Configuration Guide User guide

FastIron Configuration Guide xlvii
53-1002494-02
Web authentication options configuration . . . . . . . . . . . . . . . . . 1901
Enabling RADIUS accounting for web authentication . . . . . 1901
Changing the login mode (HTTPS or HTTP) . . . . . . . . . . . . . 1901
Specifying trusted ports. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1901
Specifying hosts that are permanently authenticated . . . . 1902
Configuring the re-authentication period . . . . . . . . . . . . . . . 1903
Defining the web authentication cycle . . . . . . . . . . . . . . . . . 1903
Limiting the number of web authentication attempts. . . . . 1903
Clearing authenticated hosts from the web
authentication table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1903
Setting and clearing the block duration for web
authentication attempts . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1904
Manually blocking and unblocking a specific host . . . . . . . 1904
Limiting the number of authenticated hosts . . . . . . . . . . . . 1904
Filtering DNS queries. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1905
Forcing re-authentication when ports are down . . . . . . . . . 1905
Forcing re-authentication after an inactive period . . . . . . . 1906
Defining the web authorization redirect address . . . . . . . . 1906
Deleting a web authentication VLAN . . . . . . . . . . . . . . . . . . 1906
Web authentication pages . . . . . . . . . . . . . . . . . . . . . . . . . . 1908
Displaying web authentication information. . . . . . . . . . . . . . . . . .1915
Displaying the web authentication configuration . . . . . . . . .1915
Displaying a list of authenticated hosts . . . . . . . . . . . . . . . . .1917
Displaying a list of hosts attempting to authenticate . . . . . 1918
Displaying a list of blocked hosts . . . . . . . . . . . . . . . . . . . . . .1919
Displaying a list of local user databases . . . . . . . . . . . . . . . .1919
Displaying a list of users in a local user database . . . . . . . 1920
Displaying passcodes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1920
Chapter 47 DoS Attack Protection
Smurf attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1921
Avoiding being an intermediary in a Smurf attack. . . . . . . . 1922
Avoiding being a victim in a Smurf attack . . . . . . . . . . . . . . 1922
TCP SYN attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1923
TCP security enhancement . . . . . . . . . . . . . . . . . . . . . . . . . . 1925
Displaying statistics about packets dropped
because of DoS attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1926
Chapter 48 DHCP
Dynamic ARP inspection. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1927
ARP poisoning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1927
About Dynamic ARP Inspection. . . . . . . . . . . . . . . . . . . . . . . 1928
Configuration notes and feature limitations for DAI . . . . . . 1929
Dynamic ARP inspection configuration . . . . . . . . . . . . . . . . 1930
Displaying ARP inspection status and ports . . . . . . . . . . . . 1931
Displaying the ARP table . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1931