Deployment Guide
Table Of Contents
- Table of Contents
- Preface
- About Extreme Campus Controller Deployment
- Configuring DHCP, NPS, and DNS Services
- Centralized Site with a Captive Portal
- Centralized Site with AAA Network
- Deploying a Mesh Network
- Configuring an External NAC Server for MBA and AAA Authentication
- Manage RADIUS Servers for User Authentication
- External Captive Portal on a Third-Party Server
- Access Control Rule Admin Portal Access
- Deploying Centralized Web Authentication
- Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
- Configuring an External Captive Portal Network
- Editing the Configuration Profile for Network and Roles
- Extreme Campus Controller Default Pass-Through Rule
- Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
- Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
- Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
- Deploying an ExtremeGuest Captive Portal
- Deploying Client Bridge
- Deploying an Availability Pair
- Deploying Universal APs
- Extreme Campus Controller Pair with ExtremeLocation and AirDefense
- ECP Local Authentication
- PHP External Captive Portal, Controller’s Firewall Friendly API
- Index
Configure CWA on ExtremeControl
Configure CWA to integrate with an ExtremeControl server.
1. On the ExtremeControl server, create a policy mapping for the Extreme Campus Controller network:
• Map the policy to the Extreme Campus Controller network name.
• Provide the redirection rule that you created on Extreme Campus Controller as the Filter ID value.
• Provide the Redirection URL as the Cisco RADIUS attribute value pair (AVP). For example:
cisco-avpair=url-redirect=http://10.47.1.15:80/
Note
Do not include query parameters in the url-redirect. The following AVP is not valid:
cisco-avpair=url-redirect=http://10.47.1.15:80/?a=123, where ?a=123 is a query
parameter.
2. From the ExtremeControl server, go to Configuration > Profiles > Policy Mapping.
The rules engine assigns the policy Unregistered to the redirection and assigns the policy Enterprise
User when authenticated by the captive portal.
CWA Server Configuration — ExtremeControl Deploying Centralized Web Authentication
146 Extreme Campus Controller Deployment Guide for version 5.46.03










