Configuring Captive Portal with a PEFNG License
You must purchase and install thePEFNGPolicy Enforcement Firewall. PEF also known as PEFNG provides context-based controls to enforce application-layer security and prioritization. The customers using Aruba mobility controllers can avail PEF features and services by obtaining a PEF license. PEF for VPN users—Customers with PEF for VPN license can apply firewall policies to the user traffic routed to a controller through a VPN tunnel.license on theMobility Master使用基于身份的安全功能。有两个用户角色对captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.:
Default user role, which you specify in thecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.authentication profile, is the role granted to clients uponcaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.验证。这可以是预定义的 system role.
初始用户角色,您在AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。profile, directs clients who associate to theSSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.tocaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.每当用户启动Web浏览器连接时。这可以是预定义的 system role.
Thecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.authentication profile specifies thecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.login page and other configurable parameters. The initial user role configuration must include the applicablecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证配置文件实例。
Following are the basic tasks for configuringcaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.使用政策执行提供的基于角色的访问防火墙防火墙is a network security system used for preventing unauthorized access to or from a private network.software module:
有关更多信息,请参阅ArubaMobility MasterLicensing Guide.
2.为默认用户配置用户角色。
为客人或注册创建和配置用户角色和策略captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.用户。有关更多信息,请参阅配置政策和角色.
3.Create a server group.
如果您要配置captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.对于注册用户,配置服务器并创建服务器组。有关更多信息,请参阅Authentication Servers
If you are using the internal database of themanaged devicefor user authentication, use the predefined “Internal” server group. The "internal" server is the local database on theMobility Master. You need to configure entries in the internal database, as described inAuthentication Servers. |
创建并配置一个实例captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证概况。指定默认用户角色captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.用户。有关更多信息,请参阅配置圈养门户身份验证配置文件.
5.Configure the initial user role.
创建并配置初始用户角色captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.. You also need to specify thecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.authentication profile instance in the initial user role configuration. For example, if you are using the predefined 最初角色的系统角色,您需要编辑角色以指定captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证配置文件实例。有关更多信息,请参阅Modifying the Initial User Role.
6.创建AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。轮廓。
创建并配置一个实例AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。轮廓。指定初始用户角色。有关更多信息,请参阅Configuring the AAA Profile.
7.创建SSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.轮廓。In this example, the profile name is .
创建并配置适用于AP组或AP名称的虚拟AP配置文件的实例。指定AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。您刚创建的个人资料。
8.创建Virtual AP Profile. In this example, the profile name is .
创建并配置一个实例SSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.虚拟AP的配置文件。
以下sections present the WebUI andCLICommand-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions.配置的过程captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证配置文件,初始用户角色,AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。配置文件和虚拟AP配置文件。本文档中的其他章节详细介绍了用户角色和策略,身份验证服务器和服务器组的配置。
以下procedure describes how to configurecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.with aPEFNGPolicy Enforcement Firewall. PEF also known as PEFNG provides context-based controls to enforce application-layer security and prioritization. The customers using Aruba mobility controllers can avail PEF features and services by obtaining a PEF license. PEF for VPN users—Customers with PEF for VPN license can apply firewall policies to the user traffic routed to a controller through a VPN tunnel.license:
1.登录到Mobility Master.
2.在里面 node hierarchy, navigate to the 标签。选择 轮廓。
一个。在里面 window, click to create a newCaptive PortalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证配置文件并输入 (for example, )。
c.Enable 或者 , as well as other parameters (refer toCaptive Portal Authentication Profile Parameters表)。
d.点击 .
3.To specify the authentication servers, select 在下面captive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.您刚刚配置的身份验证配置文件。
一个。选择服务器组(例如, ) from the drop-down list.
b.点击
4.选择 标签。
一个。ExpandAAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。配置文件并单击 在里面 添加新配置文件的窗口。进入一个 (for example, )。
b.Set the to a role that you will configure with thecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.身份验证概况。
c.点击 .
5.Navigate to the 标签 Select a role and click + to add a new rule.
一个。To edit the predefined logon role, select the role and click + in the policies page that opens and select .
b.要配置新角色,首先在 选项卡,然后选择 标签to add a new user role and assign policies.
c.选择profile from theCaptive PortalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.选定角色下的身份验证选项卡中的配置文件下拉列表。
d.点击 .
6.Navigate to the page to configure the virtual AP profile.
7.选择AP组。点击 for the applicable AP group name or AP name.
8.Under Profiles, select , then select Virtual AP.
9。选择添加一个新的配置文件op-down list to create a new virtual AP profile. Enter the name for the virtual AP profile (for example, ), then click
一个。在里面Profile Details entry for the new virtual AP profile, select theAAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。您以前配置的个人资料。弹出窗口显示已配置的AAA身份验证,授权和会计。AAA是一个安全框架,可以对用户进行身份验证,授权基于用户凭据的访问类型,并记录有关网络访问和网络资源消耗的身份验证事件以及信息。profile parameters. Click .
b.From theSSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.profile drop-down list, select NEW. A pop-up window allows you to configure theSSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.轮廓。
c.输入名称SSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.profile (for example, )。
d.Enter the Network Name for theSSIDService Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.(for example, )。
e.在个人资料详细信息页面的底部,单击
10。单击“配置文件”列表或配置文件详细信息中的新虚拟AP名称以显示配置参数。
一个。Make sure Virtual AP enable is selected.
b.ForVlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。,选择Vlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。to which users are assigned (for example,900)。
c.点击Submit.
11.点击 .
12.在里面 窗口,选择复选框,然后单击 .
以下CLICommand-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions.commands configurecaptive portalA captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users.与PEFNGPolicy Enforcement Firewall. PEF also known as PEFNG provides context-based controls to enforce application-layer security and prioritization. The customers using Aruba mobility controllers can avail PEF features and services by obtaining a PEF license. PEF for VPN users—Customers with PEF for VPN license can apply firewall policies to the user traffic routed to a controller through a VPN tunnel.license:
(host) [md] (config) #aaa authentication captive-portal c-portal
默认角色员工
server-group cp-srv
(主机)[MD](config)#用户 - 角登录
(host) [md] (config-submode)#access-list session c-portal
圈式c-portal
(host) [md] (config) #aaa profile aaa_c-portal
initial-role logon
(主机)[MD](config)#wlan ssid-profile ssid_c-portal
essid c-portal-ap
VLAN 900
(主机)[MD](config)#wlan Virtual-AP VP_C-PORTAL
AAA-PROFILE AAA_C-PORTAL
SSID-Profile SSID_C-PORTAL
Configuring Captive Portal in the Base Operating System