web-authentication (Access)
Syntax
web-authentication { banner { success success; } default-profile profile-name; timeout seconds; }
Hierarchy Level
[edit access firewall-authentication ] [edit logical-systems name tenants name access firewall-authentication], [edit tenants name access firewall-authentication]
Description
Specify that users go through the Web authentication process. The user uses HTTP or HTTPS to access an IP address on the device that is enabled for Web authentication. In this scenario, the user does not use HTTP or HTTPS to access the IP address of the protected resource. The user is prompted for a username and password, which are verified by the device. Subsequent traffic from the user or host to the protected resource is allowed or denied based on the results of this authentication. This method of authentication differs from pass-through authentication in that users need to access the protected resource directly after accessing the Web authentication IP address and being authenticated.
Options
banner success; | Configure the banner that appears to users during the Web authentication process. The banner appears during login, after successful authentication, and after failed authentication. |
default-profile profile-name | Specify the authentication profile to use if no profile is specified in a policy. |
timeout seconds | Specify the If you do not specify a timeout value, and if the web authentication process takes more than 3
seconds, your browser may display
|
Required Privilege Level
access—To view this statement in the configuration.
access-control—To add this statement to the configuration.
Release Information
Statement introduced in Junos OS Release 8.5.
HTTPS for Web authentication is supported on SRX5400, SRX5600, and SRX5800 devices starting from Junos OS Release 12.1X44-D10 and on vSRX Virtual Firewall, SRX300, SRX320, SRX340, SRX345, SRX380, SRX550M, and SRX1500 Services Gateways starting from Junos OS Release 15.1X49-D40.
Option timeout
introduced in Junos OS Release 15.1X49-D130.