ArubaOS 8.6.0.0帮助中心
You are here: Home > Captive Portal Authentication > Captive Portal with the PEFNG License

Configuring Captive Portal with a PEFNG License

You must purchase and install thePEFNGPolicy Enforcement Firewall. PEF also known as PEFNG provides context-based controls to enforce application-layer security and prioritization. The customers using Aruba mobility controllers can avail PEF features and services by obtaining a PEF license. PEF for VPN users—Customers with PEF for VPN license can apply firewall policies to the user traffic routed to a controller through a VPN tunnel.license on theMobility Master使用基于身份的安全功能。有两个用户角色对captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.:

Default user role, which you specify in thecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.authentication profile, is the role granted to clients uponcaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.验证。这可以是预定义的guestsystem role.

初始用户角色,您在AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。profile, directs clients who associate to theSSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.tocaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.每当用户启动Web浏览器连接时。这可以是预定义的logonsystem role.

Thecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.authentication profile specifies thecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.login page and other configurable parameters. The initial user role configuration must include the applicablecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证配置文件实例。

苹果电脑媒体访问控制。MAC地址是分配给网络通信网络接口的唯一标识符。基于基于身份验证,如果在Mobility Master,优先captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.验证。

Following are the basic tasks for configuringcaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.使用政策执行提供的基于角色的访问防火墙防火墙is a network security system used for preventing unauthorized access to or from a private network.software module:

1.安装PEFNGPolicy Enforcement Firewall. PEF also known as PEFNG provides context-based controls to enforce application-layer security and prioritization. The customers using Aruba mobility controllers can avail PEF features and services by obtaining a PEF license. PEF for VPN users—Customers with PEF for VPN license can apply firewall policies to the user traffic routed to a controller through a VPN tunnel.初级许可证Mobility Master.

有关更多信息,请参阅ArubaMobility MasterLicensing Guide.

2.为默认用户配置用户角色。

为客人或注册创建和配置用户角色和策略captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.用户。有关更多信息,请参阅配置政策和角色.

3.Create a server group.

如果您要配置captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.对于注册用户,配置服务器并创建服务器组。有关更多信息,请参阅Authentication Servers

If you are using the internal database of themanaged devicefor user authentication, use the predefined “Internal” server group. The "internal" server is the local database on theMobility Master. You need to configure entries in the internal database, as described inAuthentication Servers.

4.创建captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证概况。

创建并配置一个实例captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证概况。指定默认用户角色captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.用户。有关更多信息,请参阅配置圈养门户身份验证配置文件.

5.Configure the initial user role.

创建并配置初始用户角色captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.. You also need to specify thecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.authentication profile instance in the initial user role configuration. For example, if you are using the predefinedlogon最初角色的系统角色,您需要编辑角色以指定captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证配置文件实例。有关更多信息,请参阅Modifying the Initial User Role.

6.创建AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。轮廓。

创建并配置一个实例AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。轮廓。指定初始用户角色。有关更多信息,请参阅Configuring the AAA Profile.

7.创建SSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.轮廓。In this example, the profile name isssid_c-portal.

创建并配置适用于AP组或AP名称的虚拟AP配置文件的实例。指定AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。您刚创建的个人资料。

8.创建Virtual AP Profile. In this example, the profile name isvp_c-portal.

创建并配置一个实例SSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.虚拟AP的配置文件。

以下sections present the WebUI andCLICommand-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions.配置的过程captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证配置文件,初始用户角色,AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。配置文件和虚拟AP配置文件。本文档中的其他章节详细介绍了用户角色和策略,身份验证服务器和服务器组的配置。

以下procedure describes how to configurecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.with aPEFNGPolicy Enforcement Firewall. PEF also known as PEFNG provides context-based controls to enforce application-layer security and prioritization. The customers using Aruba mobility controllers can avail PEF features and services by obtaining a PEF license. PEF for VPN users—Customers with PEF for VPN license can apply firewall policies to the user traffic routed to a controller through a VPN tunnel.license:

1.登录到Mobility Master.

2.在里面托管网络node hierarchy, navigate to theConfiguration > Authentication > L3 Authentication标签。选择Captive Portal Authentication轮廓。

一个。在里面圈式门户身份验证配置文件:新配置文件window, click+to create a newCaptive PortalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证配置文件并输入配置文件名称(for example,c-portal)。

b.选择Default role(for example,员工)captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.用户。

c.EnableGuest login或者User login, as well as other parameters (refer toCaptive Portal Authentication Profile Parameters表)。

d.点击Submit.

3.To specify the authentication servers, select服务器组在下面captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.您刚刚配置的身份验证配置文件。

一个。选择服务器组(例如,CP-SRV) from the drop-down list.

b.点击提交。

4.选择AAA Profiles标签。

一个。ExpandAAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。配置文件并单击+在里面AAA配置文件:新个人资料添加新配置文件的窗口。进入一个配置文件名称(for example,AAA_C-PORTAL)。

b.Set theInitial roleto a role that you will configure with thecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证概况。

c.点击Submit.

5.Navigate to the配置>角色和策略>角色标签.Select a role and click + to add a new rule.

一个。To edit the predefined logon role, select the role and click + in the policies page that opens and select访问控制.

b.要配置新角色,首先在Policies选项卡,然后选择User Roles标签to add a new user role and assign policies.

c.选择profile from theCaptive PortalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.选定角色下的身份验证选项卡中的配置文件下拉列表。

d.点击Submit.

6.Navigate to the配置> AP组page to configure the virtual AP profile.

7.选择AP组。点击+for the applicable AP group name or AP name.

8.Under Profiles, select无线网络, then select Virtual AP.

9。选择添加一个新的配置文件op-down list to create a new virtual AP profile. Enter the name for the virtual AP profile (for example,vp_c-portal), then click节省.

一个。在里面Profile Details entry for the new virtual AP profile, select theAAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。您以前配置的个人资料。弹出窗口显示已配置的AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。profile parameters. Click节省.

b.From theSSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.profile drop-down list, select NEW. A pop-up window allows you to configure theSSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.轮廓。

c.输入名称SSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.profile (for example,ssid_c-portal)。

d.Enter the Network Name for theSSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.(for example,C-portal-ap)。

e.在个人资料详细信息页面的底部,单击提交。

10。单击“配置文件”列表或配置文件详细信息中的新虚拟AP名称以显示配置参数。

一个。Make sure Virtual AP enable is selected.

b.ForVlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。,选择Vlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。to which users are assigned (for example,900)。

c.点击Submit.

11.点击等待更改.

12.在里面等待更改窗口,选择复选框,然后单击部署更改.

以下CLICommand-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions.commands configurecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.PEFNGPolicy Enforcement Firewall. PEF also known as PEFNG provides context-based controls to enforce application-layer security and prioritization. The customers using Aruba mobility controllers can avail PEF features and services by obtaining a PEF license. PEF for VPN users—Customers with PEF for VPN license can apply firewall policies to the user traffic routed to a controller through a VPN tunnel.license:

(host) [md] (config) #aaa authentication captive-portal c-portal

默认角色员工

server-group cp-srv

(主机)[MD](config)#用户 - 角登录

(host) [md] (config-submode)#access-list session c-portal

圈式c-portal

(host) [md] (config) #aaa profile aaa_c-portal

initial-role logon

(主机)[MD](config)#wlan ssid-profile ssid_c-portal

essid c-portal-ap

VLAN 900

(主机)[MD](config)#wlan Virtual-AP VP_C-PORTAL

AAA-PROFILE AAA_C-PORTAL

SSID-Profile SSID_C-PORTAL

相关话题

Configuring Captive Portal in the Base Operating System

Sample Authentication with Captive Portal

配置圈养门户身份验证配置文件

/*]]>*/
Baidu