Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
Authentication Protocol
Authentication protocol type for the RADIUS server (PAP, CHAP, MS-CHAP, or MSCHAP2).
NAS IP Address
IP address of the Network Access Server (NAS).
NAS ID
A RADIUS attribute that identifies the client to a RADIUS server. The NAS-Identifier can be used
instead of an IP address to identify the client.
Call Station ID
Identifies a group of access points. The Call Station ID is often configured in a large network
using an external NAC or RADIUS server. Possible values are:
• Wired MAC: SSID
• BSSID (APs supported on a Centralized site only)
• Site Name
• Site Name: Device Group Name
• AP Serial Number
Note
Call Station ID allows for Zone authentication with a Centralized site.
• Site Campus
• Site Region
• Site City
Accounting Type
Determines when the appliance generates the accounting request. Valid values are:
• Start-Interim-Stop — Start record after successful login by the wireless device, interim record,
and an accounting stop record based on session termination.
• Start-Stop — Start record after successful login by the wireless device user and an accounting
stop record based on session termination.
The appliance sends the accounting requests to a remote RADIUS server.
Wait for client IP before starting accounting procedure
By default, the Accounting Start record is generated when the client is authenticated. Enable this
setting to generate the Accounting Start record when the client acquires a non local IP address.
Use this option for captive portals, which use RADIUS Accounting to learn of the client IP
address before providing the landing page.
Accounting Interim Interval
The number of seconds (60-3600) between each interim update for a specific session. Default
value is 60.
RADIUS Authentication Servers Mode
Select the availability behavior for RADIUS servers. Valid values are: Failover or Load Balance.
Configure
 AAA Policy — ExtremeControl Deploying Centralized Web Authentication
138 Extreme Campus Controller Deployment Guide for version 5.46.03










