Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
Table 17: Centralized Web Authentication Network Settings (continued)
Field Description
MAC-Based Authentication (Optional) Select this option to enable MBA. When selected,
multi-factor authentication is enabled.
The following parameter displays when MAC-based
Authentication is enabled:
• MBA Timeout Role. Select the role that will be assigned to a
wireless client during MAC-based authentication (MBA) if
the RADIUS server access request times out. If no MBA
Timeout Role is selected, then a RADIUS server timeout is
treated like an Access-Reject, which prevents the client from
accessing the network. Other options:
◦  — create a new role
◦  — edit role
◦
 — delete role
Captive Portal Type CWA
AAA Policy Specify the AAA Policy associated with the captive portal.
Define the RADIUS server used for authentication in the AAA
Policy. This is the IP address of the captive portal. See Figure 44
on page 130.
Default Auth Role Specify the default authorization role that is configured on
Extreme Campus Controller.
Default VLAN Specify the default VLAN that is configured on Extreme
Campus Controller.
Deploying Centralized Web Authentication CWA Network Settings — ISE
Extreme Campus Controller Deployment Guide for version 5.46.03 129










