Default Web-Based Proxy Authentication Configuration; Web-Based Authentication Guidelines And Restrictions - Cisco WS-C6506 Software Manual

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Default Web-Based Proxy Authentication Configuration

Default Web-Based Proxy Authentication Configuration
Table 42-1
Table 42-1
Feature
Port access entity (PAE) capability
Web-based proxy authentication—Global
Web-based proxy authentication—Per port
Global session timeout
Quiet timeout
Login attempts

Web-Based Authentication Guidelines and Restrictions

This section provides the guidelines and restrictions for configuring web-based proxy authentication:
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
42-8
MAC-Authentication Bypass—MAC-Authentication Bypass is a Layer 2 authentication that uses a
MAC address. There is no actual authentication with MAC-Authentication Bypass. When you
configure web-based proxy authentication on an interface that has MAC-Authentication Bypass
configured, web-based proxy authentication occurs when the MAC-Authentication Bypass
completes. MAC-Authentication Bypass adds the port to a VLAN and gets an IP address using
DHCP, which triggers web-based proxy authentication.
Port Security—When you enable port security and web-based proxy authentication on a port, the
hosts that are secured by port security are web authenticated.
Voice VLAN ID (VVID)—Web-based proxy authentication and VVID support is restricted to
port-VLAN hosts.
Guest VLAN—At the completion of the 802.1X authentication or MAC-Authentication Bypass, a
port is added to the guest VLAN based on the 802.1X or the MAC-Authentication Bypass
authentication result. The port receives an IP address using DHCP in the guest VLAN. Web-based
proxy authentication occurs after the IP address is received.
Auth-Fail-VLAN—You can enable web-based proxy authentication and the authentication-fail
VLAN on the same port/VLAN.
Network Admission Control (NAC)—You can enable web-based proxy authentication and NAC
LAN port IP on the same port/VLAN. NAC with LAN port IP is independent of web-based proxy
authentication; LAN port IP posture validation can happen before web-based proxy authentication.
shows the default web-based proxy authentication configuration settings.
Web-Based Proxy Authentication Default Configuration
Web-based authentication is not supported on trunk or port-channel interfaces.
Because PBACL will be mapped to a VLAN, all ports in the VLAN have default access specified by
the PBACLs default policy. We recommend that you enable web-based authentication on all the
ports in the VLAN.
Chapter 42
Configuring Web-Based Proxy Authentication
Default Value
Authenticator only
Disabled
Disabled
3600 seconds
60 seconds
3 attempts
OL-8978-04

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents