Specifications
Configuring Web Web Portal WebAAA
17-22 Configuring AAA for Network Users
Configuring Web Web Portal WebAAA
WebAAAsimplifiessecureaccesstounencryptedSSIDs.WhenauserrequestsaccesstoanSSID
orattemptstoaccessawebpagebeforeloggingontothenetwork,MSSservesaloginpagetothe
user’sbrowser.Aftertheuserentersausernameandpassword,MSSchecksthelocaldatabaseor
RADIUS
serversfortheuserinformation,andgrantsordeniesaccessbasedonwhethertheuser
informationisfound.
MSSredirectsanauthenticateduserbacktotherequestedwebpage,ortoapagespecifiedbythe
administrator.
WebAAA,likeothertypesofauthentication,isbasedonanSSIDorona
wiredauthentication
port.
YoucanuseWebAAAonbothencryptedandunencryptedSSIDs.IfyouuseWebAAAonan
encryptedSSID,youcanusestaticWEPorWPAwithPSKastheencryptiontype.
MSSprovidesanEnterasysNetworksloginpage,whichisusedbydefault.Youcanaddcustom
login
pagestotheRoamAboutswitch’snonvolatilestorage,andconfigureMSStoservethose
pagesinstead.
How Web Web Portal WebAAA Works
1. AWebAAAuserattemptstoaccessthenetwork.Forawirelessuser,thisbeginswhenthe
user’snetworkinterfacecard(NIC)associateswithanSSIDonaEnterasysradio.Forawired
authenticationuser,thisbeginswhentheuser’sNICsendsdataonthewiredauthentication
port.
2. MSSstartsaportal
sessionfortheuserandplacestheuserinaVLAN.
•Iftheuseriswireless(associatedwithanSSID),MSSassignstheusertotheVLANsetby
thevlan‐nameattributefortheSSID’sserviceprofile.
•Iftheuserisonawiredauthenticationport,theVLANisthe
oneassignedtotheweb‐
portal‐wireduser.
3. Theuseropensawebbrowser.ThewebbrowsersendsaDNSrequestfortheIPaddressofthe
homepage,oraURLrequestedbytheuser.
4. MSSdoesthefoll owing:
•InterceptstheDNSrequest,usestheMSSDNSproxytoobtain
theURL’sIPaddressfrom
thenetworkDNSserver,andsendstheaddresstotheuser’sbrowser.
•ServesaloginpagetotheWebAAAuser.(Alsosee“DisplayoftheLoginPage”on
page 17‐23.)
5. TheuserenterstheirusernameandpasswordintheWebAAAloginpage
6. MSSauthenticatesthe
userbycheckingRADIUSortheswitch’slocaldatabaseforthe
usernameandpasswordenteredbytheuser.Iftheuserinformationispresent,MSS
authorizestheuserbasedontheauthorizationattributessetfortheuser.
Note: Web Web Portal WebAAA replaces the WebAAA implementation in MSS Version
3.x. The previous implementation is deprecated beginning in MSS Version 4.0. During
upgrade from MSS Version 3.x, your 3.x WebAAA configuration is automatically
converted to a Web Web Portal WebAAA configuration.