...
RADIUS portal authorisation method is supported on the access point (next thereafter "AP").
The client connects to an open SSID. When the client first connects, there is no account for the client in the external system (RADIUS server) yet, therefore all client traffic is blocked except:
...
- username – user name;
- password – user password;
- redirect_url – URL that the client originally requested as the portal may have spoofed the address. In our example, the client tried to connect to http://www.msftconnecttest.com, but was redirected to https://eltex-co.ru;
- error_url – URL for redirecting the client in case of authorisation error. This parameter is not used in our example.
...
Create a whitelist of URLs, it can contain URLs and/or RegExp. Access to the specified addresses will be allowed before authorisation.
Блок кода object-group url white_url url eltex-co.ru regexp '(.+\.)eltex-co\.com' exit
Create a whitelist of IP addresses, access to the specified addresses will be allowed before authorisation. You can add to the whitelist the addresses of subnets that are required for authorisation.
Блок кода object-group network white_ip ip prefix 192.168.0.0/24 exit
Create portal-profile.
Parameters description:
redirect-url – portal url – portal address;
age-timeout – the time interval during which the access point "remembers" the client and does not perform MAB authorisation;
verification-mode – portal mode – portal operation mode;
white-list domain – URL whitelist;
white-list address – IP addresses whitelist.Блок кода wlc portal-profile portal-pr redirect-url https://eltex-co.ru age-timeout 10 verification-mode external-portal white-list domain white_url white-list address white_ip exit exit
Информация With verification-mode external-portal, parameters are automatically added to the specified URL in redirect-url so that the resulting URL has the form:
Блок кода https://eltex-co.ru/?switch_url=<SWITCH_URL>&ap_mac=<AP_MAC>&client_mac=<CLIENT_MAC>&wlan=<SSID>&redirect=<ORIGINAL_URL>
If you need to change the names of the parameters switch_url, ap_mac, client_mac, wlan, redirect you can need to be changed, it is possible to specify the line yourself through the parameter redirect-url-custom, for example:
Блок кода redirect-url-custom https://eltex-co.ru/?action_url=<SWITCH_URL>&ap_addr=<AP_MAC>&client_addr=<CLIENT_MAC>&ssid_name=<SSID>&red_url=<ORIGINAL_URL>&nas=<NAS_ID>
In the example, <NASexample <NAS_ID> was added to the line and the following parameter names were changed:
- switch_url → action_url
- ap_mac → ap_addr
- client_mac →clientmac → client_addr
- wlan →ssidwlan → ssid_name
- redirect →redredirect → red_url
The redirect line may contain placeholders:
- <NAS_ID>
- <SWITCH_URL>
- <AP_MAC>
- <CLIENT_MAC>
- <SSID>
- <ORIGINAL_URL>
Create radius-profile.
Блок кода wlc radius-profile portal_radius auth-address 192.168.4.5 auth-password ascii-text encrypted 92BB3C7EB50C5AFE80 auth-acct-id-send acct-enable acct-address 192.168.4.5 acct-password ascii-text encrypted 92BB3C7EB50C5AFE80 acct-periodic acct-interval 300 exit exit
Scroll Pagebreak Create ssid-profile.
Блок кода wlc ssid-profile portal_test ssid portal_test radius-profile portal_radius portal-enable portal-profile portal-pr vlan-id 3 band 5g enable exit exit
Add ssid-profile to ap-location.
Блок кода wlc ap-location default-location description default-location mode tunnel ap-profile default-ap ssid-profile portal_test exit exit
...