Wireless Access

last person joined: 12 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Wifi Users Authentication /Captive Portal Authentication

This thread has been viewed 4 times
  • 1.  Wifi Users Authentication /Captive Portal Authentication

    Posted Mar 07, 2018 01:11 AM

    hi am new to Aruba WLC, we have 7010 controller installed as a standalone with 325 APs (5 qty).

    we have two SSID (Name: Office & Guest), we are plananing to enable user based authentication to get the network access on office SSID users, our requirements are mentioned below.

    1. Office SSID will configured with preshared Key, once we connected to office SSID with this preshared key user need to redirect to captive portal, so with captive portal user need to authenticte with Domain controller using their active directory username and password.

    so for captive portal authentication on controller we are planning to use Radius Server authentication method, so for this we are planning to install Radius Server on our Domain controller or any domain member server.

    could you please advice about can we achieve our requirements as per above mentioned plan if yes could you please share the configuration procedure for the same.
    if no could you please suggest the solution to achieve our requirements.



  • 2.  RE: Wifi Users Authentication /Captive Portal Authentication

    EMPLOYEE
    Posted Mar 07, 2018 07:53 AM

    It is possible. Which version of ArubaOS?

     

     



  • 3.  RE: Wifi Users Authentication /Captive Portal Authentication

    Posted Mar 07, 2018 08:51 AM

    controller software version is 6.5.1.4



  • 4.  RE: Wifi Users Authentication /Captive Portal Authentication
    Best Answer

    EMPLOYEE
    Posted Mar 07, 2018 09:24 AM

    The easy way would be to:

    1. Use the WLAN/LANWizard (configuration> Wizards> Campus WLAN) and create a separate Captive Portal SSID

    2.  When you are finished, go into the AAA profile for your WPA2-PSK SSID and change the initial role to the logon role for your newly created SSID.

     

    In short, there are quite a few profile that you have to configure to create a Captive Portal SSID.  If you use the Wizard to Create Another SSID, you can simply change the Initial Role for your WPA2-PSK SSID to the "logon-***" role for your new SSID and you will have a Captive Portal on your PSK SSID.  You will end up with another SSID, and you can simply remove the Virtual AP from the ap-group so that it does not broadcast.



  • 5.  RE: Wifi Users Authentication /Captive Portal Authentication

    Posted Mar 07, 2018 09:27 AM

    Thanks man.....