Cisco Web Authentication Proxy Service

This service is a web-based authentication service for guests or agent-less hosts. The Cisco switch hosts a captive portal A captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users. and the portal web page that collects username and password information. Subsequently, the switch sends a RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allows authentication, authorization, and accounting of remote users who want to access network resources.  request in the form of a Password Authentication Protocol (PAP Password Authentication Protocol. PAP validates users by password. PAP does not encrypt passwords for transmission and is thus considered insecure.) authentication request to Policy Manager. By default, this service uses the PAP authentication method. You can click on the Authorization and Audit End-hosts options to enable additional tabs.

To create a Cisco Web Authentication Proxy service:

1. Navigate to Configuration > Services, then select the Add link. The Add Services page opens.

2. From the Type drop down, select Cisco Web Authentication Proxy.The Cisco Web Authentication Proxy service configuration dialog opens:

Figure 1  Cisco Web Authentication Proxy Service

Configuring the Cisco Web Authentication Proxy service is similar to configuring the Aruba 802.1X Wireless service except that the Posture Compliance and Profile Endpoints options are not available. For more information on configuration, see Aruba 802.1X Wireless Service.