246 CHAPTER 8: AAA C OMMANDSset authenticationwebConfigures an authentication rule to allow a user to log in to the networkusing a web page served by the WX switch. The rule can be activated ifthe user is not otherwise granted or denied access by 802.1X, or grantedaccess by MAC authentication.Syntax — set authentication web {ssid ssid-name | wired}user-glob method1 [method2] [method3] [method4] user-glob — A single user or a set of users.Specify a username, use the double-asterisk wildcard character (**) tospecify all usernames, or use the single-asterisk wildcard character (*)to specify a set of usernames up to or following the first delimitercharacter—either an at sign (@) or a period (.). (For details, see “UserGlobs” on page 28.) ssid ssid-name — SSID name to which this authentication ruleapplies. To apply the rule to all SSIDs, type any. wired — Applies this authentication rule specifically to usersconnected to a wired authentication port. method1, method2, method3, method4 — At least one and up to fourmethods that MSS uses to handle authentication. Specify one or moreof the following methods in priority order. MSS applies multiplemethods in the order you enter them.A method can be one of the following: local — Uses the local database of usernames and user groups onthe WX switch for authentication. server-group-name — Uses the defined group of RADIUS serversfor authentication. You can enter up to four names of existingRADIUS server groups as methods.RADIUS servers cannot be used with the EAP-TLS protocol.For more information, see “Usage.”Defaults — By default, authentication is unconfigured for all clients withnetwork access through MAP ports or wired authentication ports on theWX switch. Connection, authorization, and accounting are also disabledfor these users.Access — Enabled.History —Introduced in MSS Version 3.0.