Configuring Port Web Authentication (PWA)
SecureStack C2 Configuration Guide 18-57
Configuring Port Web Authentication (PWA)
About PWA
PWAprovidesawayofauthenticatingusersbeforeallowinggeneralaccesstothenetwork.A
PWAuser’saccesstothenetworkisrestricteduntilaftertheusersuccessfullylogsinviaaweb
browserusingtheEnterasysNetworks’web‐basedsecurityinterface.TheSecureStackC2device
willvalidatealllogincredentials
fromtheuserwithaRADIUSserverbeforeallowingnetwork
access.
PWAisanalternativeto802.1XandMACauthentication.Itallowsonlytheessentialprotocols
andservicesrequiredbytheauthenticationprocessbetweentheend‐stationandthenetwork.All
othertrafficisdiscarded.Whenauserisinthe
unauthenticatedstate,anyusertrafficrequesting
networkresourceswillnotbeallowed.
TologonusingPWA,theusermakesarequestviaawebbrowserforthePWAwebpageoris
automaticallyredirectedtothisloginpageafterrequestingaURLinabrowser.
Dependingupontheauthenticated
stateoftheuser,aloginpageoralogoutpagewilldisplay.
Whenausersubmitsusernameandpassword,theswitchthenauthenticatestheuserviaa
preconfiguredRADIUSserver.Iftheloginissuccessful,thentheuserwillbegrantedfullnetwork
accessaccordingtotheuser’spolicyconfiguration
ontheswitch.
Purpose
Toreview,enable,disable,andconfigurePortWebAuthentication(PWA).
Commands
Note: One user per PWA-configured port can be authenticated on SecureStack C2 devices. Only
one method of authentication can be deployed per port.
For information about... Refer to page...
show pwa 18-58
set pwa 18-59
show pwa banner 18-60
set pwa banner 18-60
clear pwa banner 18-61
set pwa displaylogo 18-61
set pwa ipaddress 18-62
set pwa protocol 18-62
set pwa guestname 18-63
clear pwa guestname 18-63
set pwa guestpassword 18-64
set pwa gueststatus 18-64
set pwa initialize 18-65