clear dot1x auth-config Configuring Port Web Authentication (PWA)
Enterasys Matrix DFE-Gold Series Configuration Guide 25-11

Configuring Port Web Authentication (PWA)

About PWA

PWAprovidesawayofauthenticatingusersbeforeallowinggeneralaccesstothenetwork.A
PWAusersaccesstothenetworkisrestricteduntilaftertheusersuccessfullylogsinviaaweb
browserusingtheEnterasysMatrixSerieswebbasedsecurityinterface.TheEnterasysMatrix
SeriesdevicewillvalidatealllogincredentialfromtheuserwithaRADIUSserverbeforeallowing
networkaccess.
PWAisanalternativeto802.1XandMACauthentication.Itallowsonlytheessentialprotocols
andservicesrequiredbytheauthenticationprocessbetweentheendstationandthenetwork.All
othertrafficisdiscarded.Whenauserisintheunauthenticatedstate,anyusertrafficrequesting
networkresourceswillnotbeallowed.
TologonusingPWA,theusermakesarequestviaawebbrowserforthePWAwebpageoris
automaticallyredirectedtothisloginpageafterrequestingaURLinabrowser.
Dependingupontheauthenticatedstateoftheuser,aloginpageoralogoutpagewilldisplay.
Whenausersubmitsusernameandpassword,theswitchthenauthenticatestheuserviaa
preconfiguredRADIUSserver.Iftheloginissuccessful,thentheuserwillbegrantedfullnetwork
accessaccordingtotheuserspolicyconfigurationontheswitch.

PWA Configuration Considerations

InordertooptimizePWAauthenticationontheEnterasysMatrixSeriesdevice,thedevicemustbe
configuredtosatisfytheminimumrequirementsofanauthenticatingclientneedingtosendan
HTTPrequestwithitswebbrowser.Typically,theclientwillneedDNSandARPresolutionbefore
itcangeneratetheHTTPrequestneededtodoaPWAlogin.Also,DHCPmaybeneededinmany
environments.TheseservicesarenotprovidedbyPWAandmustbeprovidedbythenetwork.To
accomplishthis,thedevicemustbeconfiguredtoallowaccesstotheneededservices.
Thefirststepistomakesurethatthemultipleauthenticationportmodesettingsaresetto“auth
opt”onallportsthatareconfiguredtorunPWA.
Examples
Thisexampleshowshowtosetthemultipleauthenticationportmodeto“authopt”forallFast
Ethernetportsinthechassisorstandalonedevice:
Matrix(rw)->set multiauth port mode auth-opt fe.*.*
Fordetailsonusingthesetmultiauthportcommand,refertosetmultiauthportonpage 276.
Settingtheportmodeinthisfashionwillallowtraffictoflowthroughtheportwithout
authenticationaccordingtoitsconfiguration.Bydefault,thiswouldallowalltraffictobe
forwarded.Conversely,youcouldconfiguretheportstodropalltraffic,butthisisnotthemost
effectivesolution.Betteryetwouldbetoconfiguretheporttoprovideonlytheminimalservices
andnothingmore.Themostpowerfultoolforaccomplishingthisgoalispolicyconfiguration.
Policiesprovidetheflexibilityneededtotailortheseservicestotheconfigurationandsecurity
needsofyourenvironment.
Thisexampleshowshowtoconfigureapolicyprofilethatwilldiscardalltrafficbydefault:
Matrix(rw)->set policy profile 1 name “Unauthenticated User” pvid 0 pvid-status
enable
Thisexampleshowshowtoconfigurepolicyprofilerule1thatwillenabletheselectiveservices
requiredforPWA.Thisrulewill:
•forwardARPrequests,