ECS3510-26P_Management Guide R02

Table Of Contents
C
HAPTER
13
| Security Measures
Web Authentication
– 294 –
WEB AUTHENTICATION
Web authentication allows stations to authenticate and access the network
in situations where 802.1X or Network Access authentication are infeasible
or impractical. The web authentication feature allows unauthenticated
hosts to request and receive a DHCP assigned IP address and perform DNS
queries. All other traffic, except for HTTP protocol traffic, is blocked. The
switch intercepts HTTP protocol traffic and redirects it to a switch-
generated web page that facilitates user name and password
authentication via RADIUS. Once authentication is successful, the web
browser is forwarded on to the originally requested web page. Successful
authentication is valid for all hosts connected to the port.
N
OTE
:
RADIUS authentication must be activated and configured properly
for the web authentication feature to work properly. (See "Configuring
Local/Remote Logon Authentication" on page 277.)
N
OTE
:
Web authentication cannot be configured on trunk ports.
CONFIGURING GLOBAL
SETTINGS FOR WEB
AUTHENTICATION
Use the Security > Web Authentication (Configure Global) page to edit the
global parameters for web authentication.
CLI REFERENCES
"Web Authentication" on page 679
PARAMETERS
These parameters are displayed:
Web Authentication Status – Enables web authentication for the
switch. (Default: Disabled)
Note that this feature must also be enabled for any port where required
under the Configure Interface menu.
Session Timeout – Configures how long an authenticated session
stays active before it must re-authenticate itself. (Range: 300-3600
seconds, or 0 for disabled; Default: 3600 seconds)
Quiet Period – Configures how long a host must wait to attempt
authentication again after it has exceeded the maximum allowable
failed login attempts. (Range: 1-180 seconds; Default: 60 seconds)
Login Attempts – Configures the amount of times a supplicant may
attempt and fail authentication before it must wait the configured quiet
period. (Range: 1-3 attempts; Default: 3 attempts)