12-9
Catalyst 3750-X and 3560-X Switch Software Configuration Guide
OL-21521-01
Chapter 12 Configuring Web-Based Authentication Configuring Web-Based Authentication
Configuring Web-Based Authentication
Default Web-Based Authentication Configuration, page 12-9
Web-Based Authentication Configuration Guidelines and Restrictions, page 12-9
Web-Based Authentication Configuration Task List, page 12-10
Configuring the Authentication Rule and Interfaces, page 12-10
Configuring AAA Authentication, page 12-11
Configuring Switch-to-RADIUS-Server Communication, page 12-11
Configuring the HTTP Server, page 12-13
Configuring the Web-Based Authentication Parameters, page 12-16
Removing Web-Based Authentication Cache Entries, page 12-17

Default Web-Based Authentication Configuration

Table 12-1 shows the default web-based authentication configuration.

Web-Based Authentication Configuration Guidelines and Restrictions

Web-based authentication is an ingress-only feature.
You can configure web-based authentication only on access ports. Web-based authentication is not
supported on trunk ports, EtherChannel member ports, or dynamic trunk ports.
You must configure the default ACL on the interface before configuring web-based authentication.
Configure a port ACL for a Layer 2 interface or a Cisco IOS ACL for a Layer 3 interface.
You cannot authenticate hosts on Layer 2 interfaces with static ARP cache assignment. These hosts
are not detected by the web-based authentication feature because they do not send ARP messages.
By default, the IP device tracking feature is disabled on a switch. You must enable the IP device
tracking feature to use web-based authentication.
You must configure at least one IP address to run the switch HTTP server. You must also configure
routes to reach each host IP address. The HTTP server sends the HTTP login page to the host.
Tab le 12-1 Default Web-based Authentication Configuration
Feature Default Setting
AAA Disabled
RADIUS server
IP address
UDP authentication port
Key
None specified
1812
None specified
Default value of inactivity timeout 3600 seconds
Inactivity timeout Enabled