Sample Authentication with Captive Portal
- Guest clients associate to the SSID Service Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network. which is an open WLAN Wireless Local Area Network. WLAN is a 802.11 standards-based LAN that the users access through a wireless connection.. Guest clients are placed into VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN. 900 and assigned IP addresses by the internal DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. server of the managed device. The user has no access to network resources beyond DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. and DNS Domain Name System. A DNS server functions as a phone book for the intranet and Internet users. It converts human-readable computer host names into IP addresses and IP addresses into host names. It stores several records for a domain name such as an address 'A' record, name server (NS), and mail exchanger (MX) records. The Address 'A' record is the most important record that is stored in a DNS server, because it provides the required IP address for a network peripheral or element. until they open a web browser and log in with a guest account using captive portal A captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users..
- Guest users are given a login and password from guest accounts created in the internal database of the managed device. The temporary guest accounts are created and administered by the site receptionist.
- Guest users must enter their assigned login and password into the captive portal A captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users. login before they are given access to use web browsers (HTTP Hypertext Transfer Protocol. The HTTP is an application protocol to transfer data over the web. The HTTP protocol defines how messages are formatted and transmitted, and the actions that the w servers and browsers should take in response to various commands. and HTTPS Hypertext Transfer Protocol Secure. HTTPS is a variant of the HTTP that adds a layer of security on the data in transit through a secure socket layer or transport layer security protocol connection.), POP3 email clients, and VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. clients (IPsec Internet Protocol security. IPsec is a protocol suite for secure IP communications that authenticates and encrypts each IP packet in a communication session., PPTP Point-to-Point Tunneling Protocol. PPTP is a method for implementing virtual private networks. It uses a control channel over TCP and a GRE tunnel operating to encapsulate PPP packets., and L2TP Layer-2 Tunneling Protocol. L2TP is a networking protocol used by the ISPs to enable VPN operations. ) on the Internet and only during specified working hours. Guest users are prohibited from accessing internal networks and resources. All traffic to the Internet is with source network address translation.
This example assumes a Policy Enforcement Firewall Firewall is a network security system used for preventing unauthorized access to or from a private network. Next Generation license is installed in the Mobility Conductor.
In this example, you create two user roles:
- is a user role assigned to any client who associates to the guestnet SSID Service Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network.. Normally, any client that associates to an SSID Service Set Identifier. SSID is a name given to a WLAN and is used by the client to access a WLAN network. will be placed into the logon system role. The user role is more restrictive than the logon role.
- is a user role granted to clients who successfully authenticate via the captive portal A captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users..
Creating a Guest User Role
The user role consists of the following ordered policies:
- is a predefined policy that allows captive portal A captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users. authentication.
- is a policy that you create with the following rules:
- Allows DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. exchanges between the user and the DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. server during business hours while blocking other users from responding to DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. requests.
- Allows ICMP Internet Control Message Protocol. ICMP is an error reporting protocol. It is used by network devices such as routers, to send error messages and operational information to the source IP address when network problems prevent delivery of IP packets. exchanges between the user and the managed devices during business hours.
- is a policy that you create that denies user access to the internal networks.
The user role configuration needs to include the name of the captive portal A captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users. authentication profile instance. You can modify the user role configuration after you create the captive portal A captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users. authentication profile instance.
Creating an Auth-guest User Role
The user role consists of the following ordered policies:
- is a predefined policy that allows captive portal A captive portal is a web page that allows the users to authenticate and sign in before connecting to a public-access network. Captive portals are typically used by business centers, airports, hotel lobbies, coffee shops, and other venues that offer free Wi-Fi hotspots for the guest users. logout.
- is a policy that you create with the following rules:
- Allows DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. exchanges between the user and the DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. server during business hours while blocking other users from responding to DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. requests.
- Allows DNS Domain Name System. A DNS server functions as a phone book for the intranet and Internet users. It converts human-readable computer host names into IP addresses and IP addresses into host names. It stores several records for a domain name such as an address 'A' record, name server (NS), and mail exchanger (MX) records. The Address 'A' record is the most important record that is stored in a DNS server, because it provides the required IP address for a network peripheral or element. exchanges between the user and the public DNS Domain Name System. A DNS server functions as a phone book for the intranet and Internet users. It converts human-readable computer host names into IP addresses and IP addresses into host names. It stores several records for a domain name such as an address 'A' record, name server (NS), and mail exchanger (MX) records. The Address 'A' record is the most important record that is stored in a DNS server, because it provides the required IP address for a network peripheral or element. server during business hours. Source-NAT Network Address Translation. NAT is a method of remapping one IP address space into another by modifying network address information in Internet Protocol (IP) datagram packet headers while they are in transit across a traffic routing device. the traffic using the IP interface of the managed devices for the VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN..
- is a policy that you create that denies user access to the internal networks.
- is a policy that you create with the following rules:
- Allows DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. exchanges between the user and the DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. server during business hours while blocking other users from responding to DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. requests.
- Allows DNS Domain Name System. A DNS server functions as a phone book for the intranet and Internet users. It converts human-readable computer host names into IP addresses and IP addresses into host names. It stores several records for a domain name such as an address 'A' record, name server (NS), and mail exchanger (MX) records. The Address 'A' record is the most important record that is stored in a DNS server, because it provides the required IP address for a network peripheral or element. exchanges between the user and the public DNS Domain Name System. A DNS server functions as a phone book for the intranet and Internet users. It converts human-readable computer host names into IP addresses and IP addresses into host names. It stores several records for a domain name such as an address 'A' record, name server (NS), and mail exchanger (MX) records. The Address 'A' record is the most important record that is stored in a DNS server, because it provides the required IP address for a network peripheral or element. server during business hours. Source-NAT Network Address Translation. NAT is a method of remapping one IP address space into another by modifying network address information in Internet Protocol (IP) datagram packet headers while they are in transit across a traffic routing device. the traffic using the IP interface of the managed devices for the VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN..
- Allows HTTP Hypertext Transfer Protocol. The HTTP is an application protocol to transfer data over the web. The HTTP protocol defines how messages are formatted and transmitted, and the actions that the w servers and browsers should take in response to various commands. or HTTPS Hypertext Transfer Protocol Secure. HTTPS is a variant of the HTTP that adds a layer of security on the data in transit through a secure socket layer or transport layer security protocol connection. traffic from the user during business hours. Source-NAT Network Address Translation. NAT is a method of remapping one IP address space into another by modifying network address information in Internet Protocol (IP) datagram packet headers while they are in transit across a traffic routing device. the traffic using the I interface of the managed devices for the VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN..
- is a policy that you create that denies all traffic and logs the attempted network access.
Configuring Policies and Roles
The following section describes how to configure roles and policies by creating a time range, creating aliases, creating a Guest-Logon-Access policy, Auth-Guest-Access policy, Block-Internal-Access policy, Drop-and-Log policy, and Auth-Guest role.
Creating a Time Range
The following procedure describes how to create the guest-logon-access policy:
- Login to the Mobility Conductor.
- In the node hierarchy, navigate to the tab.
- Select to add the guest-logon-access policy.
- For , enter
- For , select .
- Click .
- Select the newly created policy.
- Click under the table.
- In the popup, select option and click OK.
- Under1 table, to add a new rule select the following options:
- For , select .
- For , select.
- For , select . Enter the port range.
- For , select .
- Click .
- For the , select and enter the following for adding a new time range:
- For , enter.
- For , select and click +.
- For , click .
- For , enter
- For , enter .
- Click .
- Add another new rule for the guest-logon-access:
- For , select .
- For , select .
- For , select .
- Select for .
- For , select
- For , select
- Click .
- Click .
- In the window, select the check box and click .
Creating Aliases
The following step defines an alias representing the public DNS Domain Name System. A DNS server functions as a phone book for the intranet and Internet users. It converts human-readable computer host names into IP addresses and IP addresses into host names. It stores several records for a domain name such as an address 'A' record, name server (NS), and mail exchanger (MX) records. The Address 'A' record is the most important record that is stored in a DNS server, because it provides the required IP address for a network peripheral or element. server addresses. Once defined, you can use the alias for other rules and policies.
The following procedure describes how to create a destination alias:
- In the node hierarchy, navigate to the > > tab.
- In , click .
- Select an from the drop-down list.
- For , enter
- For , enter a description of the destination within 128 characters.
- Select to specify that the inverse of the network addresses configured are used.
- For , click .
- In the window, for Rule Type, select . For IP Address, enter 64.151.103.120.
- Click .
- Click .
- In the window, select the check box and click .
Creating guest-logon-access policy
The following procedure describes how to create a guest-logon-access policy:
- Login to the Mobility Conductor.
- In the node hierarchy, navigate to the page.
- Select to add the guest-logon-access policy.
- For Policy Name, enter
- For Policy Type, select .
- Click .
- Select the newly created policy.
- Click under the table.
- In the popup, select option and click OK.
- Under the table, to add a new rule select the following options:
- For , select.
- For , select .
- For , select
- For , select
- For , select .
- Under Time Range, select .
- Click .
- Click .
- In the window, select the check box and click .
Creating an Auth-Guest-Access Policy
The following procedure describes how to configure the auth-guest-access policy:
- Login to the Mobility Conductor.
- In the node hierarchy, navigate to the tab.
- Select to create the policy.
- For , enter .
- For select.
- Click .
- Select the newly created policy.
- Click under the table.
- In the popup, select option and click OK.
- Under, to add a new rule select the following options:
- For , select .
- For , select .
- For , select . Enter the port range.
- For , select .
- Click .
- Repeat the steps 8 and 9 and in, select the following options to add another rule.
- For , select .
- For , select .
- For , select .
- Select for Service alias.
- For , select .
- For , select .
- Click .
- Repeat the steps 8 and 9 and under, select the following options to add another rule.
- For , select .
- For , select .
- For , select from the drop-down list.
- For , select .
- Select for Service Alias.
- For , select .
- For , select .
- Click .
- Repeat steps 8 and 9 and under, select the following options to add another rule.
- For , select .
- For , select .
- For , select .
- Select for .
- For , select .
- For , select .
- Click .
- Repeat the steps 8 and 9 and under table, select the following options to add another rule.
- For , select .
- For , select .
- For , select.
- Select for .
- For , select.
- For , select .
- Click .
- Click .
- Click .
- In the window, select the check box and click .
Creating an Block-Internal-Access Policy
It is recommended to first create a destination alias and then create a block-internal-access policy. If the destination alias is already created, the user can directly create a block - internal - access policy and skip the procedure given below.
The following procedure describes how to create a block-internal-access policy:
- In the node hierarchy, navigate to the > > tab.
- In , click .
- Select an from the drop-down list.
- For , enter
- For , enter a description of the destination within 128 characters.
- Select to specify that the inverse of the network addresses configured are used.
- For , click .
- In the window, for Rule Type, select . For IP Address, enter 10.0.0.0. For Network Mask or Range, enter 255.0.0.0.
- Click .
- Click .
- In the window, select the check box and click .
The following procedure describes how to create the block-internal-access policy:
- Login to the Mobility Conductor.
- In the node hierarchy, navigate to the tab.
- Select to add a new policy.
- For Policy Name, enter .
- For Policy Type, select .
- Click .
- Select the newly created policy.
- Click under the table.
- In the popup, select option and click OK.
- Under the table, to add a new rule select the following options:
- For Source, select .
- For Destination, select .
- For , select
- For , select Any.
- For , select Deny.
- Click Submit.
- Click .
- Click .
- In the window, select the check box and click .
Creating a Drop-and-Log Policy
The following procedure describes how to create the drop-and-log policy:
- Login to the Mobility Conductor.
- In the node hierarchy, navigate to the tab.
- Click to add a new policy.
- For , enter
- For , select.
- Click .
- Select the newly created policy.
- Click under the table.
- In the popup, select option and click OK.
- Under, to add a new rule select the following options:
- For , select
- For , select .
- For , select
- For , select .
- Select the checkbox from .
- Click .
- Click .
- Click .
- In the window, select the check box and click .
Creating a Guest Role
The following procedure describes how to create a guest role:
- Login to the Mobility Conductor.
- In the node hierarchy, navigate to the tab.
- Click to add a new role.
- Enter as a New Role.
- Select the role name you just created and click .
- Click + under thetab.
- In the popup, select the option.
- Select the policy name as from the drop-down list
- Click .
- Similarly, add block-internal-access policy for the role guest-logon.
- Click .
- Click .
- In the window, select the check box and click .
Creating an Auth-Guest Role
The following procedure describes how to create the guest-logon role:
- Login to the Mobility Conductor.
- In the node hierarchy, navigate to the tab.
- Click to add a new role.
- Enter as a New Role.
- Select the role name you just created and click .
- Click + under thetab.
- In the pop-up, select the option.
- Select the policy name from the drop-down list
- Click .
- Similarly, add guest-logon-access, block-internal-access, auth-guest-access, drop-and-log policies for the role .
- Click .
- Click .
- In the window, select the check box and click .
The following set of CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. commands configures sample roles and policies:
Defining a Time Range
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. command creates a time range:
(host) [md] (config) #time-range working-hours periodic
weekday 07:30 to 17:00
Creating Aliases
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. commands create aliases:
(host) [md] (config) #netdestination “Internal Network”
network 10.0.0.0 255.0.0.0
network 172.16.0.0 255.255.0.0
network 192.168.0.0 255.255.0.0
(host)(config) #netdestination “Public DNS”
host 64.151.103.120
host 216.87.84.209
Creating a Guest-Logon-Access Policy
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. commands create a guest-logon-access policy:
(host)(config) #ip access-list session guest-logon-access
user any udp 68 deny
any any svc-dhcp permit time-range working-hours
user alias “Public DNS” svc-dns src-nat time-range working-hours
Creating an Auth-Guest-Access Policy
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. commands create an auth-guest-access policy:
(host) [md] (config) #ip access-list session auth-guest-access
user any udp 68 deny
any any svc-dhcp permit time-range working-hours
user alias “Public DNS” svc-dns src-nat time-range working-hours
user any svc-http src-nat time-range working-hours
user any svc-https src-nat time-range working-hours
Creating a Block-Internal-Access Policy
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. command creates a block-internal-access policy:
(host) [md] (config) #ip access-list session block-internal-access
user alias “Internal Network” any deny
Creating a Drop-and-Log Policy
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. command creates a drop-and-log policy:
(host) [md] (config) #ip access-list session drop-and-log
user any any deny log
Creating an Auth-Guest Role
The following CLI Command-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions. commands create an auth-guest role:
(host) [md] (config) #user-role auth-guest
(host) [md] (config-submode)#access-list session captiveportal
(host) [md] (config-submode)#access_list cplogout position 1
(host) [md] (config-submode)#access_list guest-logon-access position 2
(host) [md] (config-submode)#access_list block-internal-access position 3
(host) [md] (config-submode)#access_list auth-guest-access position 4
(host) [md] (config-submode)#access_list drop-and-log position 5