Example for Configuring Built-in Portal Authentication for Local Users
Service Requirements
WLAN is open to users and therefore has potential security risks. To manage access users in a centralized manner, Portal authentication is configured on the FAT AP. Any user that attempts to access the WLAN is redirected to the Portal authentication page. Users are authorized to access the WLAN after entering the correct user names and passwords. If the enterprise has a few number of users, the FAT AP can function as the Portal server to authenticate users locally to reduce costs. Built-in Portal authentication requires no additional Portal server, allowing for easy and flexible deployment. However, as the Portal server, the FAT AP provides only basic web functions (such as user login and logout) but cannot replace an independent Portal server or provide extended functions of an external Portal server.
Networking Requirements
- DHCP deployment mode: The AP functions as a DHCP server to assign IP addresses to STAs.
Data Planning
Item |
Data |
---|---|
Service VLAN for STAs |
VLAN 101 |
DHCP server |
The FAT AP functions as a DHCP server to assign IP addresses to STAs. |
IP address pool for STAs |
10.23.101.2-10.23.101.254/24 DNS: 8.8.8.8 |
STA's gateway |
VLANIF 101: 10.23.101.1 |
Built-in portal server |
|
Local user |
|
SSID profile |
|
Security profile |
|
Authentication Profile |
|
VAP profile |
|
Configuration Roadmap
- Select WLAN Wizard to configure WLAN services on the FAT AP. On the web platform, the HTTPS service is enabled and an SSL policy is applied. When configuring a built-in Portal server, configure the same SSL policy for the built-in Portal server.
- Configure a DNS server address in the DHCP address pool of the service VLAN to provide the DNS service for the STA.
- Specify network resources accessible to authentication-free users.
- Complete service verification.
Procedure
- Configure WLAN services.
- Configure DNS.
- Configure network resources accessible to authentication-free users.
- Choose Profile Management page is displayed. . The
- Choose Authentication-free Rule Profile page is displayed. . The
- Set Authentication-free Rule Profile to default_free_rule.
- Click Create. On the Create Authentication-free Rule page that is displayed, set Rule ID to 1 and the authentication-free resource to the IP address of the DNS server.
- Click OK.
- Select the authentication-free rule with the ID 1 and click Apply. In the dialog box that is displayed, click OK.
- Verify the configuration.
- The WLAN with the SSID wlan-net is available.
- The STA can associate with the WLAN and obtain an IP address 10.23.101.x/24 and its gateway address is 10.23.101.1.
- When a user browses a web page, the browser automatically redirects the user to the Portal authentication page. After entering the correct user name and password, the user passes the authentication and can access the web page.
- Choose User, you can see that STAs go online properly and obtain IP addresses. . In
- Maintain local user information.
# Choose Delete to delete the selected user. Click Create to add a local user. The following image shows adding a user.
. Click a user name to modify the password of the user. Click