Specifications

Configuring Port Web Authentication (PWA)
21-56 Security Configuration
Configuring Port Web Authentication (PWA)
About PWA
PWAprovidesawayofauthenticatingusersbeforeallowinggeneralaccesstothenetwork.A
PWAusersaccesstothenetworkisrestricteduntilaftertheusersuccessfullylogsinviaaweb
browserusingtheEnterasysNetworks’webbasedsecurityinterface.TheSecureStackC3device
willvalidatealllogincredentials
fromtheuserwithaRADIUSserverbeforeallowingnetwork
access.
PWAisanalternativeto802.1XandMACauthentication.Itallowsonlytheessentialprotocols
andservicesrequiredbytheauthenticationprocessbetweentheendstationandthenetwork.All
othertrafficisdiscarded.Whenauserisinthe
unauthenticatedstate,anyusertrafficrequesting
networkresourceswillnotbeallowed.
Tologonusing PWA,theusermakesarequestviaawebbrowserforthePWAwebpageoris
automaticallyredirectedtothisloginpageafterrequestingaURLinabrowser.
Dependingupontheauthenticated
stateoftheuser,aloginpageoralogoutpagewilldisplay.
Whenausersubmitsusernameandpassword,theswitchthenauthenticatestheuserviaa
preconfiguredRADIUSserver.Iftheloginissuccessful,thentheuserwillbegrantedfullnetwork
accessaccordingtotheuserspolicyconfiguration
ontheswitch.
Purpose
Toreview,enable,disable,andconfigurePortWebAuthentication(PWA).
Commands
ThecommandsneededtoreviewandconfigurePWAarelistedbelow:
Note: One user per PWA-configured port can be authenticated on SecureStack C3 devices. Only
one method of authentication can be deployed per port.
For information about... Refer to page...
show pwa 21-57
set pwa 21-58
show pwa banner 21-59
set pwa banner 21-60
clear pwa banner 21-60
set pwa displaylogo 21-61
set pwa ipaddress 21-61
set pwa protocol 21-62
set pwa guestname 21-62
clear pwa guestname 21-63
set pwa guestpassword 21-63
set pwa gueststatus 21-64