Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
AAA Policy
Local Onboarding
Trac passes through the internal Network Access Control engine, which is configured to
proxy trac to the Extreme Management Center or ExtremeCloud IQ - Site Engine server
control engines.
Note
It is possible to authenticate directly to the AAA RADIUS server. Refer to the
Extreme Campus Controller User Guide for information about AAA RADIUS
Authentication.
Authentication Method
Proxy RADIUS
Primary RADIUS
IP address of the Access Control Engine.
Configure a primary and backup if you have more than one Access Control Engine.
Authenticate Locally for MAC
Must be Disabled for external captive portal on the NAC server.
Default Auth Role
Enterprise User
Default VLAN
Bridged at AP Untagged
2. Select Advanced and configure the following parameters:
RADIUS Accounting
Enabled
Pre-authenticated idle timeout
Default value: 300 seconds
Post-authenticated idle timeout
Default value: 1800 seconds
Maximum session timeout
Default value: 0 seconds
End-systems are re-authenticated on Extreme Campus Controller, not from the Extreme
Management Center or ExtremeCloud IQ - Site Engine Access Control Engine. Therefore, Extreme
Campus Controller ignores Extreme Management Center or ExtremeCloud IQ - Site Engine re-
authentication requests to modify filter-ids (policies). Modification of these timeout values initiates
re-authentication from the Extreme Campus Controller to the Extreme Management Center or
Configuring
 an External Captive Portal Network
Deploying ExtremeCloud IQ - SE as an External Captive
Portal
152 Extreme Campus Controller Deployment Guide for version 5.46.03










