Defining Authentication For A Wm-Ad For Captive Portal - Extreme Networks Summit WM User Manual

Table of Contents

Advertisement

Table 14: Vendor Specific Attributes
Attribute Name
ID
Extreme-URL-
1
Redirection
Extreme-AP-Name
2
Extreme-AP-Serial
3
Extreme-WM-AD-
4
Name
Extreme-SSID
5
Extreme-BSS-MAC
6
The first five of these VSAs provide information on the identity of the specific Altitude AP that is
handling the wireless device, enabling the provision of location-based services.
The RADIUS message also includes RADIUS attributes Called-Station-Id and Calling-Station-Id in order
to include the MAC address of the wireless device.
NOTE
Extreme-URL-Redirection is supported by MAC-based authentication.

Defining authentication for a WM-AD for Captive Portal

For Captive Portal authentication, the wireless device connects to the network, but can only access the
specific network destinations defined in the non-authenticated filter. For more information, see
"Defining non-authenticated filters" on page
internal or external, which presents a Web login page - the Captive Portal. The wireless device user
must input an ID and a password. This request for authentication is sent by the Summit WM Controller
to a RADIUS server or other authentication server. Based on the permissions returned from the
authentication server, the Summit WM Controller implements policy and allows the appropriate
network access.
Captive Portal authentication relies on a RADIUS server on the enterprise network. There are three
mechanisms by which Captive Portal authentication can be carried out:
Internal Captive Portal - The Summit WM Controller displays the Captive Portal Web page, carries
out the authentication, and implements policy.
External Captive Portal - After an external server displays the Captive Portal Web page and carries
out the authentication, the Summit WM Controller implements policy.
External Captive Portal with internal authentication - After an external server displays the Captive
Portal Web page, the Summit WM Controller carries out the authentication and implements policy.
Summit WM User Guide, Software Version 5.3
Type
Messages
string
Returned from
RADIUS server
string
Sent to RADIUS
server
string
Sent to RADIUS
server
string
Sent to RADIUS
server
string
Sent to RADIUS
server
string
Sent to RADIUS
server
183. One of these destinations should be a server, either
Description
A URL that can be returned to redirect a
session to a specific Web page.
The name of the AP the client is associating to.
It can be used to assign policy based on AP
name or location.
The AP serial number. It can be used instead of
(or in addition to) the AP name.
The name of the WM Access Domain the client
has been assigned to. It is used in assigning
policy and billing options, based on service
selection.
The name of the SSID the client is associating
to. It is used in assigning policy and billing
options, based on service selection.
The name of the BSS-ID the client is
associating to. It is used in assigning policy and
billing options, based on service selection and
location.
167

Advertisement

Table of Contents
loading

Table of Contents