Cisco ASR1004-20G-SEC/K9 Software Guide - Page 337

Authentication and the Web User Interface, Domain Name System and the Web User Interface, Clocks

Page 337 highlights

Chapter 14 Configuring and Accessing the Web User Interface Authentication and the Web User Interface Router(config)# transport-map type persistent webui http-https-webui Router(config-tmap)# server Router(config-tmap)# secure-server Router(config-tmap)# exit Router(config)# transport type persistent webui input http-https-webui *Apr 22 02:47:22.981: %UICFGEXP-6-SERVER_NOTIFIED_START: R0/0: psd: Server wui has been notified to start Authentication and the Web User Interface Users attempting to access the web user interface for a router are subject to the same authentication requirements configured for that router. The web browser prompts all users for a name and password combination, and the web browser then looks to the router configuration to see if a user should or should not be granted access to the web user interface. Only users with a privilege level of 15 can access the web user interface. Otherwise, authentication of web user interface traffic is governed by the authentication configuration for all other traffic. To configure authentication on your router, see Configuring Authentication. http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfathen.html Domain Name System and the Web User Interface The Domain Name System (DNS) is a distributed database in which you can map hostnames to IP addresses through the DNS protocol from a DNS server. If the router is configured to participate in the Domain Name System, users can access the web user interface by entering http:// as the web browser address. For information on configuring DNS, see Configuring DNS. http://www.cisco.com/en/US/docs/ios/ipaddr/configuration/guide/iad_config_dns_ps6922_TSD_Produ cts_Configuration_Guide_Chapter.html Clocks and the Web User Interface Requests to view the web user interface can be rejected by certain web browsers if the time as seen by the web browser differs from the time as seen by the router by an hour or more. For this reason, we recommend checking the router time using the show clock command before configuring the router and, if the router time is not properly set, use the clock set and clock timezone commands for setting the router clock. Similarly, the web browser's clock source, which is usually the personal computer, must also have an accurate time to properly access the web user interface. The following message appears when the web browser and the router clocks are more than an hour apart: Your access is being denied for one of the following reasons: . Your previous session has timed-out, or . You have been logged out from elsewhere, or . You have not yet logged in, or . The resource requires a higher privilege level login. OL-16506-10 Cisco ASR 1000 Series Aggregation Services Routers Software Configuration Guide 14-7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378

14-7
Cisco ASR 1000 Series Aggregation Services Routers Software Configuration Guide
OL-16506-10
Chapter 14
Configuring and Accessing the Web User Interface
Authentication and the Web User Interface
Router(config)#
transport-map type persistent webui http-https-webui
Router(config-tmap)#
server
Router(config-tmap)#
secure-server
Router(config-tmap)#
exit
Router(config)#
transport type persistent webui input http-https-webui
*Apr 22 02:47:22.981: %UICFGEXP-6-SERVER_NOTIFIED_START: R0/0: psd:
Server wui has been
notified to start
Authentication and the Web User Interface
Users attempting to access the web user interface for a router are subject to the same authentication
requirements configured for that router. The web browser prompts all users for a name and password
combination, and the web browser then looks to the router configuration to see if a user should or should
not be granted access to the web user interface.
Only users with a privilege level of 15 can access the web user interface. Otherwise, authentication of
web user interface traffic is governed by the authentication configuration for all other traffic.
To configure authentication on your router, see
Configuring Authentication
.
Domain Name System and the Web User Interface
The Domain Name System (DNS) is a distributed database in which you can map hostnames to IP
addresses through the DNS protocol from a DNS server.
If the router is configured to participate in the Domain Name System, users can access the web user
interface by entering
http://
<
dns-hostname
> as the web browser address.
For information on configuring DNS, see
Configuring DNS
.
cts_Configuration_Guide_Chapter.html
Clocks and the Web User Interface
Requests to view the web user interface can be rejected by certain web browsers if the time as seen by
the web browser differs from the time as seen by the router by an hour or more.
For this reason, we recommend checking the router time using the
show clock
command before
configuring the router and, if the router time is not properly set, use the
clock set
and
clock timezone
commands for setting the router clock.
Similarly, the web browser’s clock source, which is usually the personal computer, must also have an
accurate time to properly access the web user interface.
The following message appears when the web browser and the router clocks are more than an hour apart:
Your access is being denied for one of the following reasons:
. Your previous session has timed-out, or
. You have been logged out from elsewhere, or
. You have not yet logged in, or
. The resource requires a higher privilege level login.