Specifications

Configuring Web Web Portal WebAAA
17-22 Configuring AAA for Network Users
Configuring Web Web Portal WebAAA
WebAAAsimplifiessecureaccesstounencryptedSSIDs.WhenauserrequestsaccesstoanSSID
orattemptstoaccessawebpagebeforeloggingontothenetwork,MSSservesaloginpagetothe
usersbrowser.Aftertheuserentersausernameandpassword,MSSchecksthelocaldatabaseor
RADIUS
serversfortheuserinformation,andgrantsordeniesaccessbasedonwhethertheuser
informationisfound.
MSSredirectsanauthenticateduserbacktotherequestedwebpage,ortoapagespecifiedbythe
administrator.
WebAAA,likeothertypesofauthentication,isbasedonanSSIDorona
wiredauthentication
port.
YoucanuseWebAAAonbothencryptedandunencryptedSSIDs.IfyouuseWebAAAonan
encryptedSSID,youcanusestaticWEPorWPAwithPSKastheencryptiontype.
MSSprovidesanEnterasysNetworksloginpage,whichisusedbydefault.Youcanaddcustom
login
pagestotheRoamAboutswitch’snonvolatilestorage,andconfigureMSStoservethose
pagesinstead.
How Web Web Portal WebAAA Works
1. AWebAAAuserattemptstoaccessthenetwork.Forawirelessuser,thisbeginswhenthe
usersnetworkinterfacecard(NIC)associateswithanSSIDonaEnterasysradio.Forawired
authenticationuser,thisbeginswhentheusersNICsendsdataonthewiredauthentication
port.
2. MSSstartsaportal
sessionfortheuserandplacestheuserinaVLAN.
•Iftheuseriswireless(associatedwithanSSID),MSSassignstheusertotheVLANsetby
thevlannameattributefortheSSID’sserviceprofile.
•Iftheuserisonawiredauthenticationport,theVLANisthe
oneassignedtotheweb
portalwireduser.
3. Theuseropensawebbrowser.ThewebbrowsersendsaDNSrequestfortheIPaddressofthe
homepage,oraURLrequestedbytheuser.
4. MSSdoesthefoll owing:
•InterceptstheDNSrequest,usestheMSSDNSproxytoobtain
theURLsIPaddressfrom
thenetworkDNSserver,andsendstheaddresstotheusersbrowser.
•ServesaloginpagetotheWebAAAuser.(AlsoseeDisplayoftheLoginPageon
page 1723.)
5. TheuserenterstheirusernameandpasswordintheWebAAAloginpage
6. MSSauthenticatesthe
userbycheckingRADIUSortheswitch’slocaldatabaseforthe
usernameandpasswordenteredbytheuser.Iftheuserinformationispresent,MSS
authorizestheuserbasedontheauthorizationattributessetfortheuser.
Note: Web Web Portal WebAAA replaces the WebAAA implementation in MSS Version
3.x. The previous implementation is deprecated beginning in MSS Version 4.0. During
upgrade from MSS Version 3.x, your 3.x WebAAA configuration is automatically
converted to a Web Web Portal WebAAA configuration.