
    device(config)# web-management http
    For TPM-enabled devices, TPM certificates are available by default to establish encrypted communication between the server and client. You can also import a digital certificate issued by a third-party using the copy tftp flash 192.168.9.210 certfile certificate-data-file command. ICX devices that are not TPM-capable, for example, legacy devices deployed to the field, may use an auto-generated non-TPM certificate. Non-TPM certificates are stored on the device in flash memory.

    Once a valid certificate is present, it remains available, unless the user erases the startup configuration or uses a command to zeroize (clear) the certificate.

    When no certificate is present, the RUCKUS ICX device is unable to use applications that require a certificate.

    When more than one certificate is stored in the RUCKUS ICX device, the device selects the certificate for use based on the following order of priority:

    1. TPM certificate
    2. Non-TPM (auto-generated legacy) certificate

  3. Restrict web access to the device based on the source IP address, IPv6 address, MAC address, or a combination of addresses of the clients.
    By default, there are no web access restrictions. You can control web access by allowing or denying HTTP and HTTPS traffic from the specified IP address or MAC address.
    device(config)# management access src-ip 10.10.10.1 255.255.255.255 allow web
    device(config)# management access mac 0000.000f.e9a0 deny web 
  4. Configure the wait time interval after getting disconnected from the application.
    device(config)# web-management connection-receive-timeout 3
  5. Configure the duration for which the web session can remain idle before it is disconnected.
    device(config)# web-management session-timeout 300
  6. Configure the port number for the web service.
    device(config)# web-management tcp-port 80
  7. View the web login details.
    device# show web
    HTTP server status: Enabled
    HTTPS server status: Enabled
    
    Web session management:
    User    Privilege     IP address     Timeout(secs) CONNECTION
    admin   READ-WRITE    172.26.78.58    300           HTTP
    admin   READ-WRITE    10.198.138.97   300           HTTPS 
    

Web Access Configuration

The following example enables web management for HTTP access. It also permits web access to a specific IP address and denies access to a MAC address.

device# configure terminal
device(config)# web-management http
device(config)# management access src-ip 10.10.10.1 255.255.255.255 allow web
device(config)# management access mac 0000.000f.e9a0 deny web 

Disable Web Access

The following example disables web access.

device# configure terminal
device(config)# no web-management