Deployment Guide
Table Of Contents
- Table of Contents
- Preface
- About Extreme Campus Controller Deployment
- Configuring DHCP, NPS, and DNS Services
- Centralized Site with a Captive Portal
- Centralized Site with AAA Network
- Deploying a Mesh Network
- Configuring an External NAC Server for MBA and AAA Authentication
- Manage RADIUS Servers for User Authentication
- External Captive Portal on a Third-Party Server
- Access Control Rule Admin Portal Access
- Deploying Centralized Web Authentication
- Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
- Configuring an External Captive Portal Network
- Editing the Configuration Profile for Network and Roles
- Extreme Campus Controller Default Pass-Through Rule
- Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
- Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
- Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
- Deploying an ExtremeGuest Captive Portal
- Deploying Client Bridge
- Deploying an Availability Pair
- Deploying Universal APs
- Extreme Campus Controller Pair with ExtremeLocation and AirDefense
- ECP Local Authentication
- PHP External Captive Portal, Controller’s Firewall Friendly API
- Index
Firewall Friendly External Captive Portal Flow of Events
Typically, the third-party server is on the other side of a firewall from Extreme Campus Controller.
Integrating with a third-party server through a firewall is illustrated in Figure 35 on page 92. The main
participants in the deployment scenario are:
• The client being authenticated (‘user’).
• The Extreme Campus Controller that manages the AP that the user is communicating through.
• The firewall between the user and Extreme Campus Controller on one side and the ECP on the other.
• The ECP that performs the actual authentication.
Figure 35: Firewall Friendly ECP Event Flow with Extreme Campus Controller
FF-ECP on Extreme Campus Controller
The following numbered list corresponds to the numbers illustrated in Figure 35 on page 92.
1.0 - When the user sends HTTP trac, Extreme Campus Controller spoofs the destination web server.
1.1 - Trac is redirected to the ECP. Extreme Campus Controller tells the client's browser that the
resource it is requesting has temporarily been moved to another server (the ECP) .
Firewall Friendly External Captive Portal Flow of Events
External Captive Portal on a Third-Party Server
92 Extreme Campus Controller Deployment Guide for version 5.46.03










