Specifications
Configuring Web Web Portal WebAAA
RoamAbout Mobility System Software Configuration Guide 17-25
•Fallthruauthenticationtype—ThefallthruauthenticationtypeforeachSS IDandwired
authenticationportthatyouwanttosupportWebAAA,mustbesettoweb‐portal.Thedefa ult
authenticationtypeforwiredauthenticationportsandforSSIDsisNone(nofallthru
authenticationisused).
Tosetthefallthruauthenticationtypefor
anSSID,setitintheserviceprofilefortheSSID,
usingthesetservice‐profileauth‐fallthrucommand.Tosetitonawiredauthenticationport,
usetheauth‐fall‐thruweb‐portalparameterofthesetporttypewired‐authcommand.
• Authorizationattributes—WirelessWeb‐Portalusersgettheirauthorization
attributesfrom
theSSID’sserviceprofile.ToassignwirelessWeb‐PortaluserstoaVLAN,usethe
setservice‐profilenameattrvlan‐namevlan‐idcommand.
Web‐Portalusersonwiredauthenticationportsgettheirauthorizationattributesfromthe
specialuserweb‐portal‐wired.ToassignwiredWeb‐Portal
userstoaVLAN,usethesetuser
web‐portal‐wiredattrvlan‐namevlan‐idcommand.Bydefault,web‐portal‐wiredusersare
assignedtothedefaultVLAN.
•Portalusers(createdbyMSSautomatically)—TheportalaclACLcapturesalltheportaluser’s
trafficexceptforDHCPtraffic.Theportalaclhas
thefollowingACEs:
set security acl ip portalacl permit udp 0.0.0.0 255.255.255.255 eq 68
0.0.0.0 255.255.255.255 eq 67
set security acl ip portalacl deny 0.0.0.0 255.255.255.255 capture
MSSautomaticallycreatestheportalaclACLthefirsttimeyousetthefallthruauthentication
typeonanyserviceprofileorwiredauthenticationporttoweb‐portal.
–TheACLismappedtowirelessWeb‐Portalusersthroughtheserviceprofile.Whenyou
setthefallthruauthenticationtypeonaserviceprofile
toweb‐portal,portalaclissetasthe
Web‐PortalACL.TheACLisappliedtoaWeb‐Portaluser’strafficwhentheuser
associateswiththeserviceprofile’s SSID.
–TheACLismappedtoWeb‐Portalusersonawired‐authenticationportbytheFilter‐id.in
attributeconfiguredon
theweb‐portal‐wireduser.Whenyousetthefallt hru
authenticationtypeonawiredauthenticationporttoweb‐portal,MSScreatestheweb‐
portal‐wireduser.MSSsetsthefilter‐idattributeontheusertoportalacl.in.
– Authenticationrules—AwebauthenticationrulemustbeconfiguredfortheWebAAA
users.
ThewebrulemustmatchontheusernametheWebAAAuserwillenteronthe
WebAAAloginpage.(Thematchcanbeonausergloborindividualusername.)
Note: In MSS Version 4.1 and earlier, the VLAN was required to be statically configured on the
RoamAbout Switch where WebAAA was configured and through which the user accessed the
network. MSS Version 4.2 removes this restriction. The VLAN you want to place an authenticated
WebAAA user on does not need to be statically configured on the switch where Web Portal is
configured. If the VLAN you assign to a user is not statically configured on the VLAN where the user
accesses the network, the switch where the user accessed the network builds a tunnel to the switch
where the user’s VLAN is configured. That switch uses DHCP to assign an IP address to the user.
Caution: Without the Web-Portal ACL, WebAAA users will be placed on the network without any
filters.
Caution: Do not change the deny rule at the bottom of the Web-Portal ACL. This rule must be
present and the capture option must be used with the rule. If the rule does not have the capture
option, the Web Portal user never receives a login page. If you need to modify the Web-Portal ACL,
create a new one instead, and modify the service profile or web-portal-wired user to use the new
ACL. (See “Portal ACL and User ACLs” on page 17-26.)