beautypg.com

Web authentication, Configuring global settings for web authentication, Figure 185 s – Brocade 6910 Ethernet Access Switch Configuration Guide (Supporting R2.2.0.0) User Manual

Page 918

background image

862

Brocade 6910 Ethernet Access Switch Configuration Guide

53-1002651-02

42

Web Authentication

FIGURE 185

Showing User Accounts

Web Authentication

Web authentication allows stations to authenticate and access the network in situations where
802.1X or Network Access authentication are infeasible or impractical. The web authentication
feature allows unauthenticated hosts to request and receive a DHCP assigned IP address and
perform DNS queries. All other traffic, except for HTTP protocol traffic, is blocked. The switch
intercepts HTTP protocol traffic and redirects it to a switch-generated web page that facilitates user
name and password authentication via RADIUS. Once authentication is successful, the web
browser is forwarded on to the originally requested web page. Successful authentication is valid for
all hosts connected to the port.

NOTE

RADIUS authentication must be activated and configured properly for the web authentication
feature to work properly. (See

“Configuring Local/Remote Logon Authentication”

on page 848.)

Web authentication cannot be configured on trunk ports.

Configuring Global Settings for Web Authentication

Use the Security > Web Authentication (Configure Global) page to edit the global parameters for
web authentication.

CLI References

“Web Authentication”

on page 206

Parameters
These parameters are displayed:

Web Authentication Status – Enables web authentication for the switch. (Default: Disabled)
Note that this feature must also be enabled for any port where required under the Configure
Interface menu.

Session Timeout – Configures how long an authenticated session stays active before it must
re-authenticate itself. (Range: 300-3600 seconds; Default: 3600 seconds)

Quiet Period – Configures how long a host must wait to attempt authentication again after it
has exceeded the maximum allowable failed login attempts. (Range: 1-180 seconds; Default:
60 seconds)