Specifications

Configuring SODA Functionality
RoamAbout Mobility System Software Configuration Guide 20-5
Creating the SODA Agent with SODA Manager
SygateOnDemandManager(SODAManager)isaWindowsapplicationusedforconfiguring
securitypoliciesbasedonlocations,andforcreatingagentsthatenforcethosesecuritypolicies.For
informationonhowtouseSODAManagertocreatesecuritypolicies,seethedocumentationthat
camewiththeproduct.
YoucanuseSODA
ManagertocreateaSODAagent,configuringthelevelofsecuritydesired
accordingtotherequirementsofyournetwork.WhenaSODAagentiscreated(bypressingthe
ApplybuttoninSODAManager),asubdirectorycalledOnDemandAgentiscreatedinthe
C:\ProgramFiles\Sygate\SygateOnDemanddirectory.
Youplacethe
contentsoftheOnDemandAgentdirectoryintoa.zipfile(forexample,soda.ZIP)and
copythefiletotheRoamAboutSwitchusingTFTP,asdescribedin“CopyingtheSODAAgentto
theRoamAboutSwitch”onpage 206.
NotethefollowingwhencreatingtheSODAagentinSODAManager:
•Thefailure.htmland
success.htmlpages,whenspecifiedassuccessorfailureURLsinSODA
Manager,mustbeoftheformat:
https://hostname/soda/ssid/xxx.html
wherexxxreferstothenameoftheHTMLfilebeingaccessed.
•ThesuccessandfailureURLsconfiguredinSODAManagerarerequiredtohavetwo
keywordsinthem:/soda/andsuccess.htmlorfailure.html.The
/soda/keywordmustimmediatelyfollowthehostname.Thehostnamemustmatchthe
CommonNamespecifiedin
theWebAAAcertificate.
•Thelogoutpageisrequiredtohave/logout.htmlintheURL.
•ThehostnameofthelogoutpageshouldbesettoanamethatresolvestotheRoamAbout
Switch’s IPaddressontheVLANwheretheclientresides,orshouldbe theIPaddressofthe
RoamAboutSwitch
ontheWebPortalWebAAAVLAN;forexample:
https://10.1.1.1/logout.html
Thelogoutpageshouldnotpointtoacertificatehostnamethatisunreacha blefromtheclient’s
VLAN,norshoulditpointtoanIPaddressthatisonadifferentVLAN,whichcausesthe
sourceMACaddresstobechangedtotherouters(gatewayʹs)MACaddress.TheRoamAbout
Switchuses
theclient’ssourceMACaddressandsourceIPaddresscombinationtomakesure
theclientispermittedtologitselfout.
IfthesourceIPaddressisonadifferentVLAN,thenthesou r ceMACaddressdoesnotmatch
withthesession’sMACaddress,andthelogoutprocedurefails.
Followingthe
hostname,theURLofthelogoutpagemustexactlymatchlogout.html.You
cannotspecifyanyothersubdirectoriesintheURL.
•DonotusethePartnerIntegrationbuttoninSODAManagertocreateagentfiles.