clear dot1x auth-config Configuring Port Web Authentication (PWA)
Enterasys Matrix DFE-Gold Series Configuration Guide 25-11
Configuring Port Web Authentication (PWA)
About PWA
PWAprovidesawayofauthenticatingusersbeforeallowinggeneralaccesstothenetwork.A
PWAuser’saccesstothenetworkisrestricteduntilaftertheusersuccessfullylogsinviaaweb
browserusingtheEnterasysMatrixSeriesweb‐basedsecuri tyinterface.TheEnterasysMatrix
Seriesdevicewillvalidateall
logincredentialfromtheuserwithaRADIUSserverbeforeallowing
networkaccess.
PWAisanalternativeto802.1XandMACauthentication.Itallowsonlytheessentialprotocols
andservicesrequiredbytheauthenticationprocessbetweentheend‐stationandthenetwork.All
othertrafficisdiscarded.Whenauseris
intheunauthenticatedstate,anyusertrafficrequesting
networkresourceswillnotbeallowed.
Tologonusing PWA,theusermakesarequestviaawebbrowserforthe PWAwebpageoris
automaticallyredirectedtothisloginpageafterrequestingaURLinabrowser.
Dependingupon
theauthenticatedstateoftheuser,aloginpageoralogoutpagewilldisplay.
Whenausersubmitsusernameandpassword,theswitchthenauthenticatestheuserviaa
preconfiguredRADIUSserver.Iftheloginissuccessful,thentheuserwillbegrantedfullnetwork
accessaccordingtotheuser’s
policyconfigurationontheswitch.
PWA Configuration Considerations
InordertooptimizePWAauthenticationontheEnterasysMatrixSeriesdevice,thedevicemustbe
configuredtosatisfytheminimumrequirementsofanauthenticatingclientneedingtosendan
HTTPrequestwithitswebbrowser.Typically,theclientwillneedDNS andARPresolutionbefore
itcangeneratetheHTTP
requestneededtodoaPWAlogin.Also,DHCPmaybeneededinmany
environments.TheseservicesarenotprovidedbyPWAandmustbeprovidedbythenetwork.To
accomplishthis,thedevicemustbeconfiguredtoallowaccesstotheneededservices.
Thefirststepistomakesure
thatthemultipleauthenticationportmodesettingsaresetto“auth‐
opt”onallportsthatareconfiguredtorun PWA.
Examples
Thisexampleshowshowtosetthemultipleauthenticationportmodeto“auth‐opt”forallFast
Ethernetportsinthechassisorstandalonedevice:
Matrix(rw)->set multiauth port mode auth-opt fe.*.*
Fordetailsonusingthesetmultiauthportcommand,referto“setmultiauthport”onpage 27‐6.
Settingtheportmodeinthisfashionwillallowtraffictoflowthroughtheportwithout
authenticationaccordingtoitsconfiguration.Bydefault,thiswouldallowalltraffictobe
forwarded.Conversely,you
couldconfiguretheportstodropalltraffic,butthisisnotthemost
effectivesolution.Betteryetwouldbetoconfiguretheporttoprovideonlytheminimalservices
andnothingmore.Themostpowerfultoolforaccomplishingthisgoalispolicyconfiguration.
Policiesprovidetheflexibilityneededtotailor
theseservicestotheconfigurationandsecurity
needsofyourenvironment.
Thisexampleshowshowtoconfigureapolicyprofilethatwilldiscardalltrafficbydefault:
Matrix(rw)->set policy profile 1 name “Unauthenticated User” pvid 0 pvid-status
enable
Thisexampleshowshowtoconfigurepolicyprofilerule1thatwillenabletheselectiveservices
requiredforPWA.Thisrulewill:
•forwardARPrequests,