
Configuring Internal Captive Portal Authentication for a Wired Profile
You can configure internal captive portal authentication when adding or editing a guest network created a wired
profile. You can use Instant UI or CLI to configure captive portal authentication.
In the Instant UI
To configure internal captive portal authentication for a wired profile:
1. Click the Wired link under More at the top right corner of the AOS-W Instant main window. The Wired window is
displayed.
2. Click New under Wired Networks to create a new network or select an existing profile for which you want to
enable 802.1X authentication and then click Edit.
3. In the New Wired Network or the Edit Wired Network window, ensure that all the required Wired and VLAN
attributes are defined, and then click Next
4. In the Security tab:
a. Select any of the following from the Splash page type drop-down list.
l Internal - Authenticated
l Internal - Acknowledged
b. Select Enabled from the MAC authentication drop-down list to enable the MAC authentication. For
information on MAC authentication, see Configuring MAC Authentication for a Network Profile on page 132.
c. Select any of the following from the Auth server 1drop-down list:
l Select a server from the list of servers if the server is already configured.
l Select Internal Server to authenticate user credentials at run time.
l Select New for configuring an new external RADIUSserver for authentication. For more information on
configuring external radius server, see Configuring an External Server for Authentication on page 124.
d. Select a value for Reauth interval to allow APs to periodically reauthenticate all associated and
authenticated clients.
e. If Internal Server is selected as an authentication server, under Internal server, click the User link to add
users for internal authentication. For more information about adding a user, see Configuring Users on page
129.
f. To exclude an uplink, select the uplink type for Disable if uplink type is.
5. Configure the required encryption parameters.
6. Click Next to configure access rules, and then click Finish to apply the changes.
7. Assign the profile to an Ethernet port. For more information, see Assigning a Profile to Ethernet Ports on page 116
In the CLI
To configure internal captive portal for a wired profile:
(Instant Access Point) (config)# wired-port-profile <profile-name>
(Instant Access Point) (wired ap profile <profile-name>)# type <guest>
(Instant Access Point) (wired ap profile <profile-name>)# captive-portal {<internal-
authenticated>| <internal-acknowledged>}
(Instant Access Point) (wired ap profile <profile-name>)# captive-portal {<internal-
authenticated>| <internal-acknowledged>} exclude-uplink {3G|4G|Wifi|Ethernet}
(Instant Access Point) (wired ap profile <profile-name>)# mac-authentication
(Instant Access Point) (wired ap profile <profile-name>)# auth-server <server1>
(Instant Access Point) (wired ap profile <profile-name>)# radius-reauth-interval <Minutes>
(Instant Access Point) (wired ap profile <profile-name>)# end
(Instant Access Point)# commit apply
AOS-W Instant 6.2.1.0-3.3| User Guide Authentication | 137
Kommentare zu diesen Handbüchern