Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
RADIUS Settings
Configure the following parameters, and then select Save.
Server Address
The address of the Local Onboarding Server. This value cannot be changed.
Timeout
Determines a timeout value, in seconds, for the RADIUS server connection.
Retries
Determines the number of times Extreme Campus Controller will attempt to authenticate an end
user.
For Local Onboarding, use the Retries and Timeout values with the RADIUS Server Health Check
parameters to detect RADIUS servers that are not responding and fail over to a second server if
necessary. When Local Onboarding bypassed is enabled, all RADIUS requests are sent to one
RADIUS server until it fails; then, the next RADIUS server is used.
Port
User Datagram Protocol (UDP) port number used for client authentication. UDP needs only one port
for full-duplex, bidirectional trac.
Shared Secret
The password that is used to validate the connection between the client and the RADIUS server.
Mask
Determines if the Shared Secret or password value is displayed on the user interface. Enable Mask to
display dots in place of the Shared Secret or password value. To display the password characters,
clear the Mask check box.
CWA Network Settings — ISE
To configure a Centralized Web Authentication (CWA) captive portal:
1. Go to Configure > Network > WLANS.
Deploying Centralized Web Authentication
CWA Network Settings — ISE
Extreme Campus Controller Deployment Guide for version 5.46.03 127










