Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
1-26
Introduction
ProCurve Wireless Edge Services xl Module
Web-Auth. The Wireless Edge Services xl Module can also provide Web-Auth
for stations that do not support 802.1X authentication. In this case, the module
confines unauthenticated wireless users’ access to a list of allowed IP
addresses. The module forces a user to authenticate itself by redirecting all
nonapproved traffic to a login page on a Web server.
Because the Wireless Edge Services xl Module handles all background pro-
cesses (such as forwarding requests to DHCP, RADIUS, and DNS servers), the
allow list only needs to include the IP address of the Web server that stores
the pages that guide the user through the authentication process.
You can even opt to maintain the Web pages on the Wireless Edge Services xl
Module itself to secure your organization’s Web server. In this case, the allow
list can be completely empty.
Figure 1-10 illustrates the Web-Auth process.
Figure 1-10. Web-Auth Process