Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
ECP Local Authentication
Scenario Outline on page 192
Deployment Strategy on page 192
Configuring External Captive Portal Network on page 193
Editing the Device Group Profile for ECP Network on page 195
Scenario Outline
The following scenario outlines an availability pair of Extreme Campus Controller appliances with
ExtremeWireless access point models. This scenario employs an External Captive Portal.
This deployment scenario oers the following configuration factors:
• Availability pair of Extreme Campus Controller appliances.
• Appliance capacity 32K-100K users
• MBA with local authentication and External Captive Portal.
Related Topics
Deployment Strategy on page 192
Configuring External Captive Portal Network on page 193
Deployment Strategy
1. Create a site with a device group for the AP3915 devices.
2. Configure an External Captive Portal.
3. Specify the network topology.
Specify Bridged@AP. ExtremeWireless APs support both Bridged@AC and Bridged@AP
topologies.
4. Configure an External Captive Portal network.
5. Engine Rules: The Extreme Campus Controller rules engine generates a default Unauthenticated
rule. There is no user interaction required on the Extreme Campus Controller. An authenticated rule
is generated from the External Captive Portal server. You must define a policy role on Extreme
Campus Controller that matches the authenticated role on the server. This can be a unique role or
default authenticated role like Enterprise User.
6. Go back to each device group and configure the configuration profile. Specify the External Captive
Portal network and the Extreme Campus Controller authenticated role that matches the ECP server
authenticated policy.
7. Create adoption rules for each device group.
192
Extreme Campus Controller Deployment Guide for version 5.46.03










