Using Captive Po rtal with a PEFNG License
The PEFNG license provides identity-based security for wired and wireless users. There are two user roles that are
important for captive portal:
lDefault userrole, which you specify in the captive portal authentication profile, is the role granted to clients
upon captive portal authentication. This can be the predefined guest system role.
lInitial user role,which you specify i nt heA AA profile, directs clients who associate to the SSID to captive portal
wheneverthe user initiates a Web browser connection. This can be the predefined logon system role.
The captive portal authentication profile specifies the captive portal login page ando therc onfigurable
parameters.The initial user role configuration must include the applicablecaptive po rtalauthenticatio nprofile
instance.
NOTE:MAC-based authentication, if enabled on the controller, takesprecedence over captive portal authentication.
The followingare the basic tasks for configuring captive portal using role-based access provided by the Policy
EnforcementFi rewallsoftware module. Note that you must install the PEFNG license before proceeding (see
Software Licenses on page 100).
lConfigurethe user role for a default user.
Create andco nfigureuser roles and policies for guest or registered captive portal users. (SeeR oles andP olicies on
page 296 for more information about configuring policies and user roles.)
lCreate a server group.
If you are configuringcaptive portal for registered users, configuret heserver(s) and create the server group.(See
Authentication Servers on page 168for more information about configuring authentication servers and server
groups.)
NOTE:If you are using the controller’s internal database for user authentication, use the predefined “Internal”server group. You
needto configure entries in the internal database, as described in Authe nticationS ervers on page 168.
lCreate the captive portal authentication profile.
Create andco nfigurean instance of the captive portal authentication profile. Specify the default userrole for
captive portal users.
lConfigurethe i nitial user role.
Create andco nfigurethe initial user role for captive portal. You need to includet hepredefined captiveportal
policy, which directs clients to the captive portal, in the initial user role configuration.
You also needto specify the captive portal authentication profile instance in the initial user role configuration.
For example,if you areusi ngt he predefinedlogon system role for the initial role, you need to edit the role to
specify the captive portal authentication profile instance.
lCreate the AAA Profile.
Create andco nfigurean instance of the AAA profile. Specify the initial user role.
lCreate the SSID Profile “ssid_c-portal”.
Create andconfigure an instance of thevi rtualAP profile that you apply to anA P groupor AP name. Specify the
AAA profile you just created.
lCreate the Virtual AP Profile “vp_c-portal”.
Create andco nfigurean instance of the SSID profile for the virtual AP.
DellPowerConnect W- Series ArubaOS 6.2 | UserGuide CaptivePortal Authentication |237