Deployment Guide
Table Of Contents
- Table of Contents
- Preface
- About Extreme Campus Controller Deployment
- Configuring DHCP, NPS, and DNS Services
- Centralized Site with a Captive Portal
- Centralized Site with AAA Network
- Deploying a Mesh Network
- Configuring an External NAC Server for MBA and AAA Authentication
- Manage RADIUS Servers for User Authentication
- External Captive Portal on a Third-Party Server
- Access Control Rule Admin Portal Access
- Deploying Centralized Web Authentication
- Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
- Configuring an External Captive Portal Network
- Editing the Configuration Profile for Network and Roles
- Extreme Campus Controller Default Pass-Through Rule
- Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
- Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
- Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
- Deploying an ExtremeGuest Captive Portal
- Deploying Client Bridge
- Deploying an Availability Pair
- Deploying Universal APs
- Extreme Campus Controller Pair with ExtremeLocation and AirDefense
- ECP Local Authentication
- PHP External Captive Portal, Controller’s Firewall Friendly API
- Index
Figure 46: Redirect-80 rule redirects HTTP trac from Port 80
Table 18: Rule Configuration for Layer3/Layer4 Redirection Rules
Field Description
Name Provide a name for the rule. Example: Redirect-80 that
redirects trac on HTTP port 80.
Action Redirect
Protocol TCP
IP/Subnet User-Defined. Then specify the IP address of the captive portal.
The redirection role includes a rule that points to the CWA
server IP address.
Port Include at least one rule for HTTP port 80 or HTTPS port 443
The redirection role includes a rule for both HTTP port 80 and
HTTPS port 443
For more information about creating policy roles, see the Extreme Campus Controller User Guide.
Related Topics
Deployment Strategy on page 120
Configure AAA Policy — ISE on page 121
CWA Network Settings — ISE on page 127
Configure CWA on ExtremeControl on page 146
Configure Authorization Policy on Cisco® ISE Server on page 132
CWA Server Configuration — ISE
Configure an Authorization Policy on the CWA server to integrate with Extreme Campus Controller.
From the CWA server, you configure the redirect policy to return the specific redirect rule that you
configured on Extreme Campus Controller. The CWA Authorization Policy on the CWA server includes
three profiles: the Redirection Profile that is referenced from Extreme Campus Controller, an Allow
Profile, and a Deny Profile.
CWA integrates with a captive portal on a Cisco ISE server. The following topics outline how to
configure the captive portal server:
• Configure Authorization Policy on Cisco® ISE Server on page 132
Configure Authorization Policy on Cisco® ISE Server
Configure Centralized Web Authentication (CWA) to integrate with a Cisco® ISE server:
1. Configure the Authorization Profile (CWA_WebAuth) on the Cisco® ISE server. This profile references
the role (ACL_WEBAUTH_Redirect) that was configured on Extreme Campus Controller.
a. Go to Policy > Policy Elements > Results.
b. Select Authorization > Authorization Profiles.
CWA Server
Configuration — ISE Deploying Centralized Web Authentication
132 Extreme Campus Controller Deployment Guide for version 5.46.03










