Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
Access Control Rule Admin Portal Access
Deployment Strategy on page 112
Configure Access Control Group on page 113
Configure Admin Access Policy Role on page 114
Configure Access Control Rule on page 116
Define Rule Precedence on page 119
Deployment Strategy
For enhanced security, the Portal Administration login page is now available under a proprietary URL:
<Management Interface IP Address>:8445/administration. The previous URL: <ICP
WLAN Interface IP Address>:443/administration is no longer supported for admin
access.
All network clients connected through a VLAN that is configured as the Management Port (port 5825)
have access to the new port 8445. This includes the following VLANs with management access:
• The Admin Interface.
• A physical interface configured with Mgmt trac enabled.
To access:
1. Go to Administration > System > Interfaces.
2. Scroll down to the list of Interfaces.
• Bridged@AC VLANS with Mgmt trac enabled.
To access:
1. Go to Configure > Policy > VLANs > Add.
2. Select Layer 3.
3. Select Mgmt trac.
Additionally, you can configure Access Control Rules to filter client access and limit exposure to the
Admin portal by associating members of the admin group to port 8445. This deployment strategy
involves configuring: Access Control Groups, policy roles, and captive portal definitions to define an
Access Control Rule for Admin access.
From Extreme Campus Controller, take the following steps:
1. Create an Access Control Group.
2. Create a Policy Role with Layer 3 and Layer 4 rule definitions.
112
Extreme Campus Controller Deployment Guide for version 5.46.03










