Deployment Guide
Table Of Contents
- Table of Contents
 - Preface
 - About Extreme Campus Controller Deployment
 - Configuring DHCP, NPS, and DNS Services
 - Centralized Site with a Captive Portal
 - Centralized Site with AAA Network
 - Deploying a Mesh Network
 - Configuring an External NAC Server for MBA and AAA Authentication
 - Manage RADIUS Servers for User Authentication
 - External Captive Portal on a Third-Party Server
 - Access Control Rule Admin Portal Access
 - Deploying Centralized Web Authentication
 - Deploying ExtremeCloud IQ - SE as an External Captive Portal
- Deployment Strategy
 - Configuring an External Captive Portal Network
 - Editing the Configuration Profile for Network and Roles
 - Extreme Campus Controller Default Pass-Through Rule
 - Adding Extreme Campus Controller as a Switch to ExtremeCloud IQ - Site Engine
 - Editing the Unregistered Policy on ExtremeCloud IQ - Site Engine
 - Editing the ExtremeCloud IQ - Site Engine Profile for Policy and Location-Based Services
 
 - Deploying an ExtremeGuest Captive Portal
 - Deploying Client Bridge
 - Deploying an Availability Pair
 - Deploying Universal APs
 - Extreme Campus Controller Pair with ExtremeLocation and AirDefense
 - ECP Local Authentication
 - PHP External Captive Portal, Controller’s Firewall Friendly API
 - Index
 
Table 11: Parameters Available on the Redirection URL from Extreme Campus
Controller to the ECP (continued)
Parameter
Name
Parameter Value Required Notes
vlan ASCII-encoded
decimal number
No The VLAN ID of the VLAN/topology to which the
client is assigned at the moment of
authentication. The VLAN ID is a number in the
range 1 to 4094.
The VLAN ID is the containment VLAN of the
default action of the role to which the
authenticating client is assigned. A role’s default
action does not have to be “contain to VLAN”. If
the default action is not “Contain to VLAN” then
this attribute will be empty or not present.
vns Alphanumeric
String
No The name of the Virtual Network Service (VNS)
on which the client is authenticating. In Extreme
Campus Controller,this value is treated as the
ssid-name.
wlan ASCII-encoded
decimal string
Yes An internal identifier for the WLAN service on
which the client is authenticating. The wlan
attribute must be present in all redirection
responses (and redirected requests) sent by the
appliance. The ECP must return the wlan
attribute in the redirection back to the appliance
that it sends to the authenticating client’s
browser.
X-Amz-
Algorithm
Alphanumeric
String
No The identifier for the algorithm used to compute
the “X-Amz-Signature”. Only present when the
appliance is configured to sign the redirection.
This attribute must be present when the
appliance is configured to sign the redirection.
The value of this attribute is “AWS4-HMAC-
SHA256” and is not configurable. The signing
algorithm and the role of the identifier in it are
covered in more detail in section Verifying the
Signed Request on page 98.
X-Amz-
Credential
Alphanumeric
String
No The identifier for the account whose shared
secret was used to compute the “X-Amz-
Signature”. Only present when the appliance is
configured to sign the redirection. If the
appliance is configured to sign the redirection
then this field must be present. This is covered in
more detail in section Verifying the Signed
Request on page 98.
External Captive Portal on a Third-Party Server
The Redirection URL Sent from Extreme Campus
Controller
Extreme Campus Controller Deployment Guide for version 5.46.03 97










