background image

ArubaOS   +   Amigopod   Integration   Cheet   Sheet   

   

   

   

Aruba   Networks   |   

2

   

Table   of   Contents

   

   

1.    Create   RADIUS   Server   instance   ...........................................................................................................   3   

2.    Add   RADIUS   Server   to   a   Server   Group   .................................................................................................   3   

3.    Create   Captive   Portal   Profile   ...............................................................................................................   4   

4.    Configure   Authentication   for   Captive   Portal   Profile   ............................................................................   5   

5.    Create   AAA   Profile   ...............................................................................................................................   6   

6.    Enable   Captive   Portal   on   Initial   Role   of   Captive   Portal   Profile   ............................................................   7   

7.    Ensure   the   Amigopod   IP   Address   allowed   in   captiveportal   policy   ......................................................   8   

8.    Configure   Guest   VAP   with   new   AAA   Profile   ........................................................................................   9   

9.    Configure   RADIUS   NAS   for   Aruba   Controller   .....................................................................................   10   

10.    Configure   Web   Login   for   Captive   Portal   Authentication   .................................................................   11   

11.    Configure   RADIUS   User   Role   ............................................................................................................   15   

13.    Check   RADIUS   Accounting   is   working   as   expected   ..........................................................................   17   

14.    Troubleshooting   Tips   .......................................................................................................................   18   

   

   
   
   

   

   

Содержание ArubaOS

Страница 1: ...FOR ARUBA NETWORKS EMPLOYEES CUSTOMERS AND PARTNERS ArubaOS Amigopod Integration Cheat Sheet...

Страница 2: ...rofile 5 5 Create AAA Profile 6 6 Enable Captive Portal on Initial Role of Captive Portal Profile 7 7 Ensure the Amigopod IP Address allowed in captiveportal policy 8 8 Configure Guest VAP with new AA...

Страница 3: ...a RADIUS server so the basis of the integration in ArubaOS is the full AAA config Amigopod uses the default ports of 1812 for Authentication and 1813 for Accounting 2 Add RADIUS Server to a Server Gr...

Страница 4: ...tionally Welcome Pages to be hosted by Amigopod For example we could set these pages to the following Login Page https Amigopod IP Address or FQDN Aruba_login php Welcome Page https Amigopod IP Addres...

Страница 5: ...t Sheet Aruba Networks 5 4 Configure Authentication for Captive Portal Profile Now the new Captive Portal Profile has been created make sure the Server Group for the Amigopod RADIUS definition is sele...

Страница 6: ...5 Create AAA Profile The AAA Profile should be configured to have the Initial Role reference the newly created Captive Portal Profile Also ensure the RADIUS Accounting Server Group of the AAA profile...

Страница 7: ...ble Captive Portal on Initial Role of Captive Portal Profile This step is easy to miss and the Captive Portal will not be triggered Select the configured Captive Portal profile from the dropdown box a...

Страница 8: ...gh the CLI or GUI It is handy to define the Amigopod appliance in an alias definition as shown below netdestination Amigopod host 10 0 20 15 Add an entry that allows the client based HTTPS traffic to...

Страница 9: ...appropriate AP Group To activate the new Amigopod specific Guest configuration edit your VAP and ensure the AAA Profile for the VAP is set to the new AAA Profile configured in the previous step Assum...

Страница 10: ...ic Authorization As usual the shared secret must match on the Amigopod and the ArubaOS RADIUS Server definition You can optionally check the Web Login option at the bottom of the form to automatically...

Страница 11: ...utomatically created Web Login but you can equally create a new one manually at a later stage The Page Name field is what defines the URL that will be hosted on the Amigopod appliance For example in s...

Страница 12: ...u can enable the display of an Accept Terms Conditions option of the login page if required This refers to the default T Cs URL defined under Guest Manager Customization Customize Guest Manager Unfort...

Страница 13: ...n see there are options to Insert Content and Self Registration page respectively found in Administrator Content Manager Guest Manager Customization Guest Self Registration You will notice the code at...

Страница 14: ...e Login Message HTML will be displayed This is a useful point to grab the contents of a View Source in the client s browser if you need to troubleshoot any Captive Portal issues Finally each Web Login...

Страница 15: ...ributes These attributes can be used to signal role based access control context back to the Aruba Controller as shown in the example screenshot This RADIUS Role is presented in the Create User screen...

Страница 16: ...ully redirected to the Amigopod Web Login page Use the Amigopod Guest Manager to create a test account and then attempt to login via the redirected Web Login page If you have been able to successfully...

Страница 17: ...sions screen shown below Given the Interim Accounting support in ArubaOS 6 1 this screen will display live traffic statistics based on these updates Assuming you have configured RFC 3576 on your Aruba...

Страница 18: ...ensure traffic is permitted to configured IP address of the controller in the step above Receiving error message in RADIUS Logs about unknown client Check the RADIUS NAS List and make sure there is a...

Страница 19: ...kplace Is Now Open For Business Green Island and The Mobile Edge Company are trademarks of Aruba Networks Inc All rights reserved Aruba Networks reserves the right to change modify transfer or otherwi...

Отзывы: