Installation Instructions
Table Of Contents
- A3 Installation and Usage Guide
- No Registration VLAN Version
- Table of Contents
- Introduction
- Deployment Modes
- Enforcement Modes
- Installation
- Network Topology
- Clustering
- Table of Addresses and VLANs
- Initial A3 Configuration
- ExtremeCloud IQ Setup
- Authentication Methods
- A3 Configuration Flow
- Certificates and PKI
- Portal Modules
- Security Events and Scan Engines
- Provisioning
- Firewall Integration
- Use Case 1: Guest Access with Captive Web Portal
- Use Case 2: Active Directory Authentication
- Use Case 3: Local User Authentication
- Use Case 4: Sponsored Access
- Use Case 5: EAP-TLS Authentication
- Use Case 6: Guest Access with External Captive Web Portal
- Use Case 7: Headless IoT Devices
- Use Case 8: Eduroam
- Advanced Topics
- A3 Troubleshooting
- Glossary
- Index
Layer 3 Hybrid Out-of-Band Deployment Deployment Modes
Part Number: A3 Installation and Usage Guide Community 5
1. Define routed networks for interfaces in A3.
2. Setup up a DHCP relay on the L3 switch/router connected to A3.
3. Configure firewall rules on the access point or access switch to limit client access to
A3 and required services.
An example of a Layer 3 configuration is available in the Initial A3 Configuration chapter.
Layer 3 Hybrid Out-of-Band Deployment
Layer 3 hybrid OOB (out-of-band)deployments are a new means of connecting
authenticating clients. As opposed to earlier techniques a registration VLAN is not
required and Layer 2 connectivity between clients and A3 is likewise not required. The A3
server and access point or switches need only have Layer 3 connectivity.
This deployment mode is shown in the figure below. An Extreme Networks AP is used in
this figure, but an access switch or other intelligent network device can be used. This
deployment model may be used with VLAN, Web Auth, and RADIUS enforcement as
described in Enforcement Modes.
Access point L3 switch/router
DHCP, DNS
RADIUS
HTTP/HTTPS
Wireless client
DNS
DHCP
A3
Management VLAN
Logical
Uses DHCP, DNS,
HTTP and HTTPS










