Web Authentication Options
Web Authentication also offers the following configuration options:
- RADIUS accounting
- Trusted ports
- Permanently authenticated hosts
- White-lists
- Re-authentication period
- Web authentication time limit
- Maximum web authentication attempts
- Clearing of authenticated hosts from the Web Authentication table
- Block duration for too many authentication attempts
- Manual blocking of a specific host
- Limiting the number of authenticated hosts
- Filtering DNS queries
- Forced re-authentication
- Web authorization redirect and redirect page authentication
- Honoring the RADIUS-returned VLAN
RADIUS Accounting for Web Authentication
When Web Authentication is enabled, you can
enable RADIUS accounting using the accounting command to record login (start) and logout (stop) events per host.
The information is sent to a RADIUS server. Note that packet and byte count is not
supported.
Trusted Ports
You can configure certain ports of a Web
Authentication VLAN as trusted ports using the trust-port command. All
hosts connected to the trusted ports need not authenticate and are automatically allowed
access to the network.
Permanently Authenticated Hosts
Certain hosts, such as a DHCP server, gateways,
and printers, may need to be permanently authenticated. Typically, these hosts are
managed
by the network administrator and are considered to be authorized hosts. Some of these
hosts
(such as printers) may not have a web browser and will not be able to perform Web
Authentication. Such hosts can be permanently authenticated using the add mac command. You can set the
duration to specify how long the MAC address remains authenticated. The default is
the time
configured using the reauth-time command. To keep the host
permanently authenticated, set the duration to 0 so that the Web Authentication for the MAC
address does not expire.
Instead of simply entering a duration for how long the MAC address remains authenticated, you can specify the MAC address to be added by the specified port that is a member of the VLAN.
IP Addresses and Domain Names Allowed During Web Authentication
You can create a list of preconfigured hosts and servers that are allowed access during Web Authentication. This capability is typically referred to as a walled garden. Depending on the Web Authentication processes followed by users, communication with more than one host or server may be required during authentication. A typical example would be when Web Authentication requires certificate exchanges with a specific host.
Web Authentication automatically allows DHCP or DNS packets, depending on the protocol used, and allows access to the Captive Portal server used for authentication. Any other sites that may be required can be configured as white-lists at the VLAN level. An IPv4 address with or without a subnet mask or a fully qualified domain name (FQDN) can be configured as a Web Authentication white-list. Up to 100 white-lists can be configured for Web Authentication.
Re-authentication Period
After a successful authentication, a user remains
authenticated for a duration of time. At the end of this duration, the host is automatically
logged off. The user must be re-authenticated. The number of seconds a host remains
authenticated before being logged off can be configured using the reauth-time command.
Web Authentication Cycle
You can specify the amount of time allowed for a user to authenticate successfully, starting from the first Login attempt on the Login page. When the time expires, the user must enter a valid URL again to display the Web Authentication welcome page.
Limiting the Number of Web Authentication Attempts
You can use the attempt-max-num command to limit
the number of times a user enters an invalid username and password during the Web
Authentication cycle. If the user exceeds the limit, the user is blocked for the time
defined by the block
duration command and is redirected to the exceeded allowable attempts web page.
Clearing Authenticated Hosts from the Web Authentication Table
You can clear dynamically authenticated
hosts from the Web Authentication table. All authenticated hosts in a Web Authentication
VLAN can be cleared using the clear
webauth vlan
vlan-id
authenticated-mac command. If you want to clear a particular host in a
Web Authentication VLAN, use the clear webauth vlan
vlan-id
authenticated-mac
mac-address command.
Block Duration for Web Authentication Attempts
You can use the block duration command to specify how long users must
wait to try again after exceeding the number of allowed Web Authentication attempts.
To unblock the MAC address, wait until the block
duration timer expires, or enter the clear webauth vlan
vlan-id
block-mac
mac-address command.
Manually Blocking a Specific Host
A host can be temporarily or permanently blocked
from attempting Web Authentication block mac
mac-address
duration
time command.
You can specify the duration from 0 through
128000 seconds. The default is the current value of the block duration command. To keep
the MAC address permanently blocked, set the block mac
mac-address
duration to 0.
Limiting the Number of Authenticated Hosts
You can limit the number of hosts that are
authenticated at a time by entering the host-max-num command. You can
specify from 0 through 8192 hosts. The default value is 0, which means that there
is no
limit to the number of hosts that can be authenticated. The maximum of 8192 is the
maximum
number of MAC addresses the device supports. When the maximum number of hosts has
been
reached, the ICX switch redirects any new host that has been authenticated successfully
to
the maximum host web page.
Filtering DNS Queries
Many of the Web Authentication solutions allow
DNS queries to be forwarded from unauthenticated hosts. To eliminate the threat of
forwarding DNS queries from unauthenticated hosts to unknown or untrusted servers
(also
known as domain-casting), you can restrict DNS queries from unauthenticated hosts
to be
forwarded explicitly to defined servers by defining DNS filters using the dns-filter command. Any DNS query
from an unauthenticated host to a server that is not defined in a DNS filter is dropped.
Only DNS queries from unauthenticated hosts are affected by DNS filters; authenticated
hosts
are not. If the DNS filters are not defined, then any DNS queries can be made to any
server.
You can have up to four DNS filters and specify a number from 1 through 4 to identify
the
DNS filter.
You can specify the IP address and subnet mask of unauthenticated hosts that will be forwarded to the unknown or untrusted servers.
You can use a wildcard for the filter. The wildcard is in dotted-decimal notation (IP address) format. It is a four-part value, where each part is 8 bits (one byte) separated by dots, and each bit is a one or a zero. Each part is a number ranging from 0 through 255 (for example, 0.0.0.255). Zeros in the mask mean the packet source address must match the IP address. Ones mean any value matches.
Forcing Re-authentication When Ports Are Down
By default, the device checks the link state
of all ports that are members of the Web Authentication VLAN and if the state of all
the
ports is down, then the device forces all authenticated hosts to re-authenticate.
That is,
the port-down-authenticated-mac-cleanup command that enforces re-authentication of
all authenticated hosts when all the ports are down is enabled by default. However,
hosts
that were authenticated using the add mac command will remain authenticated; they are not affected by the
port-down-authenticated-mac-cleanup command.
Forcing Re-authentication After an Inactive Period
You can force Web Authentication hosts to
be re-authenticated if they have been inactive for a period of time. The inactive
duration
is calculated by adding the mac-age-time that has been configured for the device and the configured
authenticated-mac-age-time. (The mac-age-time command defines how
long a port address remains active in the address table.) If the authenticated host
is
inactive for the sum of these two values, the host is forced to be re-authenticated.
In the authenticated-mac-age-time
command, you can specify a value from 0 through the value entered for the reauth-time command. The default
is 3600 seconds.
Defining the Web Authorization Redirect Address
When a user enters a valid URL, the user is
redirected to the Web Authentication welcome page. By default, the Web Authentication
address returned to the browser is the IP address of the ICX switch. To prevent the
display
of error messages saying that the certificate does not match the name of the site,
you can
change this address so that it matches the name on the security certificates using
the
webauth-redirect-address
command.
Entering "my.domain.net" redirects the browser to https://my.domain.net/ when the user enters a valid URL on the web browser.
You can enter any value up to 64 alphanumeric characters for the string, but entering the name on the security certificate prevents the display of error messages saying that the security certificate does not match the name of the site.
Customizing the Web Authentication Redirect Page
The Web Authentication login page presented by ICX devices (except when the external captive portal is used) contains the prompts for authentication credentials. These prompts are labeled UserId and Password by default. The administrator can remove the UserId label and associated entry field from the webpage. The administrator can also rename the UserId and Password labels on the authentication page.
Honoring the RADIUS-Returned VLAN