<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Extreme Wireless Controller Redirect to External Captive Portal in ExtremeWireless (Identifi)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54417#M6186</link>
    <description>Hi Extreme experts,&lt;BR /&gt;
&lt;BR /&gt;
I have a question regarding (Firewall friendly) External Captive Portal Redirection.&lt;BR /&gt;
&lt;BR /&gt;
First my goal:&lt;BR /&gt;
I need to integrate the Extreme Wireless Controller into an external Captive Portal System.&lt;BR /&gt;
- The Portal System first needs a MAC Authentication Request via RADIUS (like Extreme NAC) - which is accepted.&lt;BR /&gt;
- The Portal expects a URL-Request: "https://&lt;I&gt;:8443/ahsfasdzfgfaszdfd&amp;amp;mac=00-11-22-33-44-55" where 00-11-22-33-44-55 is the MAC of the Client.&lt;BR /&gt;
&lt;BR /&gt;
The Extreme Wireless Controller should do the following:&lt;BR /&gt;
1) Send MAC Authentication Request to Portal-System&lt;BR /&gt;
2) Redirect any HTTP/HTTPS request to "https://&lt;I&gt;:8443/ahsfasdzfgfaszdfd&amp;amp;mac=00-11-22-33-44-55"&lt;BR /&gt;
3) After successfull authentication the  Role of the client should be changed via RADIUS-CoA.&lt;BR /&gt;
&lt;BR /&gt;
What I tried is the Firewall Friendly External Captive Portal with the following settings:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-14809-sh0neq-FF_Redirect_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3641i1A074F76D1309093/image-size/large?v=v2&amp;amp;px=999" role="button" title="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-14809-sh0neq-FF_Redirect_inline.png" alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-14809-sh0neq-FF_Redirect_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-u67b12-FF_Redirect_2_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/622iFBE6F99462C3E947/image-size/large?v=v2&amp;amp;px=999" role="button" title="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-u67b12-FF_Redirect_2_inline.png" alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-u67b12-FF_Redirect_2_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
But unfortunately that configuration does not work.&lt;BR /&gt;
1) If MAC Authentication is enabled no redirection is performed (The return Policy role is identical to the Unauthenticated Role in VNS settings). If I disable the MAC Authentication on the WLAN Service URL-Redirection is performed but with unexpected attributes:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-1w85xzp-FF_Redirect_3_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2367iA09E1D93F79992B1/image-size/large?v=v2&amp;amp;px=999" role="button" title="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-1w85xzp-FF_Redirect_3_inline.png" alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-1w85xzp-FF_Redirect_3_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Is there any way to disable the unwanted attributes dst, token and wlan?&lt;BR /&gt;
How can I perform MAC Authentication and Redirection?&lt;BR /&gt;
&lt;BR /&gt;
Any ideas?&lt;BR /&gt;
&lt;BR /&gt;
Best Regards&lt;BR /&gt;
Michael&lt;/I&gt;&lt;/I&gt;</description>
    <pubDate>Sun, 08 Nov 2015 23:21:00 GMT</pubDate>
    <dc:creator>Michael_Kirchne</dc:creator>
    <dc:date>2015-11-08T23:21:00Z</dc:date>
    <item>
      <title>Extreme Wireless Controller Redirect to External Captive Portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54417#M6186</link>
      <description>Hi Extreme experts,&lt;BR /&gt;
&lt;BR /&gt;
I have a question regarding (Firewall friendly) External Captive Portal Redirection.&lt;BR /&gt;
&lt;BR /&gt;
First my goal:&lt;BR /&gt;
I need to integrate the Extreme Wireless Controller into an external Captive Portal System.&lt;BR /&gt;
- The Portal System first needs a MAC Authentication Request via RADIUS (like Extreme NAC) - which is accepted.&lt;BR /&gt;
- The Portal expects a URL-Request: "https://&lt;I&gt;:8443/ahsfasdzfgfaszdfd&amp;amp;mac=00-11-22-33-44-55" where 00-11-22-33-44-55 is the MAC of the Client.&lt;BR /&gt;
&lt;BR /&gt;
The Extreme Wireless Controller should do the following:&lt;BR /&gt;
1) Send MAC Authentication Request to Portal-System&lt;BR /&gt;
2) Redirect any HTTP/HTTPS request to "https://&lt;I&gt;:8443/ahsfasdzfgfaszdfd&amp;amp;mac=00-11-22-33-44-55"&lt;BR /&gt;
3) After successfull authentication the  Role of the client should be changed via RADIUS-CoA.&lt;BR /&gt;
&lt;BR /&gt;
What I tried is the Firewall Friendly External Captive Portal with the following settings:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-14809-sh0neq-FF_Redirect_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3641i1A074F76D1309093/image-size/large?v=v2&amp;amp;px=999" role="button" title="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-14809-sh0neq-FF_Redirect_inline.png" alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-14809-sh0neq-FF_Redirect_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-u67b12-FF_Redirect_2_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/622iFBE6F99462C3E947/image-size/large?v=v2&amp;amp;px=999" role="button" title="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-u67b12-FF_Redirect_2_inline.png" alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-u67b12-FF_Redirect_2_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
But unfortunately that configuration does not work.&lt;BR /&gt;
1) If MAC Authentication is enabled no redirection is performed (The return Policy role is identical to the Unauthenticated Role in VNS settings). If I disable the MAC Authentication on the WLAN Service URL-Redirection is performed but with unexpected attributes:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-1w85xzp-FF_Redirect_3_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2367iA09E1D93F79992B1/image-size/large?v=v2&amp;amp;px=999" role="button" title="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-1w85xzp-FF_Redirect_3_inline.png" alt="30fb81785a8d4dd7b033fed27d38bd8d_RackMultipart20151108-9621-1w85xzp-FF_Redirect_3_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Is there any way to disable the unwanted attributes dst, token and wlan?&lt;BR /&gt;
How can I perform MAC Authentication and Redirection?&lt;BR /&gt;
&lt;BR /&gt;
Any ideas?&lt;BR /&gt;
&lt;BR /&gt;
Best Regards&lt;BR /&gt;
Michael&lt;/I&gt;&lt;/I&gt;</description>
      <pubDate>Sun, 08 Nov 2015 23:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54417#M6186</guid>
      <dc:creator>Michael_Kirchne</dc:creator>
      <dc:date>2015-11-08T23:21:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme Wireless Controller Redirect to External Captive Portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54418#M6187</link>
      <description>How to you have your policies setup roles? You have to makes sure that this information is allowed based on your policy. &lt;BR /&gt;
&lt;BR /&gt;
If you go to VNS &amp;gt; Roles &amp;gt; &lt;U&gt;&lt;BR /&gt;
&lt;BR /&gt;
Verify that the services that you need to pass are allowed. Also please do not forget that the rules are run from top to bottom, so placement of your allows and denies are key&lt;BR /&gt;
&lt;BR /&gt;
Please let me know if this does or does not work so I can assist further &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;/U&gt;</description>
      <pubDate>Mon, 09 Nov 2015 23:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54418#M6187</guid>
      <dc:creator>Joseph_Burnswor</dc:creator>
      <dc:date>2015-11-09T23:19:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme Wireless Controller Redirect to External Captive Portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54419#M6188</link>
      <description>Hi Joseph,&lt;BR /&gt;
&lt;BR /&gt;
first - thanks for your advice. I double checked bute unfortunately all necessary traffic is allowed.&lt;BR /&gt;
&lt;BR /&gt;
In fact&lt;BR /&gt;
&lt;BR /&gt;
I allow ARP, BootP, DNS, IP to WLC, IP to Portal and deny the rest&lt;BR /&gt;
&lt;BR /&gt;
Should be enough and the Role works if I do no MACAuth.&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
&lt;BR /&gt;
Michael&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 09 Nov 2015 23:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54419#M6188</guid>
      <dc:creator>Michael_Kirchne</dc:creator>
      <dc:date>2015-11-09T23:19:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme Wireless Controller Redirect to External Captive Portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54420#M6189</link>
      <description>You are very welcome. I just had a thought. Is this a virtual controller or a physical controller?&lt;BR /&gt;
&lt;BR /&gt;
The reason I ask is, now that I am thinking about it I had a similar issue with guest in the past. it ended up being the port group security on the VSwitch in VMWare. If it is indeed a virtual controller and in VMWare, can you verify that the security settings look like this for that particular port group?&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="c740fec599084a34bd6ee46591a597f4_RackMultipart20151113-5449-bp5zkd-Controller_Vswitch_Security_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3932i35F68AFB19755BCD/image-size/large?v=v2&amp;amp;px=999" role="button" title="c740fec599084a34bd6ee46591a597f4_RackMultipart20151113-5449-bp5zkd-Controller_Vswitch_Security_inline.png" alt="c740fec599084a34bd6ee46591a597f4_RackMultipart20151113-5449-bp5zkd-Controller_Vswitch_Security_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Otherwise, VMWare won't let the MAC through</description>
      <pubDate>Mon, 09 Nov 2015 23:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54420#M6189</guid>
      <dc:creator>Joseph_Burnswor</dc:creator>
      <dc:date>2015-11-09T23:19:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme Wireless Controller Redirect to External Captive Portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54421#M6190</link>
      <description>Hi&lt;BR /&gt;
&lt;BR /&gt;
Firstly if you haven't already I would recommend you study the guide found in this article: &lt;A href="https://gtacknowledge.extremenetworks.com/articles/Q_A/What-is-a-Firewall-Friendly-External-Captive-Portal-on-the-IdentiFi-Appliance" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/Q_A/What-is-a-Firewall-Friendly-External-Captive-Portal-on-the-IdentiFi-Appliance&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
It would be interesting to note the state of the client in the report after MBA (MAC based auth) has completed, in the left column is a padlock that indicates the various states the client is in, hanging your mouse over the padlock will give further details of the state.&lt;BR /&gt;
&lt;BR /&gt;
As you will see in the guide, the unwanted attributes you inquired about are mandatory.&lt;BR /&gt;
&lt;BR /&gt;
As Joseph said, check that your rule allows the client to reach the external web server on the ports you have configured, along with having dns/dhcp working and denying everything else.&lt;BR /&gt;
&lt;BR /&gt;
I would also consider working on getting the authentication piece working first, then add in the MBA.&lt;BR /&gt;
&lt;BR /&gt;
-Gareth</description>
      <pubDate>Tue, 10 Nov 2015 00:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54421#M6190</guid>
      <dc:creator>Gareth_Mitchell</dc:creator>
      <dc:date>2015-11-10T00:05:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme Wireless Controller Redirect to External Captive Portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54422#M6191</link>
      <description>Hi Gareth,&lt;BR /&gt;
&lt;BR /&gt;
thanks a lot for your provided information. I checked the document and see that the unanwanted attributes are mandatory.&lt;BR /&gt;
&lt;BR /&gt;
Do you see any chance to realize the requirement of the portal system?&lt;BR /&gt;
&lt;BR /&gt;
Requirement is to redirect to a url like: https://%3cip/DNS%3E:8443/ahsfasdzfgfaszdfd&amp;amp;mac=001122334455&lt;BR /&gt;
&lt;BR /&gt;
? -&amp;gt; Without token, ect.&lt;BR /&gt;
&lt;BR /&gt;
Or would that be a feature request?&lt;BR /&gt;
&lt;BR /&gt;
With best Regards&lt;BR /&gt;
&lt;BR /&gt;
Michael&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 10 Nov 2015 00:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54422#M6191</guid>
      <dc:creator>Michael_Kirchne</dc:creator>
      <dc:date>2015-11-10T00:05:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme Wireless Controller Redirect to External Captive Portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54423#M6192</link>
      <description>Hi Michael&lt;BR /&gt;
&lt;BR /&gt;
To strip these values would require you to submit a feature request.&lt;BR /&gt;
&lt;BR /&gt;
In your URL, what does the string ahsfasdzfgfaszdfd actually refer to?&lt;BR /&gt;
&lt;BR /&gt;
-Gareth</description>
      <pubDate>Tue, 10 Nov 2015 00:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54423#M6192</guid>
      <dc:creator>Gareth_Mitchell</dc:creator>
      <dc:date>2015-11-10T00:05:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme Wireless Controller Redirect to External Captive Portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54424#M6193</link>
      <description>Hi Gareth&lt;BR /&gt;
&lt;BR /&gt;
"ahsfasdzfgfaszdfd" is just a place holder for a static reference. The portal system in this case can handle multiple mandators, so for each portal a spespific mandadtor reference needs to be included in the redirect URL - but that reference is static.&lt;BR /&gt;
&lt;BR /&gt;
Best Regards&lt;BR /&gt;
&lt;BR /&gt;
Michael&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 10 Nov 2015 00:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54424#M6193</guid>
      <dc:creator>Michael_Kirchne</dc:creator>
      <dc:date>2015-11-10T00:05:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme Wireless Controller Redirect to External Captive Portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54425#M6194</link>
      <description>Michael&lt;BR /&gt;
&lt;BR /&gt;
Could you not, for example, use the VNS name attribute as an identifier?&lt;BR /&gt;
&lt;BR /&gt;
At this point I would probably recommend you get a case opened for this so we can track it and make sure we are fully understanding your requirements.&lt;BR /&gt;
&lt;BR /&gt;
-Gareth&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 10 Nov 2015 00:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54425#M6194</guid>
      <dc:creator>Gareth_Mitchell</dc:creator>
      <dc:date>2015-11-10T00:05:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme Wireless Controller Redirect to External Captive Portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54426#M6195</link>
      <description>Hi Michael,&lt;BR /&gt;
Were you able to get this working?&lt;BR /&gt;</description>
      <pubDate>Wed, 11 Nov 2015 22:23:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/extreme-wireless-controller-redirect-to-external-captive-portal/m-p/54426#M6195</guid>
      <dc:creator>Drew_C</dc:creator>
      <dc:date>2015-11-11T22:23:00Z</dc:date>
    </item>
  </channel>
</rss>

