Configuring Passcode Authentication

The following steps configure the device to use the passcode authentication mode.

  1. Complete the configuration steps described in Configuring Web Authentication.
  2. Create static passcodes.
    device(config-vlan-10-webauth)# auth-mode passcode static 56127
  3. Enable passcode authentication.
    device(config-vlan-10-webauth)# auth-mode passcode
    
    This command enables Web Authentication to use dynamically created passcodes to authenticate users in the VLAN. If the configuration includes static passcodes, they are used in conjunction with dynamically created passcodes.
  4. (Optional) Configure the length of dynamically generated passcodes.
    device(config-vlan-10-webauth)# auth-mode passcode length 10
    
    By default, dynamically generated passcodes are 4 digits in length; for example, 0123. If desired, you can increase the passcode length to up to 16 digits.
  5. (Optional) Configure one of the following passcode refresh methods:
    • Configure the duration of time (in minutes) after which passcodes must be refreshed.
      device(config-vlan-10-webauth)# auth-mode passcode refresh-type duration 4320
      
    • Configure the time of day at which the passcodes must be refreshed.
      device(config-vlan-10-webauth)# auth-mode passcode refresh-type time 6:00
    By default, passcodes will be refreshed at 00:00 (12:00 midnight). You can configure up to 24 refresh periods in a 24-hour period. Each must be at least five minutes apart.
    1. (Optional) Reset the passcode refresh time of day configuration and revert back to the default time of 00:00 (12:00 midnight).
      device(config-vlan-10-webauth)# auth-mode passcode refresh-type time delete-all
      
  6. (Optional) Configure a grace period for an expired passcode.
    device(config-vlan-10-webauth)# auth-mode passcode grace-period 5
    
  7. (Optional) Delete all expired passcodes that are currently in the grace period.
    device(config-vlan-10-webauth)# auth-mode passcode flush-expired
    
  8. (Optional) Disable and re-enable passcode log.
    A Syslog message and SNMP trap message are generated every time a new passcode is generated and passcode authentication is attempted,. This is the default behavior. If desired, you can disable passcode-related Syslog messages or SNMP trap messages, or both.
    device(config-vlan-10-webauth)# no auth-mode passcode log syslog
    device(config-vlan-10-webauth)# auth-mode passcode log syslog
    device(config-vlan-10-webauth)# no auth-mode passcode log snmp-trap
    device(config-vlan-10-webauth)# auth-mode passcode log snmp-trap
    
  9. (Optional) Retransmit the current passcode to a Syslog message or SNMP trap.
    device(config-vlan-10-webauth)# auth-mode passcode resend-log
    
    The switch retransmits the current passcode only. Passcodes that are in the grace period are not sent.
  10. (Optional) Manually refresh the passcode.
    device(config-vlan-10-webauth)# auth-mode passcode generate