Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
Auth Type
WPA2 Enterprise 802.1x/EAP
AAA Policy
Local On-boarding
This option is not displayed for WLAN Networks that do not require authentication or
authorization. The value Local Onboarding refers to RADIUS requests that are directed through
the Extreme Campus Controller. Local Onboarding is the default value for WLAN Networks
configured for Internal Captive Portal. AAA Policy can only be configured for WLAN Networks
requiring MACAUTH, External Captive Portal, or EAP.
To use AAA Policy to bypass Extreme Campus Controller, create a policy with RADIUS servers
and a NAS IP address, then specify the policy here. To get started, go to Configure > AAA Policy
> Add. For more information, see the Extreme Campus Controller User Guide or Online Help.
Authentication Method
Default
Default AAA Authentication Method
Local
LDAP Configuration
None
Default Auth Role
Quarantine
Defines the default Accept Policy for a client attempting to join the network. When an
authenticated client does not meet rule conditions on an 802.1x AAA Network, the default policy
role is Quarantine.
Default VLAN
test2 (This is the VLAN we created for the AAA Network.)
3. Click Save.
Note
To activate the Scheduling button and schedule when network services are enabled, install
the Extreme Scheduler Application on Extreme Campus Controller. For more information, see
the Extreme Campus Controller User Guide located in the Extreme Networks documentation
portal.
Next, work with engine rules.
Related Topics
Creating an Engine Rule on page 67
Configuring
 a AAA Network Centralized Site with AAA Network
66 Extreme Campus Controller Deployment Guide for version 5.46.03










