Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
Network with Pass-Through External RADIUS
The following procedure outlines how to configure a network and associate it with a Pass-Through
External RADIUS accept policy. The following network types are described:
• MBA Network
• AAA Network
Related Topics
Configuring an MBA Network on page 83
Configuring a AAA Network on page 84
Configuring an MBA Network
To create the MBA network associated to a Pass-thru External RADIUS accept policy. Take the following
steps:
1. Configure a RADIUS server for AAA authentication.
• Log in to Extreme Campus Controller and go to Onboard > AAA > Radius Server and add a new
RADIUS server.
• Configure the following parameters:
Radius Server IP Address
Add the NAC IP address
Shared Secret
Provide the NAC Shared Secret.
Note
To find the Shared Secret of the NAC Manager, go to:
Advanced NAC Configuration Settings > Global and Appliance Settings >
Appliance Settings.
2. Create a new network.
• Enable MAC-based authentication (MBA) and choose an appropriate MBA Timeout Role.
• Clear the Authenticate Locally for MAC check box.
• Choose RADIUS as the Authentication Method and select the NAC added in Step 1 as the Primary
RADIUS.
• Select a Default VLAN.
•
Click Save.
3. Add a new rule.
• From Extreme Campus Controller, navigate to Onboard > Rules.
• Click Add.
• In the Location Group drop-down menu, select Network: <name of your network>.
• From the Accept Policy field:
◦ To configure a Default Auth Role Policy: select Use Default Auth Role.
Configuring
 an External NAC Server for MBA and AAA
Authentication Network with Pass-Through External RADIUS
Extreme Campus Controller Deployment Guide for version 5.46.03 83










