EasyManuals Logo

Cisco Catalyst 4500 Series Software Configuration Guide

Cisco Catalyst 4500 Series
2086 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1434 background imageLoading...
Page #1434 background image
52-6
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 52 Configuring Web-Based Authentication
Configuring Web-Based Authentication
Configuring Web-Based Authentication
These sections describe how to configure web-based authentication:
• Default Web-Based Authentication Configuration, page 52-6
• Web-Based Authentication Configuration Guidelines and Restrictions, page 52-6
• Web-Based Authentication Configuration Task List, page 52-7
• Configuring the Authentication Rule and Interfaces, page 52-7
• Configuring AAA Authentication, page 52-9
• Configuring Switch-to-RADIUS-Server Communication, page 52-9
• Configuring the HTTP Server, page 52-11
• Configuring the Web-Based Authentication Parameters, page 52-13
• Removing Web-Based Authentication Cache Entries, page 52-14
Default Web-Based Authentication Configuration
Table 52-1 shows the default web-based authentication configuration.
Web-Based Authentication Configuration Guidelines and Restrictions
When configuring web-based authentication, consider these guidelines and restrictions:
• Web authentication requires two Cisco Attribute-Value (AV) pair attributes:
The first attribute, priv-lvl=15, must always be set to 15. This sets the privilege level of the user who
is logging into the switch.
The second attribute is an access list to be applied for web-authenticated hosts. The syntax is similar
to 802.1x per-user access control lists (ACLs). However, instead of ip:inacl, this attribute must begin
with proxyacl, and the source field in each entry must be any. (After authentication, the client IP
address replaces the any field when the ACL is applied.)
For example:
proxyacl# 10=permit ip any 10.0.0.0 255.0.0.0
proxyacl# 20=permit ip any 11.1.0.0 255.255.0.0
proxyacl# 30=permit udp any any eq syslog
Table 52-1 Default Web-based Authentication Configuration
Feature Default Setting
AAA Disabled
RADIUS server
• IP address
• UDP authentication port
• Key
• None specified
• 1812
• None specified
Default value of inactivity timeout 3600 seconds
Inactivity timeout Enabled

Table of Contents

Other manuals for Cisco Catalyst 4500 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco Catalyst 4500 Series and is the answer not in the manual?

Cisco Catalyst 4500 Series Specifications

General IconGeneral
SeriesCatalyst 4500 Series
CategorySwitch
Layer SupportLayer 2, Layer 3
Form FactorModular chassis
StackableNo
Chassis Slots3, 6, 7, 10
Power Supply OptionsAC, DC
RedundancyPower supply, Supervisor engine
Network ManagementCisco IOS Software CLI, SNMP, Cisco Prime Infrastructure
FeaturesSecurity, QoS
Port DensityUp to 384 ports per chassis
Security Features802.1X, ACLs, DHCP Snooping, Dynamic ARP Inspection, IP Source Guard
Supervisor Engine8-E

Related product manuals