Configuring Captive Portal Profile
Captive portal is an authentication method supported by Central NAC. Captive portal displays a web page, which requires users to either view and agree to the Terms and Conditions and provide their login credentials.
Captive portal is also supported for wired configurations. A port profile must be created for a wired configuration. For more information, see Creating a Port Profile.
To create a captive portal profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the Menu
icon. -
In the Central NAC card, click Manage.
The NAC Monitoring page is displayed.
-
Click the Configuration
icon. The configuration view appears, which displays the Authentication Profiles, Authorization Policies, Identity Management, Visitors, and Messaging cards.
-
In the Authentication Profiles card, click Manage.
-
Click .
-
In the Create Profile side panel, configure the following parameters:
-
Name—Enter a name of the profile.
-
Description—Enter a description of the authentication profile.
-
Authentication Type—Select Captive Portal.
-
Network—Select the network to be configured with this profile.
-
Use for wired connection—Select this check box to enable wired configuration for a captive portal profile.
Note:This option can be enabled only in one profile for an authentication type.
-
Port Profile—Select a specific port profile from the drop-down.
Note:A port profile must be selected for a wired configuration.
-
Authentication—choose the following options:
-
Select either Users sign in with an account or Users sign in anonymously
-
Identity Store—Select the required identity store from the drop-down list.
-
Enable Allow users to register an account.
-
Select the Registered user identity store from the drop-down.
-
Select a suitable registration type.
-
Set an expiration type from the drop-down.
-
Verify registered accounts—On enabling this, a verification link (email) or a verification code (SMS) will be sent to the user.
Note:When Verify registered accounts is enabled, visitors who register using an email address are granted an initial 15-minute session to access their email and complete the verification process. Once the verification is complete and they sign back into the network, the standard session and daily usage limits will apply.
-
-
Default Policy—choose the following options:
-
Enable MAC Caching—Select the check box to enable MAC caching. You can automatically resume your current network session through MAC authentication as long as it does not exceed any session time or data limit.
-
Limit Concurrent Clients Per Account—Select the check box to add a limit on the number of clients you want to allow. Enter the maximum number of clients for each account.
-
Session Limits—Set the session limits in terms of Time and Data.
Time—Enter the maximum time allowed per session before it is terminated.
Data—Enter the maximum data transfer allowed per session before it is terminated.
-
Daily Limits—Set the daily limits for an account or client in terms of Time and Data
Time—Enter the maximum time allowed per day before active sessions are terminated.
Data—Enter the maximum data transfer allowed per day before active sessions are terminated.
-
-
Portal Customization—Select a portal profile from the drop-down to apply customizations to the web portal for the authentication profile.
-
Portal URL—Displays the captive portal URL to which the users are automatically redirected when connecting to the network. The URL appears after the profile is created.
-
-
Click Create.
The captive portal profile is created and is listed in the Authentication Profiles page.
Viewing Web Portal
Administrators can view and access the web portal from the Authentication Profiles page.
-
In the Authentication Profiles page, hover over an captive portal profile and click the ellipsis
icon. A pop-up menu is displayed.
-
Click View Portal.
The captive portal page opens in a new browser window.