Chapter 12 Common Configuration Examples
158
Aerohive
Configuring a Captive Web Portal
In this example, you configure a captive web portal to provide guests with wireless network access. The
configuration includes the following elements:
"Captive Web Portal"
– Define a captive web portal that uses self-registration, the auto-generated web pages
provided in HiveManager, and external DHCP and DNS servers.
"QoS Rate Limiting"
– To preserve bandwidth for employees, reduce the rate limit for guests somewhat.
"Firewall Policy" on page 159
– To maintain security, restrict visitors to accessing just the public network.
"User Profile" on page 161
– Apply the QoS rate limiting and firewall policy to the user profile that the HiveAP
applies to traffic from successfully registered users.
"SSID" on page 163
– Configure an SSID that secures wireless traffic with a preshared key and permits access to
the public network only through the captive web portal.
"WLAN Policy" on page 164
– Add the SSID to a WLAN policy.
"Files and Configuration Upload" on page 164
– Push the captive web portal files and the WLAN policy to the
managed HiveAPs.
Guests use a preshared key to secure wireless traffic between their wireless clients and HiveAPs. After forming a
secure association with a HiveAP, the HiveAP intercepts all outbound traffic—except DHCP, DNS, and ICMP
traffic—and presents them with a self-registration page. The guests must complete a form and accept a network
usage policy before being allowed to access the public network. Registered visitors’ activity can be tracked and
stored in historical logs on a syslog server for security and compliance auditing.
Captive Web Portal
To create a captive web portal requiring users to self-register to gain network access, click Configuration >
Advanced Configuration > Authentication > Captive Web Portals > New, enter the following, leave all the
other values at their default settings, and then click Save:
Name: CWP-guest1
Registration Type: Self-registration
Description: Captive web portal for guest registration
Leaving everything else at its default setting creates a captive web portal configuration that uses all the
predefined web files and the default network settings. The DHCP, DNS, and ICMP traffic from the clients of
unregistered users is allowed to pass through the HiveAP to external servers.
QoS Rate Limiting
To allot guests with enough bandwidth to satisfy basic network access but not enough to interfere with
employee traffic, click Configuration > Advanced Configuration > QoS Policies > Rate Control & Queuing >
New, enter the following, and then click Save:
Name: QoS-Guests
Per User Rate Limit: 2000 Kbps for 802.11a/b/g; 2000 Kbps for 802.11n
This is the maximum amount of bandwidth that a single user belonging to this profile can use. It is far less
than the bandwidth you can reserve for other users such as employees, but it should be sufficient for basic
web access for visitors.
Description: QoS per guest
Содержание access point
Страница 1: ...Aerohive Deployment Guide ...
Страница 7: ...HiveAP Compliance Information 6 Aerohive ...
Страница 13: ...Contents 12 Aerohive ...
Страница 37: ...Chapter 2 The HiveAP 20 ag Platform 36 Aerohive ...
Страница 71: ...Chapter 4 The HiveAP 340 Platform 70 Aerohive ...
Страница 81: ...Chapter 5 The HiveAP 320 Platform 80 Aerohive ...
Страница 105: ...Chapter 8 The High Capacity HiveManager Platform 104 Aerohive ...
Страница 123: ...Chapter 10 Using HiveManager 122 Aerohive ...
Страница 209: ...Chapter 14 Deployment Examples CLI 208 Aerohive ...
Страница 217: ...Appenidix A Country Codes 216 Aerohive ...