Deployment Guide
Table Of Contents
- Table of Contents
- Preface
- About Extreme Campus Controller Deployment
- Configuring DHCP, NPS, and DNS Services
- Centralized Site with a Captive Portal
- Centralized Site with AAA Network
- Deploying a Mesh Network
- Configuring an External NAC Server for MBA and AAA Authentication
- Manage RADIUS Servers for User Authentication
- External Captive Portal on a Third-Party Server
- Access Control Rule Admin Portal Access
- Deploying Centralized Web Authentication
- Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
- Configuring an External Captive Portal Network
- Editing the Configuration Profile for Network and Roles
- Extreme Campus Controller Default Pass-Through Rule
- Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
- Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
- Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
- Deploying an ExtremeGuest Captive Portal
- Deploying Client Bridge
- Deploying an Availability Pair
- Deploying Universal APs
- Extreme Campus Controller Pair with ExtremeLocation and AirDefense
- ECP Local Authentication
- PHP External Captive Portal, Controller’s Firewall Friendly API
- Index
2. Configure the following Role settings:
Table 15: Role Parameter Settings
Field Description
Name Name of the Policy Role. Example: Captive Portal Admin
Bandwidth Limit Select this option to allow unlimited bandwidth. Select to set
the Class of Service value.
Default Action Determines the access control default action. If you do not
define policy rules for a role, the role's default action is applied
to all trac subject to that role. Policy Rules aect trac that
meets the filter criteria.
Example: For Role Captive Portal Admin the Default Action is
Deny. Deny packets that do not match a filter rule or deny
packets when a filter rule does not exist.
When a packet does match the filter rule action Allow packet
using the specified VLAN GTAC (222).
VLAN ID Policy roles default to the VLAN specified during network
configuration. You can specify a unique VLAN here. Select
to add a new VLAN option.
Example: GTAC (222)
Associated Profile Indicates profiles that this role is associated with. In our
example, Role is not associated with a Profile.
Rules Specify the following L3 L4 Rule:
Example: Allow trac from IP/Subnet 22.222.2./32 through
Port 8445.
Access Control Rule Admin Portal Access Configure Admin Access Policy Role
Extreme Campus Controller Deployment Guide for version 5.46.03 115










