Captive Portal Authentication Profile
Captive portal is an authentication method supported by HPE Aruba Networking Central. Captive portal displays a web page, which requires users to either view and agree to an Acceptable Usage Policy, or enter the user ID and password. You can configure captive portal for guest users without authentication, or for registered users who must be authenticated on an external server.
Overlay support for the Aruba-Captive-Portal-URL VSA (ID 43) enhances consistency between Overlay and Underlay deployments, ensuring reliable captive portal redirection across AOS-10.
Creating a Captive Portal Authentication Profile
To create a Captive Portal Authentication profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select one of the following options:
-
Library—This is the default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a Captive Portal Authentication Profile.
-
Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.
-
Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
-
Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
Note:- To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
- To create profiles at the Site Collections, Sites, Devices, and Device Group level, complete the following steps before step 4:
- Select Site Collection, Site, Device, or Device Group in the left navigation menu.
- Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
- Select the device type from the Device Function drop-down list.
-
-
On the Security card, click Captive Portal Authentication.
Alternatively, you can complete the following steps:
-
On the Security card, click Manage.
-
On the Captive Portal Authentication card, click Manage.
The Captive Portal Authentication list view is displayed.
-
-
Click Create Profile.
The Create Profile side panel is displayed.
-
Configure the captive portal profile parameters as described in the following table:
Parameter
Description
Create as a local profile
Select this option if you want to configure this profile as local.
The Create as a local profile option is available at the Global, Site Collections, Sites, Devices, and Device Groups levels; it is not available at the Library level.
Name
Enter the name of the captive portal authentication profile
Description
Enter a brief description for the captive authentication profile.
URL
Enter the URL of the external captive portal server in the following format:
<protocol>://<domain name or IP address>:<port number (optional)>/<URL path>.Use HTTPS for authentication
Use HTTPS protocol on redirection to the Captive Portal page. If you use this option, modify the captive portal policy to allow HTTPS traffic.
Default: disabled (HTTP is used).
Post Authentication Redirection URL
Specify a redirect URL if you want to redirect the users to another URL.
Add Network Device IP in redirection URL
Select the check box to include the network device IP in the redirection URL.
URL Hash key
If a redirection URL is defined, enter a URL Hash Key to hash the redirect URL using the specified key. This parameter enhances security for the ClearPass Guest login URL so that ClearPass Policy Manager can trust and ensure that the client MAC address in the redirect URL has not been tampered with by anyone. Default: Disabled.
Retype URL Hash key
Retype the URL Hash key.
Device-Specific Parameters
Select Access Point Parameters and/or Gateway Parameters.
Access Point Parameters
Server Offload
Select the check box to enable server offload. The server offload feature ensures that the non-browser client applications are not redirected to the external portal server and reduces the load on the external captive portal server. The Server Offload option is disabled by default.
Prevent Frame Overlay
Select the check box to enable prevention of frame overlay. When the prevent frame overlay option is enabled, a frame can display a page only if it is in the same domain as the main page. This option is disabled by default and can be used to prevent the overlay of frames.
Gateway Parameters
Authentication Server Group
Select the authentication server group from the drop-down list.
To create a new server group, click New Server Group.
For more information see, Authentication Server Group Profile.
To view the selected server groups, click View Selection.
Add user VLAN In redirection URL
Sends the user VLAN ID in the redirection URL when external captive portal servers are used.
Add a gateway interface in the redirection URL
Sends the interface IP address of the gateway in the redirection URL when external captive portal servers are used. An external captive portal server can determine the gateway from which a request originated by parsing the switchip variable in the URL.
User Idle Timeout
The user idle timeout value for this profile. Specify the idle timeout value for the client in seconds. Valid range is 30-15300 in multiples of 30 seconds. Enabling this option overrides the global settings configured in the AAA timers. If this is disabled, the global settings are used.
-
To create a new authentication group, configure the parameters as described in the following table:
Parameter
Description
Name
Enter the name of the authentication server group.
Description
Enter a brief description for the authentication server group.
Server Type
Select the server type from the following options:
-
RADIUS
-
TACACS
Authentication Servers
Select the authentication server from the drop-down list.
To create a new server, click New Server. For more information, see Authentication Server Profile.
Gateway Specific Parameters
Select the check box to configure high availability options.
Gateway Specific Parameters
High Availability
Select the high availability from the following options:
-
Fail Through
-
Load Balance
Advanced
Select the check box to configure advance options.
Server Rules
Select the server rules in the server rules table.
To create server rules, click the
icon on the Server Rules table. For more information, see Server Rule Parameters. -
-
Click Create.
-
To add server rules, configure the parameters as described in the following table:
-
Click Create.
-
To add a new authentication server, configure the parameters as described in the following table:
Parameter
Description
Name
Enter the name of the authentication server.
Description
Enter a brief description for the authentication server.
Server Type
Select the server type from the following options:
-
RADIUS
-
TACACS
Secure RADIUS
Select this check box to secure communication between the RADIUS server and the gateway.
Advanced
Select the check box to configure high availability options.
IP Address
IP address or FQDN of the authentication server. The maximum supported FQDN length is 63 characters. Default: N/A
Shared Secret
Shared secret key between the gateway and the authentication server. The maximum length is 128 characters.
Retype Shared Secret
Retype the shared secret key.
Authentication Port
Authentication port of this server. The default value is 1812.
Accounting Port
Accounting port of this server. The default value is 1813.
Certificate Type
Select the certificate type from the following options:
-
Internal
-
Custom
-
EST Profile
Secure RADIUS Trusted CA
The CA certificate that is uploaded as a Trusted CA if the Radsec server uses a certificate signed by a CA. This option is available when you select Custom Certificate or Certificate (EST Profile) as the Certificate Type.
Radsec Client Certificate
The client certificate sent to the Radsec server.
Certificate Profile
Select this option to use the EST certificate as the Radsec client certificate when establishing an SSL or TLS connection with the Radsec server.
ClearPass Credentials
Select the check box to enable the ClearPass credentials.
Username
Enter the user name for ClearPass authentication.
Password
Enter the password for ClearPass authentication.
Retype Password
Retype the password.
NAS Identifier
NAS identifier to use in RADIUS packets.
NAS IP Address
The NAS IP address to be sent in RADIUS packets from that server.
Called Station ID
Called Station ID Type
Select any of the following options to configure called station ID:
-
MACAddress—Uses the MAC address as the called station ID.
-
APGroup—Uses the host name of the Instant AP as the called station ID.
-
APMAC address—Uses the MAC address of the Instant AP as the called station ID.
-
APName—Uses the host name of the Instant AP as the called station ID.
-
IPAddress—Uses the IP address of the Instant AP as the called station ID.
-
VLAN—Uses the VLAN ID of as the called station ID.
Called Station ID Delimiter
Select a character delimiter for the string from the drop-down list.
Include WLAN Name
Select this check box to include the WLAN name.
Device-Specific Parameters
Select the check box to configure the gateway parameters.
Gateway Parameters
Source Interface
Enter the source IP address.
Options
Select the check box to enable the following options:
-
Lowercase MAC Address—Send MAC address with lowercase in the authentication and accounting requests to this server.
-
Use IP Address for Calling Station ID—Enables using the IP address as the calling station ID.
MAC Address Delimiter
Send MAC address with the following delimiters in the authentication and accounting requests of this server:
-
Colon—Send MAC address as XX:XX:XX:XX:XX:XX
-
Comma—Send MAC address as XX,XX,XX,XX,XX,XX
-
Dash—Send MAC address as XX-XX-XX-XX-XX-XX
-
None—Send MAC address as XXXXXXXXXXXX
-
Oui-nic—Send MAC address as XXXXXX-XXXXXX
-
Percent—Send MAC address as XX%XX%XX%XX%XX%XX
-
Slash—Send MAC address as XX/XX/XX/XX/XX/XX
Default: None
-
-
Click Create.
The newly created profile is displayed in the Captive Portal Authentication list.
-
To edit a profile, complete the following steps:
-
Click anywhere on the row of the profile in the list view.
The Edit Profile view is displayed in the side panel. -
Edit the required parameters.
-
Click Update.
-
-
To delete a captive portal authentication profile, hover on the profile name, and click the delete
icon. -
To search for a profile, type the profile name in the search bar.
The search bar displays dynamic results as soon as you start typing.
|
Parameter |
Description |
|---|---|
|
Attribute |
Select the domain name from the drop-down list. |
|
Operator |
Set the operator from the drop-down list. |
|
Operand |
Set the operand value to the client or user information. |
|
Role |
Select a role from the drop-down list. |
Figure 1: Captive Portal Authentication - Create Profile
Assigning Scope to a Captive Portal Authentication Profile
For profiles created under Library, you must assign a scope and device function to be able to use its features and functionality.
To assign scope to a profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
Ensure that the default option Library is selected in the left navigation menu.
-
On the Security card, click Captive Portal Authentication.
Alternatively, you can complete the following steps:
-
On the Security card, click Manage.
-
On the Captive Portal Authentication card, click Manage.
The Captive Portal Authentication list view is displayed.
-
-
Hover on the profile to which you want to assign a scope and click the ellipsis
icon. -
Select Assign.
The Assign Profile side panel is displayed.
-
Select the device types from Device Function list.
-
To add a scope, click the Add
icon on the Scopes table. -
Select a scope from the following Scope Level options in the drop-down list.
-
Global—Selecting this option assigns the scope at the Global level.
-
Site Collections—Select the site collections from the Assign to Scope drop-down list.
-
Sites—Select the sites from the Assign to Scope drop-down list.
-
Devices—Select the devices from the Assign to Scope drop-down list.
-
Device Groups—Select the device groups from the Assign to Scope drop-down list .
-
-
Click Add.
The Scopes table displays the newly added scopes.
-
Click Assign.
The Captive Portal Authentication list displays the device functions and number of scopes assigned to the profile.
-
To unassign a scope from a profile, complete the following steps:
-
Hover on the profile name and click the Ellipsis
icon. -
Select Unassign.
The Unassign pop-up window is displayed.
-
Select the required scope and click Unassign.
-
-
To customize the Captive Portal Authentication Server profile list, click the Customize Columns icon
. For more information, see Customizing List.