Deployment Guide

Table Of Contents
Consecutive failed Authentications
The number of failed authentication attempts. Valid values are 1 to 10. Default value is 5.
Elapsed time for failed Authentications (Seconds)
The threshold in seconds that determines if the client authentication requests are blocked.
This is the window of time in which the failed authentication attempts occur. Valid values are
1 to 10 seconds. The default value is 3 seconds.
Quiet Timeout (Seconds)
The amount of time that authentication requests from the client are blocked before its
RADIUS requests are forwarded to the RADIUS server again. Valid values are 1 to 300
seconds. The default value is 300 seconds (5 minutes).
By default, if 5 attempts are made within 3 seconds, the client authentication requests are
blocked for 300 seconds (5 minutes), and RADIUS requests from that client are ignored. After 5
minutes, client RADIUS requests are forwarded to the RADIUS server again.
Note
In Failover mode, the Deny list is published to the peer Extreme Campus Controller.
Operator Name
RADIUS attribute composed of the operator namespace identifier and the operator name. The
combination of operator name and namespace identifier uniquely identifies the owner of an
access network. The Operator Name cannot exceed 253 bytes. Valid values are:
Tadig — Three-character Country Code followed by a two- character alphanumeric operator
ID
Realm — Registered Domain Name of Operator
E212 — Mobile Country Code or Mobile Network Code
OneCC — Three-character Country Code followed by 1-6 uppercase ITU Carrier Codes
None
RADIUS Authentication Servers
To add RADIUS servers for authentication, select Add. You can configure up to four RADIUS
servers for authentication.
We have the CWA server configured.
RADIUS Accounting Servers
To add RADIUS servers for accounting, select Add. You can configure up to four RADIUS servers
for accounting.
We have the CWA server configured.
Related Topics
RADIUS Settings on page 127
Deployment Strategy on page 120
CWA Network Settings — ISE on page 127
CWA Policy Redirection Role — ISE on page 130
Configure Authorization Policy on Cisco® ISE Server on page 132
Configure
AAA Policy — ISE Deploying Centralized Web Authentication
126 Extreme Campus Controller Deployment Guide for version 5.46.03