Prerequisite Configuration

The following steps must be completed to enable access to the Web Management Interface.
  1. Connect a PC by way of a serial connection to the device using the console port. Use a terminal program such as PuTTY to access the command line interface (CLI).
    If the switch is already connected to a network, the switch will automatically receive its IP configuration through DHCP. To check the IP configuration of the switch, use the show ip command.
    If the switch is not connected to a network or you want to assign an IP address manually, use the commands described in step 2; otherwise, go to step 3.
  2. Assign an IP address to the device using the command line interface (CLI).
    device(config)# interface management 1
    device(config-if-mgmt1)# ip address 10.37.71.212/24
    device(config)# ip route 0.0.0.0 0.0.0.0 172.26.64.1
    
    Alternatively, the IP address can also be assigned on a router interface (for example, VE 1). For more information on assigning IP addresses for a device, refer to the RUCKUS FastIron Layer 3 Routing Configuration Guide.
  3. Configure a user account with a password and privilege levels for authentication purposes.
    You can also use external AAA servers (RADIUS and TACACS+) to perform user authentication. To do so, you must configure the RADIUS server host and RADIUS server key and the TACACS+ server host and TACACS+ server key. For more information, refer to the RUCKUS FastIron Security Configuration Guide.
    device(config)# username user1 privilege 0 password xpassx
    Depending on the privilege level defined for the user account, the user can have complete read-and-write access or read-only permission while using the Web Management Interface.
  4. Configure device authentication methods to identify a user by verifying the authentication credentials before access is granted.
    device(config)# aaa authentication web-server default local radius tacacs+
    For more information about the authentication method list, refer to the RUCKUS FastIron Security Configuration Guide.
  5. (Optional) Enable web management access. By default, global web management and web management access over HTTPS are enabled. Disabling web management automatically turns off both HTTP and HTTPS services.
    For TPM-enabled devices, TPM certificates are available by default to establish encrypted communication between the server and the client.
    Note: Upon upgrade to FastIron 09.0.00 or later, the web management HTTP configuration in a pre-09.0.00 image will be disabled, and web management access over HTTPS is enabled by default.
    You can also import a digital certificate issued by a third-party certificate using the copy tftp flash 192.168.9.210 certfile certificate-data-file command. ICX devices that are not TPM-capable, for example, legacy devices deployed to the field, may use an auto-generated non-TPM certificate. Non-TPM certificates are stored on the device in flash memory.

    Once a valid certificate is present, it remains available, unless the user erases the startup configuration or uses a command to zeroize (clear) the certificate.

    When no certificate is present, the RUCKUS ICX device is unable to use applications that require a certificate.

    When more than one certificate is stored in the RUCKUS ICX device, the device selects the certificate for use based on the following order of priority:

    Removing this option from the list "User-imported (SSL) certificate"
    1. TPM certificate
    2. Non-TPM (auto-generated legacy) certificate

    For more information on ICX digital certificates, refer to the RUCKUS FastIron Security Configuration Guide.
  6. View the web login details.
    device# show web
    Web management: Enabled
    HTTP server status: Disabled
    HTTPS server status: Enabled
    
    Web session management:
    User    Privilege     IP address        Timeout(secs) CONNECTION
    admin   READ-WRITE    10.37.71.212/24   10            HTTPS