Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
Centralized Site with AAA Network
Deployment Strategy on page 65
Configuring a AAA Network on page 65
Creating an Engine Rule on page 67
Creating a Policy Role on page 67
Applying a AAA Network and Role to the Device Group on page 68
Deployment Strategy
The following strategy outlines how to create a Centralized site with a AAA network.
1. Add a Centralized site with a device group.
2. Configure a AAA network.
3. Work with engine rules.
4. Create a policy role.
5. Specify the network and role in the device group profile.
6. Create adoption rules.
Configuring a AAA Network
Using the same Centralized site: Site_ROW specify a separate tagged VLAN for the AAA Network,
defining a dierent IP address range for the AAA Network.
Note
You can configure more than one network on a single VLAN, but to configure a separate IP
address range for the AAA Network, we will create a separate VLAN.
1. Go to Configure > Policy > VLAN > Add to create a new VLAN for the AAA Network.
For more information, see Specifying B@AC Network Topology on page 57.
2. Go to Configure > Networks > Add and configure the following parameters:
Network Name
Test2-AAA
SSID
Test2-AAA
Status
Enable or disable the network service. Disabling the network service shuts o the service but
does not delete it.
Extreme Campus Controller Deployment Guide for version 5.46.03
65










