Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
Define Rule Precedence
The order of the Access Control Rules matter. Rules are evaluated from the top down. Figure 41 displays
an example Rules List. The rules are evaluated in order.
To access the Rules List, go to Onboard > Rules.
Figure 41: Access Control Rules List Order
In the following example, the MAC Address evaluates the following rules:
• Member of the Blacklist Group?
◦ Yes. MAC Address Quarantined.
◦ No. Evaluate next rule.
• Member of the Captive Portal Admin Group?
◦ Yes. Go to the captive portal Administration page.
◦ No. Evaluate next rule.
• Member of the Registered Guests Group?
◦ Yes. Present Captive Portal.
◦ No. Evaluate next rule.
• Unregistered Guest on Network Lab40-ICP?
◦ Yes. Present Captive Portal.
◦ No. Evaluate next rule.
• Unregistered Guest on Network Lab40-ECP?
◦ Yes. Present Captive Portal.
◦ No. Evaluate next rule.
• Default Catchall Rule.
◦ Access Denied
Related Topics
Default Access Control Groups on page 114
Access Control Rule Admin Portal Access
Define Rule Precedence
Extreme Campus Controller Deployment Guide for version 5.46.03 119










