11-7
Cisco IE 3010 Switch Software Configuration Guide
OL-23145-01
Chapter 11 Configuring Web-Based Authentication
Understanding Web-Based Authentication
Web-based Authentication Interactions with Other Features
Port Security, page 11-7
LAN Port IP, page 11-7
Gateway IP, page 11-7
ACLs, page 11-7
Context-Based Access Control, page 11-8
802.1x Authentication, page 11-8
EtherChannel, page 11-8

Port Security

You can configure web-based authentication and port security on the same port. Web-based
authentication authenticates the port, and port security manages network access for all MAC addresses,
including that of the client. You can then limit the number or group of clients that can access the network
through the port.
For more information about enabling port security, see the “Configuring Port Security” section on
page 24-7.

LAN Port IP

You can configure LAN port IP (LPIP) and Layer 2 web-based authentication on the same port. The host
is authenticated by using web-based authentication first, followed by LPIP posture validation. The LPIP
host policy overrides the web-based authentication host policy.
If the web-based authentication idle timer expires, the NAC policy is removed. The host is authenticated,
and posture is validated again.

Gateway IP

You cannot configure Gateway IP (GWIP) on a Layer 3 VLAN interface if web-based authentication is
configured on any of the switch ports in the VLAN.
You can configure web-based authentication on the same Layer 3 interface as Gateway IP. The host
policies for both features are applied in software. The GW IP policy overrides the web-based
authentication host policy.

ACLs

If you configure a VLAN ACL or a Cisco IOS ACL on an interface, the ACL is applied to the host traffic
only after the web-based authentication host policy is applied.
For Layer 2 web-based authentication, you must configure a port ACL (PACL) as the default access
policy for ingress traffic from hosts connected to the port. After authentication, the web-based
authentication host policy overrides the PACL.
You cannot configure a MAC ACL and web-based authentication on the same interface.
You cannot configure web-based authentication on a port whose access VLAN is configured for VACL
capture.