![Cisco 2100 Series Скачать руководство пользователя страница 559](http://html.mh-extra.com/html/cisco/2100-series/2100-series_configuration-manual_19950559.webp)
10-23
Cisco Wireless LAN Controller Configuration Guide
OL-17037-01
Chapter 10 Managing User Accounts
Configuring Wired Guest Access
Step 4
If you want to define the order in which web authentication servers are contacted, enter this command:
config wlan security web-auth server-precedence
wlan_id
{
local
|
ldap
|
radius
} {
local
|
ldap
|
radius
} {
local
|
ldap
|
radius
}
The default order of server web authentication is local, RADIUS, LDAP.
Note
All external servers must be pre-configured on the controller. You can configure them on the
RADIUS Authentication Servers page and the LDAP Servers page.
Step 5
To define which web authentication page displays for a wireless guest user, enter this command:
config wlan custom-web webauth-type
{
internal
|
customized
|
external
}
wlan_id
where
•
internal
displays the default web login page for the controller. This is the default value.
•
customized
displays the custom web login page that was configured in
.
Note
You do not need to define the web authentication type in
for the login failure and
logout pages as they are always customized.
•
external
redirects users to the URL that was configured in
.
Step 6
To use a WLAN-specific custom web configuration rather than a global custom web configuration, enter
this command:
config wlan custom-web global disable
wlan_id
Note
If you enter the
config wlan custom-web global enable
wlan_id
command, the custom web
authentication configuration at the global level is used.
Step 7
To save your changes, enter this command:
save config
Configuring Wired Guest Access
Wired guest access enables guest users to connect to the guest access network from a wired Ethernet
connection designated and configured for guest access. Wired guest access ports might be available in a
guest office or through specific ports in a conference room. Like wireless guest user accounts, wired
guest access ports are added to the network using the lobby ambassador feature.
Wired guest access can be configured in a standalone configuration or in a dual-controller configuration
that uses both an anchor controller and a foreign controller. This latter configuration is used to further
isolate wired guest access traffic but is not required for deployment of wired guest access.
Wired guest access ports initially terminate on a Layer 2 access switch or switch port configured with
VLAN interfaces for wired guest access traffic. The wired guest traffic is then trunked from the access
switch to a controller. This controller is configured with an interface that is mapped to a wired guest
access VLAN on the access switch. See
.