<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wired Captive Portal Authentication - Roles and Services in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/wired-captive-portal-authentication-roles-and-services/m-p/117290#M1999</link>
    <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;I want to authenticate wired clients with the control captive portal.&lt;BR /&gt;I got universal 5420F Switches running EXOS/Switch Engine.&lt;/P&gt;&lt;P&gt;The goal is:&lt;BR /&gt;All unregistered clients shall be moved to VLAN 400 and redirected to the portal.&lt;BR /&gt;After portal login, the switch needs to apply a different role/policy to the client, based on user groups, to limit network access.&lt;BR /&gt;The VLAN dose not change.&lt;/P&gt;&lt;P&gt;What I got:&lt;BR /&gt;I created a role “Unregistriert”, which uses “Contain to VLAN 400” and “HTTP redirect”.&lt;BR /&gt;The role has some services/rules attached to allow arp, dhcp, dns and traffic to the portal. Last rule should deny all ipv4 traffic.&amp;nbsp; (See Screenshots)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;A client connects, the switch applys "Unregistriert", client is moved to VLAN 400 and gets redirect to the portal, this is working.&lt;BR /&gt;&lt;BR /&gt;But even without logging in to the portal, the client has full network and internet access.&lt;BR /&gt;&lt;BR /&gt;Do you know what is wrong?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;172.17.32.0/20 is the Client subnet in VLAN 400&lt;/P&gt;&lt;P&gt;172.31.2.31 is the control engine.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Niko_P_2-1736346570530.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8661i09EA9732D7BED66F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Niko_P_2-1736346570530.png" alt="Niko_P_2-1736346570530.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Niko_P_0-1736346454660.png" style="width: 950px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8659iB691231A7163A94F/image-dimensions/950x261?v=v2" width="950" height="261" role="button" title="Niko_P_0-1736346454660.png" alt="Niko_P_0-1736346454660.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;BR /&gt;Niko&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jan 2025 14:36:45 GMT</pubDate>
    <dc:creator>Niko_P</dc:creator>
    <dc:date>2025-01-08T14:36:45Z</dc:date>
    <item>
      <title>Wired Captive Portal Authentication - Roles and Services</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/wired-captive-portal-authentication-roles-and-services/m-p/117290#M1999</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;I want to authenticate wired clients with the control captive portal.&lt;BR /&gt;I got universal 5420F Switches running EXOS/Switch Engine.&lt;/P&gt;&lt;P&gt;The goal is:&lt;BR /&gt;All unregistered clients shall be moved to VLAN 400 and redirected to the portal.&lt;BR /&gt;After portal login, the switch needs to apply a different role/policy to the client, based on user groups, to limit network access.&lt;BR /&gt;The VLAN dose not change.&lt;/P&gt;&lt;P&gt;What I got:&lt;BR /&gt;I created a role “Unregistriert”, which uses “Contain to VLAN 400” and “HTTP redirect”.&lt;BR /&gt;The role has some services/rules attached to allow arp, dhcp, dns and traffic to the portal. Last rule should deny all ipv4 traffic.&amp;nbsp; (See Screenshots)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;A client connects, the switch applys "Unregistriert", client is moved to VLAN 400 and gets redirect to the portal, this is working.&lt;BR /&gt;&lt;BR /&gt;But even without logging in to the portal, the client has full network and internet access.&lt;BR /&gt;&lt;BR /&gt;Do you know what is wrong?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;172.17.32.0/20 is the Client subnet in VLAN 400&lt;/P&gt;&lt;P&gt;172.31.2.31 is the control engine.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Niko_P_2-1736346570530.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8661i09EA9732D7BED66F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Niko_P_2-1736346570530.png" alt="Niko_P_2-1736346570530.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Niko_P_0-1736346454660.png" style="width: 950px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8659iB691231A7163A94F/image-dimensions/950x261?v=v2" width="950" height="261" role="button" title="Niko_P_0-1736346454660.png" alt="Niko_P_0-1736346454660.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;BR /&gt;Niko&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 14:36:45 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/wired-captive-portal-authentication-roles-and-services/m-p/117290#M1999</guid>
      <dc:creator>Niko_P</dc:creator>
      <dc:date>2025-01-08T14:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Wired Captive Portal Authentication - Roles and Services</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/wired-captive-portal-authentication-roles-and-services/m-p/117331#M2000</link>
      <description>&lt;P&gt;Problem is solved!&lt;BR /&gt;&lt;BR /&gt;First:&lt;BR /&gt;I had set "Global Domain Settings" to "Role ACL Mode".&lt;BR /&gt;I unchecked that.&lt;BR /&gt;&lt;BR /&gt;Second:&lt;BR /&gt;I changed the "Unregistriert" Role - Access Control to Deny Traffic&lt;BR /&gt;&lt;BR /&gt;Third:&lt;BR /&gt;I use the RFC 3580 - VLAN ID&lt;BR /&gt;Which sets the VLAN via Accept Policy&lt;BR /&gt;&lt;BR /&gt;And last I changed some of the services.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;BR /&gt;Niko&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Niko_P_0-1736437195812.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8670i0DC73CF4E47B008C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Niko_P_0-1736437195812.png" alt="Niko_P_0-1736437195812.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Niko_P_1-1736437246060.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8671iA64464E83A590116/image-size/large?v=v2&amp;amp;px=999" role="button" title="Niko_P_1-1736437246060.png" alt="Niko_P_1-1736437246060.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Niko_P_2-1736437297038.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8672i92EC57C253719E5A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Niko_P_2-1736437297038.png" alt="Niko_P_2-1736437297038.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Niko_P_3-1736437377692.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8673iC6B22DB5CF44CD7C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Niko_P_3-1736437377692.png" alt="Niko_P_3-1736437377692.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Niko_P_4-1736437454160.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8674i6343EF1AA4E481AA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Niko_P_4-1736437454160.png" alt="Niko_P_4-1736437454160.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Niko_P_5-1736437491594.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8675iB97F131C0D84D557/image-size/large?v=v2&amp;amp;px=999" role="button" title="Niko_P_5-1736437491594.png" alt="Niko_P_5-1736437491594.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Niko_P_0-1736437930720.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8676i54EE1DCE0A32AC66/image-size/large?v=v2&amp;amp;px=999" role="button" title="Niko_P_0-1736437930720.png" alt="Niko_P_0-1736437930720.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 15:48:58 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/wired-captive-portal-authentication-roles-and-services/m-p/117331#M2000</guid>
      <dc:creator>Niko_P</dc:creator>
      <dc:date>2025-01-09T15:48:58Z</dc:date>
    </item>
  </channel>
</rss>

