Web and MAC Authentication

Configuring Web Authentication

Syntax: aaa port-access web-based <port-list> [client-moves]

Configures whether the client can move between ports.

Default: Disabled

Syntax: aaa port-access web-based [dhcp-addr <ip-address/mask>]

Specifies the base address/mask for the temporary IP pool used by DHCP. The base address can be any valid ip address (not a multicast address). Valid mask range value is <255.255.240.0 - 255.255.255.0>.

(Default: 192.168.0.0/255.255.255.0)

Syntax: aaa port-access web-based [dhcp-lease <5 - 25>]

Specifies the lease length, in seconds, of the temporary IP address issued for Web Auth login purposes. (Default: 10 seconds)

Syntax: aaa port-access web-based <port-list> [logoff-period]<60-9999999>]

Specifies the period, in seconds, that the switch enforces for an implicit logoff. This parameter is equivalent to the MAC age interval in a traditional switch sense. If the switch does not see activity after a logoff-period interval, the client is returned to its pre- authentication state. (Default: 300 seconds)

Syntax: aaa port-access web-based <port-list> [max-requests <1-10>]

Specifies the number of authentication attempts that must time-out before authentication fails.

(Default: 2)

3-23