Captive portal authentication is typically used for hotspot users and paying guests such as hotel guests who purchase access time for an Internet connection. You can configure only a single captive portal on the wireless controller.
The wireless controller supports two types of portal settings:
- Guest portal. Use this portal if all wireless users are allowed to access the network by supplying only their email address. You do not need to define user names and passwords for these users.
- Captive portal. Use this portal type if wireless users must supply their login name and password before being allowing access the network. You must define user names and passwords for these users (see "How do I manage users, accounts, and passwords on my ProSAFE Wireless Controller WC7600?").
When you configure a captive portal, you can use either the wireless controller as a local authentication server for the captive portal clients, or you can configure an external RADIUS server for authentication.
Note:If the network authentication uses an external RADIUS server, you cannot configure captive portal authentication. That is, if you configure an external RADIUS server with WPA, WPA2, or WPA & WPA2 (or if you use legacy 802.1X), you cannot configure captive portal authentication; the network authentication must be Open System, Shared Key, WPA-PSK, WPA2-PSK, or WPA-PSK & WPA2-PSK (see "What are the network authentication and data encryption options for my ProSAFE Wireless Controller WC7600?").
Note these guidelines for captive portal user authentication and accounting through an external RADIUS server:
- You can use either the basic-Auth RADIUS server or a RADIUS server of an advanced authentication group. You cannot use the external LDAP server.
- The wireless controller uses CHAP or MS-CHAP as the authentication protocol with the authentication server.
- The following RADIUS authentication variables are supported on the wireless controller:
-User-Name
-User-Password
-WISPr-Session-Terminate-Time
-Session-Timeout
If you change the values for any of these variables before the wireless client disassociates from the access point, the new values are not updated on the wireless controller. - A managed access point can send accounting information to the external RADIUS server
because the wireless controller functions as a proxy RADIUS client for the managed
access point. The following RADIUS accounting variables are supported on the wireless
controller:
-Acct-Input-Octets
-Acct-Output-Octets
-Acct-Input-Gigawords
-Acct-Input-Gigawords