D-Link DWS-1008 Product Manual - Page 311

Display of the Login WebAAA Requirements and Recommendations

Page 311 highlights

6. MSS authenticates the user by checking RADIUS or the switch's local database for the username and password entered by the user. If the user information is present, MSS authorizes the user based on the authorization attributes set for the user. Note: MSS ignores the VLAN-Name or Tunnel-Private-Group-ID attribute associated with the user, and leaves the user in the VLAN associated with the SSID's service profile (if wireless) or with the web-portal-wired user (if the user is on a wired authentication port). 7. After authentication and authorization are complete, MSS changes the user's session from a portal session with the name web-portal-ssid or web-portal-wired to a WebAAA session with the user's name. The session remains connected, but is now an identity-based session for the user instead of a portal session. 8. MSS redirects the browser to the URL initially requested by the user or, if the URL VSA is configured for the user, redirects the user to the URL specified by the VSA. 9. The web page for the URL to which the user is redirected appears in the user's browser window. Display of the Login Page When a WebAAA client first tries to access a web page, the client's browser sends a DNS request to obtain the IP address mapped to the domain name requested by the client's browser. The switch proxies this DNS request to the network's DNS server, then proxies the reply back to the client. If the DNS server has a record for the requested URL, the request is successful and the switch serves a web login page to the client. However, if the DNS request is unsuccessful, the switch displays a message informing the user of this and does not serve the login page. If the switch does not receive a reply to a client's DNS request, the switch spoofs a reply to the browser by sending the switch's own IP address as the resolution to the browser's DNS query. The switch also serves the web login page. This behavior simplifies use of the WebAAA feature in networks that do not have a DNS server. However, if the requested URL is invalid, the behavior gives the appearance that the requested URL is valid, since the browser receives a login page. Moreover, the browser might cache a mapping of the invalid URL to the switch IP address. If the user enters an IP address, most browsers attempt to contact the IP address directly without using DNS. Some browsers even interpret numeric strings as IP addresses (in decimal notation) if a valid address could be formed by adding dots (dotted decimal notation). For example, 208194225132 would be interpreted as a valid IP address, when converted to 208.194.225.132. WebAAA Requirements and Recommendations Note: MSS Version 5.0 does not require or support special user web-portal-ssid, where ssid is the SSID the Web-Portal user associates with. Previous MSS Versions required this special user for WebPortal configurations. Any web-portal-ssid users are removed from the configuration during upgrade to MSS Version 5.0. However, the web-portal-wired user is still required for Web Portal on wired authentication ports. D-Link DWS-1008 User Manual 292

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502

D-Link DWS-1008 User Manual
±·±
6. MSS authenticates the user by checking RADIUS or the switch’s local database for the
username and password entered by the user. If the user information is present, MSS
authorizes the user based on the authorization attributes set for the user.
Note:
MSS ignores the VLAN-Name or Tunnel-Private-Group-ID attribute associated with
the user, and leaves the user in the VLAN associated with the SSID’s service profile (if
wireless) or with the
web-portal-wired
user (if the user is on a wired authentication port).
7. After authentication and authorization are complete, MSS changes the user’s session
from a portal session with the name
web-portal
-ssid
or
web-portal-wired
to a
WebAAA session with the user’s name. The session remains connected, but is now an
identity-based session for the user instead of a portal session.
8. MSS redirects the browser to the URL initially requested by the user or, if the URL VSA is
configured for the user, redirects the user to the URL specified by the VSA.
9. The web page for the URL to which the user is redirected appears in the user’s browser
window.
Display of the Login Page
When a WebAAA client first tries to access a web page, the client’s browser sends a DNS request
to obtain the IP address mapped to the domain name requested by the client’s browser. The switch
proxies this DNS request to the network’s DNS server, then proxies the reply back to the client. If the
DNS server has a record for the requested URL, the request is successful and the switch serves a web
login page to the client. However, if the DNS request is unsuccessful, the switch displays a message
informing the user of this and does not serve the login page.
If the switch does not receive a reply to a client’s DNS request, the switch spoofs a reply to the browser
by sending the switch’s own IP address as the resolution to the browser’s DNS query. The switch also
serves the web login page. This behavior simplifies use of the WebAAA feature in networks that do not
have a DNS server. However, if the requested URL is invalid, the behavior gives the appearance that the
requested URL is valid, since the browser receives a login page. Moreover, the browser might cache a
mapping of the invalid URL to the switch IP address.
If the user enters an IP address, most browsers attempt to contact the IP address directly without using
DNS. Some browsers even interpret numeric strings as IP addresses (in decimal notation) if a valid
address could be formed by adding dots (dotted decimal notation). For example, 208194225132 would
be interpreted as a valid IP address, when converted to 208.194.225.132.
WebAAA Requirements and Recommendations
Note:
MSS Version 5.0 does not require or support special user
web-portal-
ssid
, where
ssid
is the
SSID the Web-Portal user associates with. Previous MSS Versions required this special user for Web-
Portal configurations. Any
web-portal-ssid
users are removed from the configuration during upgrade
to MSS Version 5.0. However, the
web-portal-wired
user is still required for Web Portal on wired
authentication ports.