Planet Technology SGSW-2840P Switch User Manual


 
User’s Manual of SGSD-1022 / SGSD-1022P
SGSW-2840 / SGSW-2840P
480
Console#
5.13.3 Web Authentication
Web authentication allows stations to authenticate and access the network in situations where 802.1X or Network Access
authentication methods are infeasible or impractical. The web authentication feature allows unauthenticated hosts to request
and receive a DHCP assigned IP address and perform DNS queries. All other traffic, except for HTTP protocol traffic, is blocked.
The switch intercepts http protocol traffic and redirects it to a switch-generated web page that facilitates username and
password authentication via RADIUS. Once authentication is successful, the web browser is forwarded on to the originally
requested web page. .
1. RADIUS authentication must be activated and configured properly for the
web authentication feature to work properly. (See “RADIUS Client” on page
4-88.)
2. Web authentication cannot be configured on trunk ports.
Command Function Mode
web-auth login-attempts Defines the limit for failed web authentication login attempts GC
web-auth quiet-period Defines the amount of time to wait after the limit for failed login
attempts is exceeded.
GC
web-auth session-timeout Defines the amount of time a session remains valid GC
web-auth system-auth-control Enables web authentication globally for the switch GC
web-auth Enables web authentication for an interface IC
web-auth re-authenticate (Port) Ends all web authentication sessions on the port andforces the
users to re-authenticate
PE
web-auth re-authenticate (IP) Ends the web authentication session associated with the
designated IP address and forces the user to re-authenticate
PE
show web-auth Displays global web authentication parameters PE
show web-auth interface Displays interface-specific web authenticationparameters and
statistics
PE
show web-auth summary Displays a summary of web authentication port parameters and
statistics
PE
Table 5-43 Web Authentication
web-auth login-attempts
This command defines the limit for failed web authentication login attempts. After the limit is reached, the switch refuses further
login attempts until the quiet time expires. Use the no form to restore the default.