Deployment Guide
Table Of Contents
- Table of Contents
- Preface
- About Extreme Campus Controller Deployment
- Configuring DHCP, NPS, and DNS Services
- Centralized Site with a Captive Portal
- Centralized Site with AAA Network
- Deploying a Mesh Network
- Configuring an External NAC Server for MBA and AAA Authentication
- Manage RADIUS Servers for User Authentication
- External Captive Portal on a Third-Party Server
- Access Control Rule Admin Portal Access
- Deploying Centralized Web Authentication
- Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
- Configuring an External Captive Portal Network
- Editing the Configuration Profile for Network and Roles
- Extreme Campus Controller Default Pass-Through Rule
- Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
- Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
- Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
- Deploying an ExtremeGuest Captive Portal
- Deploying Client Bridge
- Deploying an Availability Pair
- Deploying Universal APs
- Extreme Campus Controller Pair with ExtremeLocation and AirDefense
- ECP Local Authentication
- PHP External Captive Portal, Controller’s Firewall Friendly API
- Index
The following additional attributes (AVP) used by RFC5580 are supported:
• LOCATION-INFO
• LOCATION-DATA
Note
Site Location details are reported in LOCATION-DATA. For more information on Site
Location information, see the Users Guide.
• BASIC-LOCATION-POLICY-RULES
• OPERATOR-NAME (Described below)
Operator Name
RADIUS attribute comprised of the operator namespace identifier and the operator name. The
combination of operator name and namespace identifier uniquely identifies the owner of an
access network. The Operator Name cannot exceed 253 bytes. Valid values are:
• Tadig — Three-character Country Code followed by a two- character alphanumeric operator
ID
• Realm — Registered Domain Name of Operator
• E212 — Mobile Country Code or Mobile Network Code
• OneCC — Three-character Country Code followed by 1-6 uppercase ITU Carrier Codes
• None
RADIUS Authentication Servers
To add RADIUS servers for authentication, select Add. You can configure up to four RADIUS
servers for authentication.
We have the CWA server configured.
RADIUS Accounting Servers
To add RADIUS servers for accounting, select Add. You can configure up to four RADIUS servers
for accounting.
We have the CWA server configured.
Related Topics
RADIUS Settings on page 127
Deployment Strategy on page 120
CWA Network Settings - ExtremeControl on page 140
CWA Policy Redirection Role — ExtremeControl on page 144
CWA Server Configuration — ExtremeControl on page 145
CWA Network Settings - ExtremeControl
To configure a Centralized Web Authentication (CWA) captive portal:
1. Go to Configure > Network > WLANS.
CWA Network Settings - ExtremeControl
Deploying Centralized Web Authentication
140 Extreme Campus Controller Deployment Guide for version 5.46.03










