Configuration Guide Vol. 2


9.1.1 List of configuration commands

The following tables list the commands used to configure Web authentication.

Table 9-1: List of configuration commands

Command name

Description

aaa accounting web-authentication default start-stop group radius

Enables accounting for Web authentication sessions.

aaa authentication web-authentication default group radius

Specifies RADIUS as the default method for Web authentication.

web-authentication auto-logout

Configures forced logout based on MAC address aging.

web-authentication ip address

Specifies the Web authentication IP address for use in fixed VLAN mode and dynamic VLAN mode.

web-authentication jump-url

Specifies the URL to which terminals are directed after successful authentication.

web-authentication logging enable

Starts the output of authentication results and operation logs to the syslog server.

web-authentication logout ping tos-windows

Specifies the TOS value of special pings sent by authenticated terminals.

web-authentication logout ping ttl

Specifies the TTL value of special pings sent by authenticated terminals.

web-authentication logout polling count

Specifies the number of times the switch resends the monitoring packet when there is no response.

web-authentication logout polling enable

Enables the connection monitoring functionality that monitors the operation of authenticated terminals.

web-authentication logout polling interval

Specifies the interval between transmissions of monitoring (ARP) packets by the connection monitoring functionality.

web-authentication logout polling retry-interval

Specifies the interval between retransmissions of monitoring (ARP) packets when there is no response.

web-authentication max-timer

Specifies the maximum connection time for Web-authenticated users.

web-authentication max-user

Specifies the maximum number of Web-authenticated users permitted in dynamic VLAN mode and legacy mode.

web-authentication port

Designates a port as an authenticating port in fixed VLAN mode and dynamic VLAN mode.

web-authentication redirect enable

Enables URL redirection.

web-authentication redirect-mode

Specifies the protocol (HTTP or HTTPS) used to display login pages on a terminal subject to URL redirection.

web-authentication ssl connection-timeout

Sets SSL session-establishment timeout.

web-authentication static-vlan max-user

Specifies the maximum number of authenticated users permitted in fixed VLAN mode.

web-authentication system-auth-control

Enables Web authentication.

web-authentication vlan

In legacy mode, specifies the VLAN IDs that can serve as post-authentication VLANs for Web authentication.

web-authentication web-port

Adds an access port capable of Web server access.