Specifications

Configuring Web Web Portal WebAAA
17-24 Configuring AAA for Network Users
WebAAA Requirements and Recommendations
RoamAbout Switch Requirements
WebAAAcertificate—AWebAAAcertificatemustbeinstalledontheswitch.Youcanusea
selfsigned(signedbytheRoamAboutSwitch)WebAAAcertificateautomaticallygenerated
byMSS,manuallygenerateaselfsignedone,orinstallonesignedbyatrustedthirdparty
certificateauthority(CA).(Formoreinformation,seeChapter 16,
ManagingKeysand
Certificates.)
IfyouchoosetoinstallaselfsignedWebAAAcertificate,useacommonname(arequired
fieldinthecertificate),thatresemblesawebaddressandcontainsatleastonedot.WhenMSS
servestheloginpagetothebrowser,thepage’sURLisbasedonthe
commonnameinthe
WebAAAcertificate.
Herearesomeexamplesofcommonnamesintherecommendedformat:
webaaa.login
webaaa.customername.com
webaaa.local
Herearesomeexamplesofcommonnamesthatarenotintherecommendedformat:
webaaa
ets_webaaa
–web
•UserVLAN—AnIPinterfacemustbeconfiguredontheusersVLAN.Theinterfacemustbe
inthesubneton
whichtheDHCPserverwillplacetheuser,sothattheswitchcan
communicatewithboththeclientandtheclient’spreferredDNSserver.(Toconfigurea
VLAN,seeConfiguringandManagingVLANsonpage 414.)
Ifuserswillroamfromtheswitchwheretheyconnecttothenetworkto
otherswitches,the
systemIPaddressesoftheswitchesshouldnotbeinthewebportalVLAN.
AlthoughtheSSID’sdefaultVLANandtheuserVLANmustbethesame,youcanusea
locationpolicyontheswitchwheretheserviceprofileisconfiguredtomovetheuserto
anotherVLAN.TheotherVLANisnotrequiredtobestaticallyconfiguredontheswitch.The
VLANdoeshavethesamerequirements asotheruserVLANs,asdescribedabove.For
example,theuserVLANontheroamedtoswitch musthaveanIPinterface,theinterface
mustbeinthesubnet
thathasDHCP,andthesubnetmustbethesameonetheDHCPserver
willplacetheuserin.
Note: MSS Version 5.0 does not require or support special user web-portal-ssid, where ssid is the
SSID the Web-Portal user associates with. Previous MSS Versions required this special user for
Web-Portal configurations. Any web-portal-ssid users are removed from the configuration during
upgrade to MSS Version 5.0. However, the web-portal-wired user is still required for Web Portal on
wired authentication ports.