Deployment Guide

Table Of Contents
%21%21&username=test&wlan=1&X-Amz-
Signature=48389399c4b9e237ff64bbbd203a9abe272b8df513dff1eae8202df82ceb2c34
Table 13: Parameters that can be included in a Signed Redirection Response from the
ECP
Parameter
Name
Parameter Value Mandatory Notes
dest URL Conditional The <dest> parameter is required only if the
appliance is configured to redirect the client to its
original destination. The appliance directs the
client’s browser to an error page if it is configured
to redirect to the original destination and the
<dest> parameter is not returned to the
appliance.
opt27
In the RADIUS
protocol
option
number 27 is
the Session-
Timeout
attribute.
Base 10 Number No The maximum amount of time, in seconds, that
the current session can last before being
terminated. If not specified, the default for the
WLAN Service is applied to the authenticated
client.
role Alphanumeric
String
No The name of an access control role defined on
Extreme Campus Controller. The appliance
applies this role to the remainder of the
authorized client’s session. If a role parameter is
not provided, the appliance uses the default
authenticated role of the VNS that the
authenticated client is accessing.
token Alpha-numeric
String
Yes An identifier for the user’s wireless session hosted
on the appliance that performed the redirection.
username Alpha-numeric
String
Yes The user name is mandatory even if the URL is
signed. It is used to identify the client in reports
and accounting messages, even if it is not used to
authenticate the client.
wlan Numeric String Yes An identifier for the WLAN Service that the client
is using to access the network.
X-Amz-
Algorithm
Alpha-numeric
string
Yes The identifier for the algorithm used to compute
the “X-Amz-Signature”. This attribute must be
present when the ECP is acting as the final
authorizing authority. The value of this attribute is
“AWS4-HMAC-SHA256” and is not configurable.
The signing algorithm and the role of the
identifier in it are covered in more detail in section
Verifying the Signed Request on page 98.
Case 2: When the ECP is the Final Authority External Captive Portal on a Third-Party Server
110 Extreme Campus Controller Deployment Guide for version 5.46.03