Access Security Guide K/KA/KB.15.15

Use the [no] form of the command to set the auth-vid to 0. (Default: 0.)
Clearing statistics
Syntax
aaa port-access web-based [clear-statisics]
Clears (resets to 0) all counters used to monitor the CEI, HTTP, Web-based
authenticated control traffic generated in web-based authentication session. (To
display Web-Auth traffic statistics, enter the show port-access web-based
statistics command.)
Maximum authenticated clients
Syntax
aaa port-access web-based <port-list> [client-limit<1-256>]
Specifies the maximum number of authenticated clients to allow on the port. (Default:
1)
NOTE: On switches where Web-based authentication and 802.1X can operate
concurrently, this limit includes the total number of clients authenticated through
both methods. The limit of 256 clients only applies when there are fewer than
16,384 authentication clients on the entire switch. After the limit of 16, 384 clients
is reached, no additional authentication clients are allowed on any port for any
method.
Specifies base address
Syntax
aaa port-access web-based [dhcp-addr<ip-address/mask>]
Specifies the base address/mask for the temporary IP pool used by DHCP. The
base address can be any valid IP address (not a multicast address). Valid mask
range value is <255.255.240.0 - 255.255.255.0>. (Default:
192.168.0.0/255.255.255.0)
Specifies lease length
Syntax
aaa port-access web-based [dhcp-lease<5-25>]
Specifies the lease length, in seconds, of the temporary IP address issued for
Web-Auth login purposes. (Default: 10 seconds)
Configures web server connection
Syntax
aaa port-access web-based [ewa-server <ipv4-addr |hostname>
[<page-path>]]
Configures a connection with the web server at the specified IPv4 address (ipv4-addr)
or host name (ipv4- addr) on which customized login web pages used for web
authentication are stored. A maximum of 3 web servers can be configured on the
switch.
The optional <page-path> parameter defines the directory path on the server where
all customized login web pages (graphics, HTML frames, and HTML files) are stored.
(Default: The default <page-path> value is “/” for root directory. If the web server
86 Web-based and MAC authentication