User Manual

Table Of Contents
M4300 Intelligent Edge Series Fully Managed Stackable Switches
Manage Switch Security User Manual592
7. In the Protocol field, select either HTTP or HTTPS as the captive portal instances used for
communication with clients during the verification process:
HTTP does not use encryption during verification.
HTTPS uses the Secure Sockets Layer (SSL), which requires a certificate to provide
encryption.
The certificate is presented to the user at connection time.
8. Select the type of user V
erification that the captive portal instance performs with clients that
attempt to connect:
Guest.
The user does not need to be authenticated by a database.
Local.
The device uses a local database to authenticate users.
RADIUS.
The device uses a database on a remote RADIUS server to authenticate
users.
9. Select the Block status.
If the CP is blocked, users cannot gain access to the network through the CP. Use this
function to temporarily protect the network during unexpected events, such as denial of
service attacks.
10. If the verification mode is Local or RADIUS, use the Group field to assign an existing user
group to the captive portal.
All users who belong to the group are permitted to access the network through this portal.
The User Group list is the same for all CP configurations on the switch.
11. In the Idle T
imeout field, enter the number of seconds to wait before terminating a session.
A user is logged out once the session idle time-out is reached. If you set the value to 0,
then the time-out is not enforced.
The valid range is 0 to 900 seconds. The default value
is 0.
12. In the User Logout list, select the Enable or Disable option to allow an authenticated client
to deauthenticate from the network.
If this option is clear or the user does not specifically request logout, the client connection
status remains authenticated until the captive portal deauthenticates the user, for
example by reaching the idle time-out or session time-out values.
13. If the verification mode is RADIUS, use the Radius Auth
Server field to enter the IP
address of the RADIUS server to use for client authentication.
The device acts as the RADIUS client and performs all RADIUS transactions on behalf of
the clients.
14. Select the Redirect Mode to specify whether the CP redirects the newly authenticated client
to the configured URL (enabled).
If this mode is disabled, the default locale specific welcome is used.
15. Specify the Redirect URL to which the newly authenticated client is redirected.
The maximum length for the URL is 512 alphanumeric characters.
16. In the Background Color field, specify the value of the background color
.
For example, #BFBFBF.