Deployment Guide

Table Of Contents
Table 23: External Captive Portal Settings (continued)
Field Description
Auth Type Define the authorization type. Valid values are:
Open —Anyone is authorized to use the network. This
authorization type has no encryption. The Default Auth role
is the only supported policy role.
WEP — Static Wired Equivalent Privacy (WEP) oers keys
for a selected network, that match the WEP mechanism
used on the rest of the network. Each AP can participate in
up to 50 networks. Specify one WEP key per network. This
option is oered to support legacy APs.
WPA2 with PSK — Network access is allowed to any client
that knows the pre-shared key (PSK). All data between the
client and the AP is AES encrypted using the shared secret.
Privacy is based on the IEEE standard, and privacy settings
are editable. If MAC-based authentication (MBA) is enabled,
you can assign dierent roles to dierent devices with a
PSK because MBA distinguishes between dierent devices.
If MBA is not enabled, then devices with a PSK use the
Default Auth role only.
WPA2 Enterprise w/ RADIUS — Supports 802.1X
authentication with a RADIUS server, using AES encryption.
This method can be used with client certificate-based
authentication (EAP-TLS). All 802.1X protocols are
supported.
Note: Captive Portal is not supported when using WPA2
Enterprise w/ RADIUS. An exception is Centralized Web
Authentication (CWA). CWA captive portal supports WPA2
Enterprise w/ RADIUS.
Privacy Settings
Protected Management Frames — Management Frames are
the signaling packets used in the 802.11 wireless standard to
allow a device to negotiate with an AP. PMF adds an
integrity check to control packets being sent between the
client and the access point. Valid values are:
Enabled. Supports PMF format but does not require it.
Disabled. Does not address PMF format. Clients connect
regardless of format.
Required. Requires all devices use PMF format. This
could result in older devices not connecting.
WPA3 - Personal with SAE — 128-bit encryption.
AP3xx running ExtremeWireless WiNG 7.3x and later.
AP4xx running ExtremeWireless WiNG 7.3x and later.
AP5xx running ExtremeWireless WiNG 7.2x and later.
WPA3 uses a pre-shared key (PSK) and Simultaneous
Authentication of Equals (SAE). WPA3 oers an augmented
Configuring
External Captive Portal Network ECP Local Authentication
194 Extreme Campus Controller Deployment Guide for version 5.46.03