Creating Adoption Rules............................................................................................................................................................64
Centralized Site with AAA Network..................................................................................... 67
Deployment Strategy....................................................................................................................................................................67
Conguring a AAA Network.....................................................................................................................................................67
Creating an Engine Rule............................................................................................................................................................ 69
Creating a Policy Role................................................................................................................................................................... 69
Applying a AAA Network and Role to the Device Group..................................................................................70
Deploying a Mesh Network..................................................................................................... 72
Deployment Strategy....................................................................................................................................................................72
Mesh Point Network Settings.................................................................................................................................................73
Congure Device Groups for Mesh Point...................................................................................................................... 73
Advanced Conguration Prole and Mesh Device Settings...........................................................................75
Prole Advanced Settings................................................................................................................................................75
Edit Mesh Device Settings...............................................................................................................................................76
Congure Transparent Bridge............................................................................................................................................... 79
Conguring an External NAC Server for MBA and AAA Authentication ................ 81
Deployment Strategy.....................................................................................................................................................................81
Conguring the External NAC Server...............................................................................................................................82
Network with Default Auth Role..........................................................................................................................................84
Conguring an MBA Network..................................................................................................................................... 84
Conguring a AAA Network...........................................................................................................................................85
Network with Pass-Through External RADIUS......................................................................................................... 87
Conguring an MBA Network......................................................................................................................................87
Conguring a AAA Network.......................................................................................................................................... 88
Manage RADIUS Servers for User Authentication........................................................... 91
RADIUS Settings................................................................................................................................................................................92
Advanced RADIUS Settings..................................................................................................................................................... 92
Congure a Pass Through Rule............................................................................................................................................ 94
External Captive Portal on a Third-Party Server..............................................................95
Firewall Friendly External Captive Portal Flow of Events..................................................................................96
FF-ECP on ExtremeCloud IQ Controller...............................................................................................................96
Congure the Firewall..................................................................................................................................................................98
Congure an External Captive Portal...............................................................................................................................98
Understand Processing Performed by the ECP...................................................................................................... 99
The Redirection URL Sent from ExtremeCloud IQ Controller............................................................ 99
Compose the Login or Splash Screen Page.....................................................................................................110
Approve the Client..........................................................................................................................................................................110
Compose the Redirection Response Sending the Browser back to the Appliance....................111
Signing the Redirection to ExtremeCloud IQ Controller.........................................................................111
Case 1: When a RADIUS Server Authenticates the Client.......................................................................112
Case 2: When the ECP is the Final Authority...................................................................................................114
Access Control Rule Admin Portal Access........................................................................118
Deployment Strategy...................................................................................................................................................................118
Congure Access Control Group......................................................................................................................................... 119
Default Access Control Groups..................................................................................................................................120
Congure Admin Access Policy Role................................................................................................................................121
Congure Access Control Rule.............................................................................................................................................122
Table of Contents
iv ExtremeCloud IQ Controller Deployment Guide for version 10.05.02