Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
IP Address of the External NAC added in Step 1.
Default Auth Role
Select a role other than Enterprise User.
Default VLAN
Select a Default VLAN. B@AP VLAN ID
Note
Both B@AP and B@AC are supported for NAC.
3. Select Save.
4. Create a policy rule.
Go to Onboard > Rules and configure the following parameters:
Location Group
Network: <name of your network>
Accept Policy
• To configure a Default Auth Role Policy, select Use Default Auth Role.
• To configure a Pass-Through External RADIUS Accept Policy, select Pass Through External
RADIUS.
5. Select Save.
On the NAC Manager:
6. Edit the rule you created on Extreme Campus Controller here.
Configure the following parameters:
Authentication Method
802.1x
End-System Group
Any
7. Select Save and enforce the NAC.
On Extreme Campus Controller:
8. Assign the network created previously and its Default Auth Role to a site and save.
• Go to Configure > Sites and select a site.
• Select the Device Groups tab and select a device group.
• Beside the Profile field, select 
 to edit the device group profile.
• Go to the Networks tab and select the configured network.
• Go to the Roles tab and select the configured Default Auth Role.
Associate clients to the SSID of the Network, when prompted for the username and password, use the
username and password created with the New User. The external NAC server matches the rule you
created under New Rule and upon successful authentication sends an Access-Accept and a Filter-ID
Enterprise User. The Extreme Campus Controller Access Control engine ignores the Filter-ID and applies
the Default Auth Role that was configured under Network Settings.
Configuring
 a AAA Network
Configuring an External NAC Server for MBA and AAA
Authentication
82 Extreme Campus Controller Deployment Guide for version 5.46.03










