Web Authentication Options

Web Authentication also offers the following configuration options:

  • RADIUS accounting
  • Trusted ports
  • Permanently authenticated hosts
  • White-lists
  • Re-authentication period
  • Web authentication time limit
  • Maximum web authentication attempts
  • Clearing of authenticated hosts from the Web Authentication table
  • Block duration for too many authentication attempts
  • Manual blocking of a specific host
  • Limiting the number of authenticated hosts
  • Filtering DNS queries
  • Forced re-authentication
  • Web authorization redirect and redirect page authentication
  • Honoring the RADIUS-returned VLAN

RADIUS Accounting for Web Authentication

When Web Authentication is enabled, you can enable RADIUS accounting using the accounting command to record login (start) and logout (stop) events per host. The information is sent to a RADIUS server. Note that packet and byte count is not supported.

Trusted Ports

You can configure certain ports of a Web Authentication VLAN as trusted ports using the trust-port command. All hosts connected to the trusted ports need not authenticate and are automatically allowed access to the network.

Permanently Authenticated Hosts

Certain hosts, such as a DHCP server, gateways, and printers, may need to be permanently authenticated. Typically, these hosts are managed by the network administrator and are considered to be authorized hosts. Some of these hosts (such as printers) may not have a web browser and will not be able to perform Web Authentication. Such hosts can be permanently authenticated using the add mac command. You can set the duration to specify how long the MAC address remains authenticated. The default is the time configured using the reauth-time command. To keep the host permanently authenticated, set the duration to 0 so that the Web Authentication for the MAC address does not expire.

Instead of simply entering a duration for how long the MAC address remains authenticated, you can specify the MAC address to be added by the specified port that is a member of the VLAN.

Note: If a MAC address is statically configured, it will not be dynamically configured on any port.

IP Addresses and Domain Names Allowed During Web Authentication

You can create a list of preconfigured hosts and servers that are allowed access during Web Authentication. This capability is typically referred to as a walled garden. Depending on the Web Authentication processes followed by users, communication with more than one host or server may be required during authentication. A typical example would be when Web Authentication requires certificate exchanges with a specific host.

Web Authentication automatically allows DHCP or DNS packets, depending on the protocol used, and allows access to the Captive Portal server used for authentication. Any other sites that may be required can be configured as white-lists at the VLAN level. An IPv4 address with or without a subnet mask or a fully qualified domain name (FQDN) can be configured as a Web Authentication white-list. Up to 100 white-lists can be configured for Web Authentication.

Re-authentication Period

After a successful authentication, a user remains authenticated for a duration of time. At the end of this duration, the host is automatically logged off. The user must be re-authenticated. The number of seconds a host remains authenticated before being logged off can be configured using the reauth-time command.

Web Authentication Cycle

You can specify the amount of time allowed for a user to authenticate successfully, starting from the first Login attempt on the Login page. When the time expires, the user must enter a valid URL again to display the Web Authentication welcome page.

Limiting the Number of Web Authentication Attempts

You can use the attempt-max-num command to limit the number of times a user enters an invalid username and password during the Web Authentication cycle. If the user exceeds the limit, the user is blocked for the time defined by the block duration command and is redirected to the exceeded allowable attempts web page.

Clearing Authenticated Hosts from the Web Authentication Table

You can clear dynamically authenticated hosts from the Web Authentication table. All authenticated hosts in a Web Authentication VLAN can be cleared using the clear webauth vlan vlan-id authenticated-mac command. If you want to clear a particular host in a Web Authentication VLAN, use the clear webauth vlan vlan-id authenticated-mac mac-address command.

Block Duration for Web Authentication Attempts

You can use the block duration command to specify how long users must wait to try again after exceeding the number of allowed Web Authentication attempts.

To unblock the MAC address, wait until the block duration timer expires, or enter the clear webauth vlan vlan-id block-mac mac-address command.

Manually Blocking a Specific Host

A host can be temporarily or permanently blocked from attempting Web Authentication block mac mac-address duration time command.

You can specify the duration from 0 through 128000 seconds. The default is the current value of the block duration command. To keep the MAC address permanently blocked, set the block mac mac-address duration to 0.

Limiting the Number of Authenticated Hosts

You can limit the number of hosts that are authenticated at a time by entering the host-max-num command. You can specify from 0 through 8192 hosts. The default value is 0, which means that there is no limit to the number of hosts that can be authenticated. The maximum of 8192 is the maximum number of MAC addresses the device supports. When the maximum number of hosts has been reached, the ICX switch redirects any new host that has been authenticated successfully to the maximum host web page.

Filtering DNS Queries

Many of the Web Authentication solutions allow DNS queries to be forwarded from unauthenticated hosts. To eliminate the threat of forwarding DNS queries from unauthenticated hosts to unknown or untrusted servers (also known as domain-casting), you can restrict DNS queries from unauthenticated hosts to be forwarded explicitly to defined servers by defining DNS filters using the dns-filter command. Any DNS query from an unauthenticated host to a server that is not defined in a DNS filter is dropped. Only DNS queries from unauthenticated hosts are affected by DNS filters; authenticated hosts are not. If the DNS filters are not defined, then any DNS queries can be made to any server. You can have up to four DNS filters and specify a number from 1 through 4 to identify the DNS filter.

You can specify the IP address and subnet mask of unauthenticated hosts that will be forwarded to the unknown or untrusted servers.

You can use a wildcard for the filter. The wildcard is in dotted-decimal notation (IP address) format. It is a four-part value, where each part is 8 bits (one byte) separated by dots, and each bit is a one or a zero. Each part is a number ranging from 0 through 255 (for example, 0.0.0.255). Zeros in the mask mean the packet source address must match the IP address. Ones mean any value matches.

Forcing Re-authentication When Ports Are Down

By default, the device checks the link state of all ports that are members of the Web Authentication VLAN and if the state of all the ports is down, then the device forces all authenticated hosts to re-authenticate. That is, the port-down-authenticated-mac-cleanup command that enforces re-authentication of all authenticated hosts when all the ports are down is enabled by default. However, hosts that were authenticated using the add mac command will remain authenticated; they are not affected by the port-down-authenticated-mac-cleanup command.

Forcing Re-authentication After an Inactive Period

You can force Web Authentication hosts to be re-authenticated if they have been inactive for a period of time. The inactive duration is calculated by adding the mac-age-time that has been configured for the device and the configured authenticated-mac-age-time. (The mac-age-time command defines how long a port address remains active in the address table.) If the authenticated host is inactive for the sum of these two values, the host is forced to be re-authenticated.

In the authenticated-mac-age-time command, you can specify a value from 0 through the value entered for the reauth-time command. The default is 3600 seconds.

Defining the Web Authorization Redirect Address

When a user enters a valid URL, the user is redirected to the Web Authentication welcome page. By default, the Web Authentication address returned to the browser is the IP address of the ICX switch. To prevent the display of error messages saying that the certificate does not match the name of the site, you can change this address so that it matches the name on the security certificates using the webauth-redirect-address command.

Entering "my.domain.net" redirects the browser to https://my.domain.net/ when the user enters a valid URL on the web browser.

You can enter any value up to 64 alphanumeric characters for the string, but entering the name on the security certificate prevents the display of error messages saying that the security certificate does not match the name of the site.

Customizing the Web Authentication Redirect Page

The Web Authentication login page presented by ICX devices (except when the external captive portal is used) contains the prompts for authentication credentials. These prompts are labeled UserId and Password by default. The administrator can remove the UserId label and associated entry field from the webpage. The administrator can also rename the UserId and Password labels on the authentication page.

Honoring the RADIUS-Returned VLAN

Note: Honoring the RADIUS-returned VLAN applies to network segmentation deployments only.
If the RADIUS server returns a VLAN attribute when client authentication is successful, the client's connected access port is moved to the RADIUS-returned VLAN, and the uplink port is also added to the RADIUS-returned VLAN. The resulting configuration is saved. Any clients that connect to the uplink port will be allowed access.
Note: When an uplink port is configured for Web Authentication, the ICX device sets a "network segmentation enabled" flag that is included with any AAA RADIUS server request. As a result, a RUCKUS Cloudpath server recognizes the ICX switch as network segmentation-eligible. When the 'remove-userid-label' option is configured for Web Authentication, the ICX device sends the host MAC address in the username attribute of the AAA RADIUS server request. Refer to Customizing Web Authentication Pages for configuration options.