Displaying Web Authentication Information

You can use a number of show commands to display information about Web Authentication.

The following example displays the Web Authentication configuration details.

device(config-vlan-300-webauth)# show webauth

=============================================================================
WEB AUTHENTICATION (VLAN 300): Enable
attempt-max-num: 5 (Default)
host-max-num: 0 (Default)
block duration: 90 (Default)
cycle-time: 600 (Default)
port-down-authenticated-mac-cleanup: Enable (Default)
reauth-time: 28800 (Default)
authenticated-mac-age-time: 3600 (Default)
webauth-redirect-address: none (Default)
dns-filter: Disable (Default)
white-list: Disable (Default)
authentication mode: username and password (Default)
  authentication methods: radius
    Local user database name:  <none>
Radius accounting: Enable (Default)
Trusted port list: lag 1
Uplink port : lag 1
Secure Login (HTTPS): Disable
Web Page Customizations:
  Top (Header): Custom Text
        "Test"
  Bottom (Footer): Default Text
  Title: Default Text
  Login Button: Custom Text
        "Press Login"
  Web Page Logo: None (Default)
    align: left (Default)
  Web Page Terms and Conditions: None (Default)
Web Page UserId label: username
Web Page Password label: password to authenticate
Host statistics:
 Number of hosts dynamically authenticated: 0
 Number of hosts statically authenticated: 0
 Number of hosts dynamically blocked: 0
 Number of hosts statically blocked: 0
 Number of hosts authenticating: 0

The show webauth command by itself displays information for all VLANs on which Web Authentication is enabled. The show webauth vlan vlan-id command displays information for a specific VLAN.

The following example displays the Web Authentication configuration details for a specific VLAN.

device(config-vlan-300-webauth)# show webauth vlan 300

=============================================================================
WEB AUTHENTICATION (VLAN 300): Enable
attempt-max-num: 5 (Default)
host-max-num: 0 (Default)
block duration: 90 (Default)
cycle-time: 600 (Default)
port-down-authenticated-mac-cleanup: Enable (Default)
reauth-time: 28800 (Default)
authenticated-mac-age-time: 3600 (Default)
webauth-redirect-address: none (Default)
dns-filter: Disable (Default)
white-list: Disable (Default)
authentication mode: username and password (Default)
  authentication methods: radius
    Local user database name:  <none>
Radius accounting: Enable (Default)
Trusted port list: lag 1
Uplink port : lag 1
Secure Login (HTTPS): Disable
Web Page Customizations:
  Top (Header): Custom Text
        "Test"
  Bottom (Footer): Default Text
  Title: Default Text
  Login Button: Custom Text
        "Press Login"
  Web Page Logo: None (Default)
    align: left (Default)
  Web Page Terms and Conditions: None (Default)
Web Page UserId label: username
Web Page Password label: password to authenticate
Host statistics:
 Number of hosts dynamically authenticated: 0
 Number of hosts statically authenticated: 0
 Number of hosts dynamically blocked: 0
 Number of hosts statically blocked: 0
 Number of hosts authenticating: 0

The following example displays the text that has been configured for Web Authentication pages.

device(config-vlan-300-webauth)# show webauth vlan 300 webpage

=================================
Web Page Customizations (VLAN 300):
  Top (Header): Default Text
        "<h3>Welcome to Ruckus Networks Web Authentication Homepage</h3>"
  Bottom (Footer): Default Text
        "This network is restricted to authorized users only. Violators may be subjected to legal prosecution. Activity on this network is monitored and may be used as evidence in a court of law.<br>Copyright &copy;2013 Ruckus Networks."
  Title: Default Text
        "Web Authentication"
  Login Button: Default Text
        "Login"
  Web Page Logo: None (Default)
    align: left (Default)
  Web Page Terms and Conditions: None (Default)
Web Page UserId label: username
Web Page Password label: password to authenticate
Web Page UserId label not displaying
ICX7650-48P Router(config-vlan-300-webauth)#

The following example displays a list of hosts that are currently authenticated.

device# show webauth allowed-list
=============================================================================
VLAN 3: Web Authentication, Mode: I = Internal E = External
-------------------------------------------------------------------------------------
Web Authenticated List                Configuration   Authenticated Duration  Dynamic
MAC Address       User Name   mode    Static/Dynamic  HH:MM:SS                ACL 
-------------------------------------------------------------------------------------
000c.2973.a42b    ruckus      E       D               1 day, 11:33:16         acl1
1222.0a15.f045    super       E       D               1 day, 11:32:51         acl1  
1222.0a15.f044    foundry     E       D               1 day, 11:32:48         acl1  
1222.0a15.f043    ruckus      E       D               1 day, 11:32:47         acl1  
1222.0a15.f042    spirent     E       D               1 day, 11:32:4          acl1 

The following example displays a list of hosts that are trying to authenticate.

device# show webauth authenticating-list
==========================================================================
VLAN 3: Web Authentication, AuthMode: I=Internal E=External 
---------------------------------------------------------------------------
Web Authenticating List             # of Failed  Cycle Time Remaining
MAC Address        User Name  Mode  Attempts     HH:MM:SS
---------------------------------------------------------------------------
000c.2973.a42b     N/A        E     0            00:01:36          

The following example displays a list of hosts that are currently blocked from any Web Authentication attempt.

device# show webauth blocked-list
=============================================================================
VLAN 3: Web Authentication, AuthMode: I=Internal E=External 
-------------------------------------------------------------------------------
Block List                       Configuration       Block Duration Remaining
MAC Address     User Name  Mode  Static/Dynamic      HH:MM:SS
-------------------------------------------------------------------------------
000c.2973.a42b  User1      E     D                   00:00:04 

The following example displays a list of all local user databases configured on the ICX switch and the number of users in each database.

device# show local-userdb 
=============================================================================
Local User Database Name           : My_Database
Number of users in the database    : 4
=============================================================================
Local User Database Name           : test
Number of users in the database    : 3
=============================================================================
Local User Database Name           : test123
Number of users in the database    : 3

The following example displays a list of all users in a particular local user database.

device# show local-userdb test
=============================================================================
Local User Database : test 
Username                        Password                                     
--------                        --------                                     
user1                           $e$&Z9'%*&+                                  
user2                           $e$,)A=)65N,%-3*%1?@U                        
user3                           $e$5%&-5%YO&&A1%6%<@U                        

As shown in the example, passwords are encrypted in the command output.

The following example displays current passcodes if the passcode Web Authentication mode is enabled.

device# show webauth vlan 25 passcode 
Current Passcode : 1389
This passcode is valid for 35089 seconds

The following example displays the details of the captive portal profile configured on the device.

device(config)# show captive-portal cp-ruckus
Configured Captive Portal Profile Details :
  cp-name               :cp-ruckus
  virtual-ip            :10.21.240.42
  virtual-port          :80
  login-page            :/enroll/ruckus/guestlogin