EasyManua.ls Logo

Enterasys Matrix DFE-Gold Series

Enterasys Matrix DFE-Gold Series
944 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
clear dot1x auth-config Configuring Port Web Authentication (PWA)
Enterasys Matrix DFE-Gold Series Configuration Guide 25-11
Configuring Port Web Authentication (PWA)
About PWA
PWAprovidesawayofauthenticatingusersbeforeallowinggeneralaccesstothenetwork.A
PWAusersaccesstothenetworkisrestricteduntilaftertheusersuccessfullylogsinviaaweb
browserusingtheEnterasysMatrixSerieswebbasedsecuri tyinterface.TheEnterasysMatrix
Seriesdevicewillvalidateall
logincredentialfromtheuserwithaRADIUSserverbeforeallowing
networkaccess.
PWAisanalternativeto802.1XandMACauthentication.Itallowsonlytheessentialprotocols
andservicesrequiredbytheauthenticationprocessbetweentheendstationandthenetwork.All
othertrafficisdiscarded.Whenauseris
intheunauthenticatedstate,anyusertrafficrequesting
networkresourceswillnotbeallowed.
Tologonusing PWA,theusermakesarequestviaawebbrowserforthe PWAwebpageoris
automaticallyredirectedtothisloginpageafterrequestingaURLinabrowser.
Dependingupon
theauthenticatedstateoftheuser,aloginpageoralogoutpagewilldisplay.
Whenausersubmitsusernameandpassword,theswitchthenauthenticatestheuserviaa
preconfiguredRADIUSserver.Iftheloginissuccessful,thentheuserwillbegrantedfullnetwork
accessaccordingtotheusers
policyconfigurationontheswitch.
PWA Configuration Considerations
InordertooptimizePWAauthenticationontheEnterasysMatrixSeriesdevice,thedevicemustbe
configuredtosatisfytheminimumrequirementsofanauthenticatingclientneedingtosendan
HTTPrequestwithitswebbrowser.Typically,theclientwillneedDNS andARPresolutionbefore
itcangeneratetheHTTP
requestneededtodoaPWAlogin.Also,DHCPmaybeneededinmany
environments.TheseservicesarenotprovidedbyPWAandmustbeprovidedbythenetwork.To
accomplishthis,thedevicemustbeconfiguredtoallowaccesstotheneededservices.
Thefirststepistomakesure
thatthemultipleauthenticationportmodesettingsaresetto“auth
opt”onallportsthatareconfiguredtorun PWA.
Examples
Thisexampleshowshowtosetthemultipleauthenticationportmodeto“authopt”forallFast
Ethernetportsinthechassisorstandalonedevice:
Matrix(rw)->set multiauth port mode auth-opt fe.*.*
Fordetailsonusingthesetmultiauthportcommand,refertosetmultiauthportonpage 276.
Settingtheportmodeinthisfashionwillallowtraffictoflowthroughtheportwithout
authenticationaccordingtoitsconfiguration.Bydefault,thiswouldallowalltraffictobe
forwarded.Conversely,you
couldconfiguretheportstodropalltraffic,butthisisnotthemost
effectivesolution.Betteryetwouldbetoconfiguretheporttoprovideonlytheminimalservices
andnothingmore.Themostpowerfultoolforaccomplishingthisgoalispolicyconfiguration.
Policiesprovidetheflexibilityneededtotailor
theseservicestotheconfigurationandsecurity
needsofyourenvironment.
Thisexampleshowshowtoconfigureapolicyprofilethatwilldiscardalltrafficbydefault:
Matrix(rw)->set policy profile 1 name “Unauthenticated User” pvid 0 pvid-status
enable
Thisexampleshowshowtoconfigurepolicyprofilerule1thatwillenabletheselectiveservices
requiredforPWA.Thisrulewill:
•forwardARPrequests,

Table of Contents

Related product manuals