Specifications
Configuring Web Web Portal WebAAA
RoamAbout Mobility System Software Configuration Guide 17-23
7. Afterauthenticationandauthorizationarecomplete,MSSchangestheuser’ssessionfroma
portalsessionwiththenameweb‐portal‐ssidorweb‐portal‐wiredtoaWebAAAsessionwith
theuser’sname.Thesess ionremainsconnected,butisnowanidentity‐basedsessionforthe
userinsteadofaportal
session.
8. MSSredirectsthebrowsertotheURLinitiallyrequestedbytheuseror,iftheURLVSAis
configuredfortheuser,redirectstheusertotheURLspecifiedbytheVSA.
9. ThewebpagefortheURLtowhichtheuserisredirectedappearsintheuser’sbrowser
window.
Display of the Login Page
WhenaWebAAAclientfirsttriestoaccessawebpage,theclient’sbrowsersendsaDNSrequestto
obtaintheIPaddressmappedtothedomainnamerequestedbytheclient’sbrowser.The
RoamAboutSwitchproxiesthisDNSrequesttothenetwork’sDNSserver,thenproxiesthereply
backto
theclient.IftheDNSserverhasarecordfortherequestedURL,therequestissuccessful
andtheRoamAboutSwitchservesawebloginpagetotheclient.However,iftheDNSrequestis
unsuccessful,theRoamAboutSwitchdisplaysamessageinformingtheuserofthisanddoesnot
servetheloginpage.
IftheRoamAboutSwitchdoesnotreceiveareplytoaclient’sDNSrequest,theRoamAbout
SwitchspoofsareplytothebrowserbysendingtheRoamAboutSwitchswitch’sownIPaddress
astheresolutiontothebrowser’sDNSquery.TheRoamAboutSwitchalsoservestheweb
login
page.ThisbehaviorsimplifiesuseoftheWebAAAfeatureinnetworksthatdonothaveaDNS
server.However,iftherequestedURLisinvalid,thebehaviorgivestheappearancethatthe
requestedURLisvalid,sincethebrowserreceivesaloginpage.Moreover,thebrowsermight
cacheamapping
oftheinvalidURLtotheRoamAboutSwitchIPaddress.
IftheuserentersanIPaddress,mostbrowsersattempttocontacttheIPaddressdirectlywithout
usingDNS.SomebrowserseveninterpretnumericstringsasIPaddresses(indecimalnotation)if
avalidaddresscouldbeformedbyaddingdots
(dotteddecimalnotation).Forexample,
208194225132wouldbeinterpretedasavalidIPaddress,whenconvertedto208.194.225.132.
Note: MSS ignores the VLAN-Name or Tunnel-Private-Group-ID attribute associated with the user,
and leaves the user in the VLAN associated with the web-portal-ssid or web-portal-wired user.
These users are automatically created by MSS, and MSS associates the default VLAN with these
users by default. To associate a web-portal-ssid or web-portal-wired user with a VLAN other than
default, you must modify the user.