5. Create a Web Authentication VLAN and enable Web Authentication on that VLAN.
device(config)#vlan 10
device(config-vlan-10)#webauth
device(config-vlan-10-webauth)#enable
Once enabled, the CLI changes to the "webauth" configuration level. In the example above, VLAN 10
will require hosts to be authenticated using Web Authentication before they can forward traffic.
6. Configure the Web Authentication mode:
• ‐ Username and password - Blocks users from accessing the switch until they enter a valid
username and password on a web login page.
‐ Passcode - Blocks users from accessing the switch until they enter a valid passcode on a
web login page.
‐ None - Blocks users from accessing the switch until they press the ’Login’ button. A
username and password or passcode is not required.
Refer to Web authentication mode configuration on page 295.
7. Configure other Web Authentication options (refer to Web authentication options configuration on
page 304).
Enabling and disabling web authentication
Web Authentication is disabled by default. To enable it, enter the following commands.
device(config)# vlan 10
device(config-vlan-10# webauth
device(config(config-vlan-10-webauth)# enable
The first command changes the CLI level to the VLAN configuration level. The second command
changes the configuration level to the Web Authentication VLAN level. The last command enables Web
Authentication. In the example above, VLAN 10 will require hosts to be authenticated using Web
Authentication before they can forward traffic.
Syntax: webauth
FastIron devices support a maximum of two Web Authentication VLANs.
Syntax: [no] enable
Enter the no enable command to disable Web Authentication.
Web authentication mode configuration
You can configure the FastIron switch to use one of three Web Authentication modes:
• Username and password - Block users from accessing the switch until they enter a valid username
and password on a web login page. Refer to Using local user databases on page 296.
• Passcode - Blocks users from accessing the switch until they enter a valid passcode on a web login
page. Refer to Passcodes for user authentication on page 299.
• None - Blocks users from accessing the switch until they press the ’Login’ button. A username and
password or passcode is not required. Refer to Automatic authentication on page 304.
This following sections describe how to configure these Web Authentication modes.
Enabling and disabling web authentication
FastIron Ethernet Switch Security Configuration Guide 295
53-1003088-03
Comentários a estes Manuais