Deployment Guide
Table Of Contents
- Table of Contents
- Preface
- About Extreme Campus Controller Deployment
- Configuring DHCP, NPS, and DNS Services
- Centralized Site with a Captive Portal
- Centralized Site with AAA Network
- Deploying a Mesh Network
- Configuring an External NAC Server for MBA and AAA Authentication
- Manage RADIUS Servers for User Authentication
- External Captive Portal on a Third-Party Server
- Access Control Rule Admin Portal Access
- Deploying Centralized Web Authentication
- Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
- Configuring an External Captive Portal Network
- Editing the Configuration Profile for Network and Roles
- Extreme Campus Controller Default Pass-Through Rule
- Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
- Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
- Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
- Deploying an ExtremeGuest Captive Portal
- Deploying Client Bridge
- Deploying an Availability Pair
- Deploying Universal APs
- Extreme Campus Controller Pair with ExtremeLocation and AirDefense
- ECP Local Authentication
- PHP External Captive Portal, Controller’s Firewall Friendly API
- Index
The Authorization Policy will include three profiles: the Redirection Profile, an Allow Profile, and a
Deny Profile.
Note
The Allow Role will take eect once the user has been successfully authenticated to the
network. From the clients list on Extreme Campus Controller, you can view the client that
authenticated the network. The Allow Role is listed in the Role column.
3. The Authorization Profile generates the following attribute details:
• The redirection policy role.
• The redirection URL.
Related Topics
CWA with ISE Deployment on page 121
CWA with ExtremeControl Deployment on page 136
CWA with ISE Deployment
This section outlines the configuration settings for Centralized Web Authentication (CWA) integration
with Cisco ISE captive portal server.
Related Topics
Configure AAA Policy — ISE on page 121
CWA Network Settings — ISE on page 127
CWA Policy Redirection Role — ISE on page 130
Configure Authorization Policy on Cisco® ISE Server on page 132
Configure AAA Policy — ISE
You can create a AAA Policy that can be referenced through a WLAN Service, bypassing the local
Network Access Control on Extreme Campus Controller.
Note
AAA Policy can only be configured for WLAN networks requiring MACAUTH, External Captive
Portal, or EAP.
To configure a AAA network policy:
1. Go to Configure > Networks > WLANs and select a network.
AAA Policy is displayed for WLAN Networks that require authentication or authorization. The value
Local Onboarding refers to RADIUS requests that are directed through the Extreme Campus
Controller. Local Onboarding is the default value for WLAN Networks configured for Internal Captive
Portal.
Deploying Centralized Web Authentication
CWA with ISE Deployment
Extreme Campus Controller Deployment Guide for version 5.46.03 121










