Configuring Web Authentication Options
The following steps configure the options available for Web Authentication.
- Complete the configuration steps described in Configuring Web Authentication.
- Enable RADIUS accounting.
- Create a list of trusted ports.
- Configure a host to be permanently authenticated.
- Configure any additional sites
that must be allowed Web Authentication access, for example, for certification.
Enter the
white-listcommand followed by an ID and an IPv4 address or the FQDN of the site. The ID can be a decimal value from 1 through 100. Create additional white-lists if needed, using one address or FQDN per command.Note: The IP address is resolved against the FQDN at the time of configuration only. The ICX device does not attempt to resolve the IP address during client authentication.The previous example adds an FQDN (www.commscope.com) to the servers and sites allowed access during Web Authentication on the ICX device.The previous example configures an IPv4 subnet as a Web Authentication white-list.The previous example configures an IPv4 server address as a Web Authentication white-list. - Configure the re-authentication
period (number of seconds a host remains authenticated before being logged
off).
You can specify 0 through 128000 seconds. The default is 28800 seconds, and 0 means the host is always authenticated and will never have to re-authenticate, except if an inactive period less than the re-authentication period is configured on the Web Authentication VLAN. If this is the case, the host becomes de-authenticated if there is no activity and the timer for the inactive period expires.
- Define the authentication cycle time.
- Limit the number of Web Authentication attempts.
- Set the block duration for Web Authentication attempts, specifying how many seconds users must wait before the next cycle of Web Authentication begins.
- Manually block a specific host from attempting Web Authentication.
- Limit the number of hosts that can be authenticated at a time.
- Define Domain Name System (DNS) filters that will restrict DNS queries from unauthenticated hosts to be forwarded explicitly to defined
- Enable forced reauthentication of the hosts if all the ports on the device go down.
- Configure the time duration after which the user-associated MAC address is aged out and reauthentication is enforced.
- Configure a redirect address for Web Authentication to prevent the display certificate mismatch error message.
- Configure an uplink port or LAG
to be used as the connection to your uplink switch.Note: The client for which the uplink port is configured must not be a member of the Flexible authentication VLAN.
- Clear authenticated hosts from the Web Authentication table.