Configuring Web Authentication

Complete the following steps to configure Web Authentication on a device.

  1. Enter the global configuration mode.
    device# configure terminal
    
  2. Set up any global configuration required for the FastIron switch, RADIUS server, Web server and other servers.
    • Assign an IP address to a virtual interface (VE) for each VLAN on which Web Authentication will be enabled.
    device(config)# vlan 10
    device(config-vlan-10)# untagged e 1/1/1 to 1/1/10
    device(config-vlan-10)# interface ve10
    device(config-vif-10)# ip address 10.1.1.101/24
  3. Configure the RADIUS server and other servers if Web Authentication will use a RADIUS server. By default, Web Authentication uses a RADIUS server to authenticate host usernames and passwords, unless it is configured to use a local user database.
    device(config)# radius-server host 10.1.1.8 auth-port 1812 acct-port 1813 default key 2 $d3NpZ0BVXFpJ web-auth 
    
    
    Note: Remember the RADIUS key you entered. You will need this key when you configure your RADIUS server.
  4. Create a Web Authentication VLAN.
    device(config)# vlan 10
    device(config-vlan-10)# webauth
    FastIron devices support a maximum of two Web Authentication VLANs.
  5. (Optional) Configure Web Authentication to use secure (HTTPS) or non-secure (HTTP) login and logout pages.
    Web management access over HTTPS is enabled by default. For TPM-enabled devices, TPM certificates are available by default to establish encrypted communication between the server and client. For more information about digital certificates for web access, refer ICX Digital Certificates.

    To enable the non-secure web server on the FastIron switch, enter the following commands.

    device(config)# web-management HTTP
    device(config)# vlan 10
    device(config-vlan-10)# webauth
    device(config-vlan-10-webauth)# no secure-login
    

    To enable the secure web server on the FastIron switch, enter the following commands.

    device(config)# web-management HTTPS
    device(config)# vlan 10
    device(config-vlan-10)# webauth
    device(config-vlan-10-webauth)# secure-login
  6. Enable Web Authentication on the VLAN.
    device(config-vlan-10-webauth)# enable
    

    When the Web Authentication is enabled, the CLI changes to the Web Authentication configuration mode. In the example, VLAN 10 requires hosts to be authenticated using Web Authentication before they can forward traffic.

  7. Configure the Web Authentication mode:
    • Username and password: Blocks users from accessing the device until they enter a valid username and password on a web login page. By default "username-password" is the authentication method. For more information, refer to Using Local User Databases.
    • Passcode: Blocks users from accessing the device until they enter a valid passcode on a web login page. For more information, refer to Passcodes for User Authentication.
    • captive-portal: Authenticates the users in a VLAN through external Web Authentication (Captive Portal user authentication) mode. For more information, refer to Configuring Captive Portal (External Web Authentication)
    • None: Blocks users from accessing the device until they press the Login button. A username and password or passcode is not required. For more information, refer to Automatic Authentication.
  8. Configure other Web Authentication options (refer to Web Authentication Options).