Specifications
Configuring Web Web Portal WebAAA
17-24 Configuring AAA for Network Users
WebAAA Requirements and Recommendations
RoamAbout Switch Requirements
• WebAAAcertificate—AWebAAAcertificatemustbeinstalledontheswitch.Youcanusea
self‐signed(signedbytheRoamAboutSwitch)WebAAAcertificateautomaticallygenerated
byMSS,manuallygenerateaself‐signedone,orinstallonesignedbyatrustedthird‐party
certificateauthority(CA).(Formoreinformation,seeChapter 16,
ManagingKeysand
Certificates.)
Ifyouchoosetoinstallaself‐signedWebAAAcertificate,useacommonname(arequired
fieldinthecertificate),thatresemblesawebaddressandcontainsatleastonedot.WhenMSS
servestheloginpagetothebrowser,thepage’sURLisbasedonthe
commonnameinthe
WebAAAcertificate.
Herearesomeexamplesofcommonnamesintherecommendedformat:
– webaaa.login
– webaaa.customername.com
– webaaa.local
Herearesomeexamplesofcommonnamesthatarenotintherecommendedformat:
– webaaa
– ets_webaaa
–web
•UserVLAN—AnIPinterfacemustbeconfiguredontheuser’sVLAN.Theinterfacemustbe
inthesubneton
whichtheDHCPserverwillplacetheuser,sothattheswitchcan
communicatewithboththeclientandtheclient’spreferredDNSserver.(Toconfigurea
VLAN,see“ConfiguringandManagingVLANs”onpage 4‐14.)
Ifuserswillroamfromtheswitchwheretheyconnecttothenetworkto
otherswitches,the
systemIPaddressesoftheswitchesshouldnotbeintheweb‐portalVLAN.
AlthoughtheSSID’sdefaultVLANandtheuserVLANmustbethesame,youcanusea
locationpolicyontheswitchwheretheserviceprofileisconfiguredtomovetheuserto
anotherVLAN.TheotherVLANisnotrequiredtobestaticallyconfiguredontheswitch.The
VLANdoeshavethesamerequirements asotheruserVLANs,asdescribedabove.For
example,theuserVLANontheroamed‐toswitch musthaveanIPinterface,theinterface
mustbeinthesubnet
thathasDHCP,andthesubnetmustbethesameonetheDHCPserver
willplacetheuserin.
Note: MSS Version 5.0 does not require or support special user web-portal-ssid, where ssid is the
SSID the Web-Portal user associates with. Previous MSS Versions required this special user for
Web-Portal configurations. Any web-portal-ssid users are removed from the configuration during
upgrade to MSS Version 5.0. However, the web-portal-wired user is still required for Web Portal on
wired authentication ports.