<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic About web authentication. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816312#M5547</link>
    <description>&lt;P&gt;I want to configure a switch port for IEEE 802.1x authentication with web authentication as a fallback method.&lt;/P&gt;&lt;P&gt;Can someone provide a valid configuration example?&lt;/P&gt;&lt;P&gt;Only web authentication doesn't work!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch#sh run&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 3012 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.2&lt;/P&gt;&lt;P&gt;no service pad&lt;/P&gt;&lt;P&gt;service timestamps debug uptime&lt;/P&gt;&lt;P&gt;service timestamps log uptime&lt;/P&gt;&lt;P&gt;no service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname Switch&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius&lt;/P&gt;&lt;P&gt;aaa authentication login line-con none&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization auth-proxy default group radius &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;switch 1 provision ws-c3750-48p&lt;/P&gt;&lt;P&gt;system mtu routing 1500&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;ip domain-name cisco.com&lt;/P&gt;&lt;P&gt;ip admission name rule1 proxy http&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;fallback profile fallback&lt;/P&gt;&lt;P&gt; ip access-group policy1 in&lt;/P&gt;&lt;P&gt; ip admission rule1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;spanning-tree mode pvst&lt;/P&gt;&lt;P&gt;spanning-tree extend system-id&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vlan internal allocation policy ascending&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet1/0/1&lt;/P&gt;&lt;P&gt; switchport access vlan 142&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet1/0/47&lt;/P&gt;&lt;P&gt; switchport access vlan 142&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x port-control auto&lt;/P&gt;&lt;P&gt; dot1x fallback fallback&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan142&lt;/P&gt;&lt;P&gt; ip address 10.1.254.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip access-list extended policy1&lt;/P&gt;&lt;P&gt; permit udp any any eq bootps&lt;/P&gt;&lt;P&gt; deny   ip any any log&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P&gt;radius-server host 10.1.254.187 auth-port 1645 acct-port 1646 key secret&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt;radius-server vsa send authentication&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;control-plane&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:19:05 GMT</pubDate>
    <dc:creator>andrea.meconi</dc:creator>
    <dc:date>2020-02-21T18:19:05Z</dc:date>
    <item>
      <title>About web authentication.</title>
      <link>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816312#M5547</link>
      <description>&lt;P&gt;I want to configure a switch port for IEEE 802.1x authentication with web authentication as a fallback method.&lt;/P&gt;&lt;P&gt;Can someone provide a valid configuration example?&lt;/P&gt;&lt;P&gt;Only web authentication doesn't work!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch#sh run&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 3012 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.2&lt;/P&gt;&lt;P&gt;no service pad&lt;/P&gt;&lt;P&gt;service timestamps debug uptime&lt;/P&gt;&lt;P&gt;service timestamps log uptime&lt;/P&gt;&lt;P&gt;no service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname Switch&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius&lt;/P&gt;&lt;P&gt;aaa authentication login line-con none&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization auth-proxy default group radius &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;switch 1 provision ws-c3750-48p&lt;/P&gt;&lt;P&gt;system mtu routing 1500&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;ip domain-name cisco.com&lt;/P&gt;&lt;P&gt;ip admission name rule1 proxy http&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;fallback profile fallback&lt;/P&gt;&lt;P&gt; ip access-group policy1 in&lt;/P&gt;&lt;P&gt; ip admission rule1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;spanning-tree mode pvst&lt;/P&gt;&lt;P&gt;spanning-tree extend system-id&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vlan internal allocation policy ascending&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet1/0/1&lt;/P&gt;&lt;P&gt; switchport access vlan 142&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet1/0/47&lt;/P&gt;&lt;P&gt; switchport access vlan 142&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x port-control auto&lt;/P&gt;&lt;P&gt; dot1x fallback fallback&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan142&lt;/P&gt;&lt;P&gt; ip address 10.1.254.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip access-list extended policy1&lt;/P&gt;&lt;P&gt; permit udp any any eq bootps&lt;/P&gt;&lt;P&gt; deny   ip any any log&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P&gt;radius-server host 10.1.254.187 auth-port 1645 acct-port 1646 key secret&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt;radius-server vsa send authentication&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;control-plane&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816312#M5547</guid>
      <dc:creator>andrea.meconi</dc:creator>
      <dc:date>2020-02-21T18:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: About web authentication.</title>
      <link>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816313#M5549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try adding this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip device tracking&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, if you want your web-auth users to be able to use DNS to resolve URLs, you probably want to add something like this to policy1:&lt;/P&gt;&lt;P&gt;permit udp any any eq domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember you'll have to wait until 802.1X times out (90 sec by default) for Web-Auth to kick in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 15:12:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816313#M5549</guid>
      <dc:creator>scadora</dc:creator>
      <dc:date>2007-09-07T15:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: About web authentication.</title>
      <link>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816314#M5551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for your help Shelly!&lt;/P&gt;&lt;P&gt;Do you known how to personalize the authentication proxy login page?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Andrea.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2007 07:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816314#M5551</guid>
      <dc:creator>andrea.meconi</dc:creator>
      <dc:date>2007-09-10T07:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: About web authentication.</title>
      <link>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816315#M5552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shelly,&lt;/P&gt;&lt;P&gt;if you want you can use the "ip admission auth-proxy-banner" command to add a banner.&lt;/P&gt;&lt;P&gt;Bye.&lt;/P&gt;&lt;P&gt;Andrea.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2007 12:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816315#M5552</guid>
      <dc:creator>andrea.meconi</dc:creator>
      <dc:date>2007-09-10T12:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: About web authentication.</title>
      <link>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816316#M5553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Andrea.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, personalization is not currently supported.  But tell your Cisco account team you want it!  They should advocate for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2007 14:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816316#M5553</guid>
      <dc:creator>scadora</dc:creator>
      <dc:date>2007-09-10T14:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: About web authentication.</title>
      <link>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816317#M5554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds good to me!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2007 16:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/about-web-authentication/m-p/816317#M5554</guid>
      <dc:creator>scadora</dc:creator>
      <dc:date>2007-09-10T16:11:03Z</dc:date>
    </item>
  </channel>
</rss>

