240| Captive Port al Authentication DellPowerConnect W- Series ArubaOS 6.2 | User Guide
nAllows DHCP exchangesbet weenthe user and the DHCP server during business hourswhile blocking other
usersfrom responding to DHCP requests.
nAllows ICMP exchangesbetw eenthe user and the controller duringbusiness hours.
lblock-internal-access is a policy that you create that deniesuser access to the internal networks.
NOTE:The guest-logon user role configuration needs to include the name of the captive portal authentication profile instance.
Youcan m odifythe user role configuration after you create the captive portal authentication profile instance.
Creating a n Auth-guest U ser Role
The auth-guestuser role consists o f the following orderedpolicies:
lcplogout is a predefinedpolicy that allows captive portal logout.
lguest-logon-access is a policy that you create wit h the followingrules:
nAllows DHCP exchangesbet weenthe user and the DHCP server during business hourswhile blocking other
usersfrom responding to DHCP requests.
nAllows DNS exchanges betweent he userand the public DNS server during business hours. Traffic is source-
NATed using the IP interface of the controllerfor the VLAN.
lblock-internal-access is a policy that you create that deniesuser access to the internal networks.
lauth-guest-accessi s a policy that you create with t hefollowing rules:
nAllows DHCP exchangesbet weenthe user and the DHCP server during business hourswhile blocking other
usersfrom responding to DHCP requests.
nAllows DNS exchanges betweent he userand the public DNS server during business hours. Traffic is source-
NATed using the IP interface of the controllerfor the VLAN.
nAllows HTTP/S trafficfrom the user during business hours.Traffic is s ource-NATedusing the I interface of
the controllerfor the VLAN.
ldrop-and-logi sa policy that you create that denies all traffic andlogs the attempted network access.
Configuring Po licies and Role s in the WebU I

Creating a Time Range

To create a time range via the WebUI:
1. N avigate to the Configuration > Security > Access Contro l > Time Ranges paget o definet het ime range
“working-hours”.
2. Click A dd.
a. For Name, enterw orking-hours.
b. For Type, select Per iodic.
c. Click Add.
d. For Start D ay, click Weekday.
e. For Start Time, enter 07:30.
f. For End Time, enter 17:00.
g. Click Done.
3. Click A pply.
To create the guest-logon-accesspolicy vi a the WebUI:
1. N avigate to the Configuration > Security > Access Contro l > Policies page.
2. Select Add to add the guest-logon-access policy.