Specifications

Configuring Web Web Portal WebAAA
RoamAbout Mobility System Software Configuration Guide 17-25
•Fallthruauthenticationtype—ThefallthruauthenticationtypeforeachSS IDandwired
authenticationportthatyouwanttosupportWebAAA,mustbesettowebportal.Thedefa ult
authenticationtypeforwiredauthenticationportsandforSSIDsisNone(nofallthru
authenticationisused).
Tosetthefallthruauthenticationtypefor
anSSID,setitintheserviceprofilefortheSSID,
usingthesetserviceprofileauthfallthrucommand.Tosetitonawiredauthenticationport,
usetheauthfallthruwebportalparameterofthesetporttypewiredauthcommand.
Authorizationattributes—WirelessWebPortalusersgettheirauthorization
attributesfrom
theSSID’sserviceprofile.ToassignwirelessWebPortaluserstoaVLAN,usethe
setserviceprofilenameattrvlannamevlanidcommand.
WebPortalusersonwiredauthenticationportsgettheirauthorizationattributesfromthe
specialuserwebportalwired.ToassignwiredWebPortal
userstoaVLAN,usethesetuser
webportalwiredattrvlannamevlanidcommand.Bydefault,webportalwiredusersare
assignedtothedefaultVLAN.
•Portalusers(createdbyMSSautomatically)—TheportalaclACLcapturesalltheportalusers
trafficexceptforDHCPtraffic.Theportalaclhas
thefollowingACEs:
set security acl ip portalacl permit udp 0.0.0.0 255.255.255.255 eq 68
0.0.0.0 255.255.255.255 eq 67
set security acl ip portalacl deny 0.0.0.0 255.255.255.255 capture
MSSautomaticallycreatestheportalaclACLthefirsttimeyousetthefallthruauthentication
typeonanyserviceprofileorwiredauthenticationporttowebportal.
–TheACLismappedtowirelessWebPortalusersthroughtheserviceprofile.Whenyou
setthefallthruauthenticationtypeonaserviceprofile
towebportal,portalaclissetasthe
WebPortalACL.TheACLisappliedtoaWebPortaluserstrafficwhentheuser
associateswiththeserviceprofile’s SSID.
–TheACLismappedtoWebPortalusersonawiredauthenticationportbytheFilterid.in
attributeconfiguredon
thewebportalwireduser.Whenyousetthefallt hru
authenticationtypeonawiredauthenticationporttowebportal,MSScreatestheweb
portalwireduser.MSSsetsthefilteridattributeontheusertoportalacl.in.
Authenticationrules—AwebauthenticationrulemustbeconfiguredfortheWebAAA
users.
ThewebrulemustmatchontheusernametheWebAAAuserwillenteronthe
WebAAAloginpage.(Thematchcanbeonausergloborindividualusername.)
Note: In MSS Version 4.1 and earlier, the VLAN was required to be statically configured on the
RoamAbout Switch where WebAAA was configured and through which the user accessed the
network. MSS Version 4.2 removes this restriction. The VLAN you want to place an authenticated
WebAAA user on does not need to be statically configured on the switch where Web Portal is
configured. If the VLAN you assign to a user is not statically configured on the VLAN where the user
accesses the network, the switch where the user accessed the network builds a tunnel to the switch
where the user’s VLAN is configured. That switch uses DHCP to assign an IP address to the user.
Caution: Without the Web-Portal ACL, WebAAA users will be placed on the network without any
filters.
Caution: Do not change the deny rule at the bottom of the Web-Portal ACL. This rule must be
present and the capture option must be used with the rule. If the rule does not have the capture
option, the Web Portal user never receives a login page. If you need to modify the Web-Portal ACL,
create a new one instead, and modify the service profile or web-portal-wired user to use the new
ACL. (See “Portal ACL and User ACLs” on page 17-26.)