Configuring Web Authentication Options

The following steps configure the options available for Web Authentication.

  1. Complete the configuration steps described in Configuring Web Authentication.
  2. Enable RADIUS accounting.
    device(config-vlan-10-webauth)# accounting
    
  3. Create a list of trusted ports.
    device(config-vlan-10-webauth)# trust-port ethernet 1/1/3
    device(config-vlan-10-webauth)# trust-port ethernet 1/1/6 to 1/1/10
    
  4. Configure a host to be permanently authenticated.
    device(config-vlan-10-webauth)# add mac 0000.00eb.2d14 duration 0
    
  5. Configure any additional sites that must be allowed Web Authentication access, for example, for certification. Enter the white-list command followed by an ID and an IPv4 address or the FQDN of the site. The ID can be a decimal value from 1 through 100. Create additional white-lists if needed, using one address or FQDN per command.
    Note: The IP address is resolved against the FQDN at the time of configuration only. The ICX device does not attempt to resolve the IP address during client authentication.
    device(config-vlan-10-webauth)# white-list 10 www.commscope.com
    The previous example adds an FQDN (www.commscope.com) to the servers and sites allowed access during Web Authentication on the ICX device.
    device(config-vlan-10-webauth)# white-list 30 192.168.0.1/24
    The previous example configures an IPv4 subnet as a Web Authentication white-list.
    device(config-vlan-10-webauth)# white-list 35 192.168.12.2 255.255.255.0
    The previous example configures an IPv4 server address as a Web Authentication white-list.
  6. Configure the re-authentication period (number of seconds a host remains authenticated before being logged off).
    device(config-vlan-10-webauth)# reauth-time 10
    

    You can specify 0 through 128000 seconds. The default is 28800 seconds, and 0 means the host is always authenticated and will never have to re-authenticate, except if an inactive period less than the re-authentication period is configured on the Web Authentication VLAN. If this is the case, the host becomes de-authenticated if there is no activity and the timer for the inactive period expires.

  7. Define the authentication cycle time.
    device(config-vlan-10-webauth)# cycle time 20
    
  8. Limit the number of Web Authentication attempts.
    device(config-vlan-10-webauth)# attempt-max-num 4
    
  9. Set the block duration for Web Authentication attempts, specifying how many seconds users must wait before the next cycle of Web Authentication begins.
    device(config-vlan-10-webauth)# block duration 4
    
  10. Manually block a specific host from attempting Web Authentication.
    device(config-vlan-10-webauth)# block mac 0000.00d1.0a3d duration 4
    
  11. Limit the number of hosts that can be authenticated at a time.
    device(config-vlan-10-webauth)# host-max-num 300
    
  12. Define Domain Name System (DNS) filters that will restrict DNS queries from unauthenticated hosts to be forwarded explicitly to defined
    device(config-vlan-10-webauth)# dns-filter 1 10.166.2.44/24
    
  13. Enable forced reauthentication of the hosts if all the ports on the device go down.
    device(config-vlan-10-webauth)# port-down-authenticated-mac-cleanup
    
  14. Configure the time duration after which the user-associated MAC address is aged out and reauthentication is enforced.
    device(config-vlan-10-webauth)# authenticated-mac-age-time 300
    
  15. Configure a redirect address for Web Authentication to prevent the display certificate mismatch error message.
    device(config-vlan-10-webauth)# webauth-redirect-address my.domain.net
    
  16. Configure an uplink port or LAG to be used as the connection to your uplink switch.
    Note: The client for which the uplink port is configured must not be a member of the Flexible authentication VLAN.
    device(config-vlan-10-webauth)# uplink-port ethernet 1/1/1
    device(config-vlan-10-webauth)# uplink-port lag 2
  17. Clear authenticated hosts from the Web Authentication table.
    device# clear webauth vlan 25 authenticated-mac