The web authentication.

I want to configure a switch for IEEE 802 authentication port. 1 x with web authentication as a means of rescue.

Can anyone provide an example of a valid configuration?

Only web authentication does not work!

Switch #sh run

Building configuration...

Current configuration: 3012 bytes

!

version 12.2

no service button

horodateurs service debug uptime

Log service timestamps uptime

no password encryption service

!

Switch host name

!

!

AAA new-model

Group AAA authentication login default RADIUS

connection of line-con AAA authentication, no

Group AAA dot1x default authentication RADIUS

Group AAA authorization auth-proxy default RADIUS

!

AAA - the id of the joint session

switch 1 supply ws-c3750 - 48P

mtu 1500 routing system

IP subnet zero

IP - cisco.com domain name

property intellectual admission name rule1 http proxy

!

!

!

!

control-dot1x system-auth

!

!

!

!

!

!

Profile relief aid

IP access-group Policy1 in

rule1 admission IP

!

pvst spanning-tree mode

spanning tree extend id-system

!

internal allocation policy of VLAN ascendant

!

!

!

!

interface FastEthernet1/0/1

switchport access vlan 142

switchport mode access

!

interface FastEthernet1/0/47

switchport access vlan 142

switchport mode access

dot1x EAP authenticator

self control-port dot1x

relief aid dot1x

!

interface Vlan1

no ip address

Shutdown

!

interface Vlan142

IP 10.1.254.1 255.255.255.0

!

IP classless

!

peche1 extended IP access list

allow udp any any eq bootps

deny ip any any newspaper

!

Server RADIUS attribute 8 include-in-access-req

secret key of acct-port 1645 auth-10.1.254.187 - RADIUS server host port 1646

Server RADIUS ports source-1645-1646

RADIUS vsa server send authentication

!

control plan

!

!

Line con 0

line vty 5 15

!

end

Try adding this:

analysis of IP device

In addition, if you want your users to web-auth to use DNS to resolve URLS, you probably want to add something like this to Policy1:

allow udp any any eq field

Don't forget that you need to wait until the 802. 1 X times out (90 seconds by default) for Web-Auth to kick.

Shelly

Tags: Cisco Security

Similar Questions

  • Assignment of VLAN dynamic of the Web authentication

    In a firmware WLC 4402 v.5.2.157 is possible to assign users to one VLAN dynamic based on the RADIUS response received from ACS?

    Yes and no. You can do for a WLAN 802.1 x internal, that the customer does not get an IP address, until they have completed the authentication process. To do this, you use 64/65/81, 64 802, 65 VLAN and to 81 use the name of the interface, not the number VLAN. you will also need to make sure you have AAA Overrided activated under the WLAN.

    If, as is said for Web authentication, the answer is no. The client has an IP address before being validated by the AAA server.

    HTH,

    Steve

  • Ie9 beta does not have the web authentication

    Hello

    / * Style definitions * / table. MsoNormalTable {mso-style-name : « Table Normal » ; mso-tstyle-rowband-taille : 0 ; mso-tstyle-colband-taille : 0 ; mso-style-noshow:yes ; mso-style-priorité : 99 ; mso-style-qformat:yes ; mso-style-parent : » « ;" mso-rembourrage-alt : 0 cm 5.4pt cm 0 5.4pt ; mso-para-margin : 0 cm ; mso-para-marge-bottom : .0001pt ; mso-pagination : widow-orphelin ; police-taille : 11.0pt ; famille de police : « Calibri », « sans-serif » ; mso-ascii-font-family : Calibri ; mso-ascii-theme-font : minor-latin ; mso-fareast-font-family : SimSun ; mso-fareast-theme-font : minor-fareast ; mso-hansi-font-family : Calibri ; mso-hansi-theme-font : minor-latin ; mso-bidi-font-family : Arial ; mso-bidi-theme-font : minor-bidi ;}

    I have a question:

    We had a user who defines the Cisco web-authentuicated WiFi SSID as network Public in the firewall of Windows 7 and when he tried to connect to WiFi, it appears a troubleshooting page and said: "Connection to Web pages are currently redirected to a different Web page."  It uses IE9 beta.  Most likely the browser it's a MiTM attack.

    Apart from declaring (SSID) network as a private network secure, y at - there another solution?

    Our goal is to get the users (which come from major conferences) on the network without them having to change a lot of things on their laptops. They would be naturally defined as a Public network.

    Thank you

    Suman

    The concept of web authentication IS a man in the Middle somehow attack... And IE9 is not a browser supported either.

    I don't know what makes IE cause this error exactly well. You have a DNS host name and the certificate on your webauth?

    Nicolas

  • Web authentication Catalyst 2960

    Hello

    I am trying to configure Web authentication relief on a catalyst 2960 switch. The goal is to authenticate customers via web authentication that are consistent (the part of 802. 1 x works fine) not 802. 1 x and allow them access to the network. The problem is that the web authentication seems to fail.

    The equipment about my question: switch catalyst 2960 (version: 122 - 37.SE) and a FreeRadius.

    Here's what happens:

    The authentication window will appear in my browser and the access request is sent to the RADIUS.

    The term RADIUS replies with an Access-Accept. Debugging running on the switch show that all this information is coming properly authentication and switch outputs debug a 'status = PASS' and permission to debug outputs a 'status = PASS_ADD'. Despite this the browser on the client generates a message "authentication failure".

    I have read the manual and the Cisco attribute value pairs are mentioned: ' priv-lvl = 15' and «proxyacl...»» ». They are required to make it work? Given that I'm not setting up any authentication switch connection via RADIUS.

    Any suggestions?

    Thanks in advance

    Yes, they are mandatory.

    If priv-lvl = 15 is not returned to the switch, the user will see? Authentication failed? and the access list will not apply. If the source in the statements of proxyacl field is not? everything? or there are other errors of syntax, the user will see? Successful authentication? but the access list will not apply and the user will be denied access to the network.

    Not sure about the configuration of specific FreeRADIUS, but you need to set up the? [026\009\001] Cisco av pair VSA. It should look like:

    Priv-lvl = 15

    proxyacl #10 = ip permit a whole

    Let me know if this lets you squared

  • Web authentication WISN and COMMENTS

    I have a WISN and we use open web Cisco

    authentication with a user's e-mail address.

    When executing this CLI command:

    > config network secureweb disable

    > save config

    > the system

    This will make the web authentication come HTTP instead of HTTPS?

    This command is for managing the unit.

    However it used to be a workaround when you disable HTTPS and SSH and you restart the WLC web authentication will be displayed as http and not https.

    Let me know if it works for you

  • Authentication service and the web

    I just started to develop blackberry applications and I recently launched on the development of an application for my Web site. My site was built with drupal and I intend to have my app work exactly like my site in terms of logon and to comment and look at a profile (something similar to facebook). I don't know that I can get if gives me an overview of the process that I can achieve different.

    First of all how the application be referred and when I get it authenticated how will I have the synchronization of the connection to the profile of this user on the Web site of th?

    I thought that I could redo the whole site for mobile and just get in a browserfield. The main reason I need an application is because I intend to use the native features such as photo taking and uploading it to the website.

    I have really need some advice how to make an app that is native and a user needs to be authenticated before use and after authentication, all done, the user must reflect on the site on his profile (similar to facebook)...

    All advice is appreciated. Thank you

    You must understand how drupal works on yourself, at least I know nothing about it.
    Basic authentication is a widely used standard authentication, that's just a guess that it is used by drupal. There are many other options, like oAuth, xAuth etc.

    If you have solved these issues no - BB you can find here detailed questions. I would also say to take a look at samples (httpdemo) and check other resources for new developers (see the new landing page)

  • Web authentication passthrough with input from the e-mail

    Is it possible to use a custom login.html page when web auth/passthrough is used with the input of the email? I have a requirement to have just the users to register with an e-mail address and I need to provide a custom page.

    I receive custom login pages, but I can't figure out how to make a customized with only e-mail login.html page entry.

    Any help is appreciated.

    Thank you

    Kurt

    You should also check wireless downloads. In the area where you can find the code of the controller to download, you can also find a 'Wireless LAN Controller Web authentication Bundle' containing several samples of html, including e-mail data.

    This link might work, maybe not:

    http://Tools.Cisco.com/support/downloads/go/InterfaceModuleSWT.x?mdfid=279911269&mdfLevel=model&treeName=wireless&modelname=Cisco%204404%20Wireless%20LAN%20Controller&treeMdfId=278875243

  • Call the web service with Digest authentication

    Hello

    I JDevelper 12.2.4, I need build the java class to call the web service with Digest authentication.

    Any suggestion?

    Refer to:

    http://StackOverflow.com/questions/14896324/consuming-WCF-service-with-Digest-authentication-from-Java

  • "Use authentication Windows session" does not work on the Web Client

    When I check "Session authentication using Windows" and click on "Login", I immediately get "username and password are required. I was able to solve the same problem of thick client with KB2050701, but that did not address the web client.

    I opened a ticket - apparently it's a known issue with no current fix or workaround.

  • Authentication customized using the Web Service construction

    Our requirement is that we want to create an application that uses the web service for authentication. How is it possible. A how to do this will help.
    We create a Web Service with an applicationLogin method that takes the user name and password input and returns true or false. I want to use this web service to authenticate the application connection.

    Hello

    Ok.
    Can you check Home > Application Builder > application 100 > shared components > authentication schemes > change the authentication scheme
    in the select field Invalid Page Session list
    what page 2.
    Check this page 101 a: APP_USER filled when you browse it.

    It seems that you have created a reference to Web Service manually by copy - paste SOAP envelope?
    And region of SOAP response with field response Collection store
    When you create a Web service reference with the location of the WSDL document, you are not asked for the name of the collection.
    Only when you create processes on submit type Web service on page 101, there is an option to use the collection or the item.

    And if you manually create the Web service, it seems that you cannot choose between the collection and the element, you should use the collection that you specified during the creation of reference.

    Anyway, you can use the collection to this approach to page dummy connection since: APP_USER is populated by anyone on page 101.

    I updated most of the page and creates a Web service reference manually the SOAP envelope (from the same Web service)
    and put the second region with the result. Collection is specified in a Web service reference.

    I hope that will solve your problem.

    Kind regards
    Oleg

  • Connections to the Web site

    Since the update of Firefox for windows 10 I cant get onto certain websites.
    All I get is the error message. Tried removing Firefox firewall and adding back on. Don't agree.
    Never had any problem until I updated. I have triewd the removal of Firefox and download again. Still not good.
    Disabled extensions and Add ons still no joy.
    Anyone know why this is happening. Could be something simple, but I just don't find that.

    The secure connection failed

    An error occurred during a connection to www.qrz.com. The peer certificate has an invalid signature. (Error code: sec_error_bad_signature)

       The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.
       Please contact the web site owners to inform them of this problem.
    

    Hi, in case, you're an avast user, please try to disable https scanning in avast:

    1. Open the Avast dashboard on an affected system.
    2. Select settings in the left side menu.
    3. Adopt a Protection Active.
    4. Click on customize next to the Web Shield.
    5. Uncheck the option "Enable HTTPS analysis", and then click ok.

    http://www.gHacks.NET/2014/10/31/avasts-HTTPS-scanning-interferes-with-Firefox-and-other-programs/

  • I can't add a second e-mail account. I get a message next to the 'User name' or password invalid password field. I can connect to the web gmail ok, imap is enabled.

    I setup a gmail account to and works very well. When I try to add another gmail account, I get an error 'User name' or invalid password. I can connect to this second gmail via the web to gmail account and the account active imap.

    PS - I use these accounts for the years through the web

    Thank you

    I also tried to delete completely the TB and reinstalled to try the problem gmail account and it still doesn't work.

    When checking on the 2-factor authentication, which I use, I noticed something. The work gmail account has allowed access to less secure applications"and my problem of account does not. I activated that and managed to add it to the TB. Everything works now!

    Not sure if less secure applications is a good thing, but its working.

    Thanks Christ1

  • Site ads continue to use the proxy settings and I get the message "Authentication required" time and time again. I have stop advertisements to use my proxy settings?

    I have put my school proxy settings and use them very often. On some Web sites, ads continue to use these proxy settings (probably to show me ads based on my preferences or I don't know), and I get the message "Authentication required" time and time again before the end of the loading page. It's annoying because if I have several tabs open and am currently on another page while loading the website with the ads, I'm brought back to this page to authenticate. Can I get asked 3 times to authenticate while this page loads, and it takes forever to load because of this. I don't want to disable my proxy settings because I use it very often. I tried to uncheck the "Accept cookies from Web sites" and nothing happens, it's always the same. I want these ads to stop going through my proxy settings. How do I do that?

    Hello

    You can try the add-on Adblock Plus . In addition to subscriptions, you can manually add URL patterns or click on an ad to add a filter.

    Support

  • How do reset us the Web integrated (built-in web server) server on our Pro Wireless 8500 A909g printers?

    We try to remotely administer printers HP OfficeJet Pro 8500 A909g Wireless

    M/N: CB023A

    They print and scan very well, and we can access the home page of each printer EWS.

    We have been asked to make a few changes and cannot go beyond the EWS username and password authentication request.

    In my view, it has been defined by a previous administrator, but him documented names of user and password we have on file do not work.

    How do reset us the EWS password?

    I have the default value is EMPTY, but if not, that would be the default password after reset?

    SOLVED!

    Then I got a job to another printer HP OfficeJet 8 X 00-

    All you have to do is RESTORE network defaults on the front control panel - this will reset the default value:

    (1) requirement for access password turned OFF

    (2) default user name is ADMIN

    (3) password is EMPTY

    then, on command before Panel set your IP network information, and you will then be able to access the built-in Web server and see all / manage all settings, including resetting the password to the web server integrated EWS.

    WITH THE SUPPORT OF HP NO.

  • Internet Explore has stopped working - question of the biometric authentication service

    My Elitebook 8540p has developed a problem where I get the error message - Internet Explorer has stopped working... Turn it back on.     I am running Windows 7 32 bit.   And using IE9.

    After some internet reading, I started my services of neutralization.    I finally got down to a service that is causing the problem.

    Biometric Authentication Service Digital Persona Inc.

    When I disable the service in the services of the MSconfig System Configuration and reboot, I use internet explore without any problem.    (I've identified some Web pages which would agrivate the question.)

    The deactivation of the Service of Authenticaton of Biomitric causes the scanner to not work.     I tried to reload the driver for fingerprint reader, and the HP Protect tools Security Manager.

    Any idea how I can activate the biometric authentication Service and not IE stopped working the issue?

    j1bissig

    I had the same problem on my HP Pavilion dv7 and had the chance of getting a solution.

    I, too, put the finger on biometric authentication as the problem Service.  By disabling the service, Internet Explorer worked well; except, now, I had no finger analysis feature.  I installed the latest version and it worked for a few sessions and then the problem comes back.

    Looking at my updates, I realized that the Flash is set to update at the same time, the problem started.  I tested by activating the biometric authentication Service.  Instead, I disabled the Flash add-on in Internet Explorer and it did not work again; except, now, I had no Flash.

    Searching online, I came across this post from Adobe:

    Post on the Adobe Forum: IE9, Windows 7 64-bit Flash causes "Internet Explorer has stopped working".

    I followed the instructions in this post, including the "clean install" and reverted to version 10.3 of Flash.

    Post on the Adobe Forum: how to return to a previous version of Flash Player?

    Now, all the features work correctly.

    I hope this helps!

Maybe you are looking for