<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: WiNG captive portal re-authentication timeout in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59013#M4683</link>
    <description>Hello Konstantinos,&lt;BR /&gt;
&lt;BR /&gt;
correct - Captive Portal service can maintain authenticated users for 24 hours top.&lt;BR /&gt;
&lt;BR /&gt;
In theory you might workaround it using CP as fallback and mapping AAA-policy as primary authentication method for a WLAN.&lt;BR /&gt;
I.e. using authentication based on MAC and AAA you might be able to drive first attempt towards RADIUS server and if this fails, Captive Portal based authentication as fallback. &lt;BR /&gt;
However, once user gets authenticated and its MAC is withing authenticated, second connection should be first tested against RADIUS server who already know this MAC and there is no need to use CP fallback.&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Ondrej&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
    <dc:creator>Ondrej_Lepa</dc:creator>
    <dc:date>2017-02-20T18:01:00Z</dc:date>
    <item>
      <title>WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59009#M4679</link>
      <description>Hi,    I have setup a captive portal on a VX9000 and I noticed that every day the user has to re-enter the username and password. Is there a way to remain authenticated for as long as the user is valid?    Also is there a way to un-authorize a certain user from the captive portal?</description>
      <pubDate>Wed, 15 Feb 2017 19:37:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59009#M4679</guid>
      <dc:creator>gluo</dc:creator>
      <dc:date>2017-02-15T19:37:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59010#M4680</link>
      <description>Hello Konstantinos,&lt;BR /&gt;
&lt;BR /&gt;
based on your Captive Portal design you may either use access time value / timeout &lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="20b5498c676e4ec390bf1faf0c435b71_RackMultipart20170215-43416-olf4wl-Captive1_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5385i9020E47D3223DAE4/image-size/large?v=v2&amp;amp;px=999" role="button" title="20b5498c676e4ec390bf1faf0c435b71_RackMultipart20170215-43416-olf4wl-Captive1_inline.png" alt="20b5498c676e4ec390bf1faf0c435b71_RackMultipart20170215-43416-olf4wl-Captive1_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Or if it is driven by RADIUS (internal) you may change RADIUS group attributes &lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="20b5498c676e4ec390bf1faf0c435b71_RackMultipart20170215-8708-v0ar6l-Captive2_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1058i89C11EE860AD970E/image-size/large?v=v2&amp;amp;px=999" role="button" title="20b5498c676e4ec390bf1faf0c435b71_RackMultipart20170215-8708-v0ar6l-Captive2_inline.png" alt="20b5498c676e4ec390bf1faf0c435b71_RackMultipart20170215-8708-v0ar6l-Captive2_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
If you want to de-authenticated Captive Portal users you may do it through Statistics - Captive Portal.&lt;BR /&gt;
&lt;BR /&gt;
Please find Captive Portal How to Guide under &lt;A href="https://extremenetworks2com-my.sharepoint.com/personal/olepa_extremenetworks_com/_layouts/15/guestaccess.aspx?docid=1dd38ef67d813470c917d02be4e773a3d&amp;amp;#38;authkey=AUy6iKvdb8ESGWh023iAVFg" target="_blank" rel="nofollow noreferrer noopener"&gt;this link&lt;/A&gt; for more details.&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Ondrej&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 15 Feb 2017 20:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59010#M4680</guid>
      <dc:creator>Ondrej_Lepa</dc:creator>
      <dc:date>2017-02-15T20:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59011#M4681</link>
      <description>Thank you for the swift reply!</description>
      <pubDate>Wed, 15 Feb 2017 20:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59011#M4681</guid>
      <dc:creator>gluo</dc:creator>
      <dc:date>2017-02-15T20:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59012#M4682</link>
      <description>Hi again,&lt;BR /&gt;
&lt;BR /&gt;
I have one more question. &lt;BR /&gt;
It seems that the maximum amount of time a captive portal guest can be inactive (meaning not connected to the wireless network) without the session to timeout and have to re-authenticate can be 24 hours . Is there any way to set it to more than 24 hours? &lt;BR /&gt;
This would allow clients to remain connected over the weekend and not have to re-authenticate each Monday for example.  Or maybe there is another way?&lt;BR /&gt;
&lt;BR /&gt;
thank you in advance.</description>
      <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59012#M4682</guid>
      <dc:creator>gluo</dc:creator>
      <dc:date>2017-02-20T18:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59013#M4683</link>
      <description>Hello Konstantinos,&lt;BR /&gt;
&lt;BR /&gt;
correct - Captive Portal service can maintain authenticated users for 24 hours top.&lt;BR /&gt;
&lt;BR /&gt;
In theory you might workaround it using CP as fallback and mapping AAA-policy as primary authentication method for a WLAN.&lt;BR /&gt;
I.e. using authentication based on MAC and AAA you might be able to drive first attempt towards RADIUS server and if this fails, Captive Portal based authentication as fallback. &lt;BR /&gt;
However, once user gets authenticated and its MAC is withing authenticated, second connection should be first tested against RADIUS server who already know this MAC and there is no need to use CP fallback.&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Ondrej&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59013#M4683</guid>
      <dc:creator>Ondrej_Lepa</dc:creator>
      <dc:date>2017-02-20T18:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59014#M4684</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
Does the mac address need to be manually added or it could be added automatically once the user first authenticates via CP?</description>
      <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59014#M4684</guid>
      <dc:creator>gluo</dc:creator>
      <dc:date>2017-02-20T18:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59015#M4685</link>
      <description>Theoretically speaking it shall pass automatically with first CP authentication - then it relies on RADIUS authentication timeout.&lt;BR /&gt;
&lt;BR /&gt;
Let me test it to get it confirmed.&lt;BR /&gt;
&lt;BR /&gt;
EDIT: In WiNG 5.8.5 I see the access time is extended to max 10080 minutes / 7 days.&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="8774f0d5c01846a98f7347a4490ea0be_RackMultipart20170220-30493-pe85vs-Accesstime_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5122iCC3BEFF250FB121E/image-size/large?v=v2&amp;amp;px=999" role="button" title="8774f0d5c01846a98f7347a4490ea0be_RackMultipart20170220-30493-pe85vs-Accesstime_inline.png" alt="8774f0d5c01846a98f7347a4490ea0be_RackMultipart20170220-30493-pe85vs-Accesstime_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59015#M4685</guid>
      <dc:creator>Ondrej_Lepa</dc:creator>
      <dc:date>2017-02-20T18:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59016#M4686</link>
      <description>It is the &lt;B&gt;inactivity timeout&lt;/B&gt; the value in question that is limited to 1 Day (1440minutes). The above numbers are both the same in 5.8.4. (inactivity timeout &amp;amp; Client Access time)&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59016#M4686</guid>
      <dc:creator>gluo</dc:creator>
      <dc:date>2017-02-20T18:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59017#M4687</link>
      <description>Hi Ondrej,  Did you have a chance to test this?</description>
      <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59017#M4687</guid>
      <dc:creator>gluo</dc:creator>
      <dc:date>2017-02-20T18:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59018#M4688</link>
      <description>Hi Konstantinos,&lt;BR /&gt;
&lt;BR /&gt;
I setup scenario with AP adopted to a controller when AP had Captive Portal service and controller ran RADIUS service.&lt;BR /&gt;
&lt;BR /&gt;
Captive Portal configuration as follows:&lt;BR /&gt;
&lt;BR /&gt;
captive-portal &lt;B&gt;RADIUS&lt;/B&gt; &lt;BR /&gt;
  access-time &lt;B&gt;10&lt;/B&gt;&lt;BR /&gt;
  inactivity-timeout &lt;B&gt;60&lt;/B&gt;&lt;BR /&gt;
  simultaneous-users &lt;B&gt;1&lt;/B&gt;&lt;BR /&gt;
  &lt;OMITTED&gt;&lt;BR /&gt;
  use aaa-policy &lt;B&gt;RADIUS&lt;/B&gt;&lt;BR /&gt;
 &lt;B&gt; bypass captive-portal-detection&lt;/B&gt;&lt;BR /&gt;
  &lt;OMITTED&gt;&lt;BR /&gt;
&lt;BR /&gt;
WLAN configuration as follows:&lt;BR /&gt;
&lt;BR /&gt;
wlan RADIUS &lt;BR /&gt;
  bridging-mode &lt;B&gt;local&lt;/B&gt;&lt;BR /&gt;
  encryption-type &lt;B&gt;none&lt;/B&gt;&lt;BR /&gt;
  authentication-type &lt;B&gt;mac&lt;/B&gt;&lt;BR /&gt;
  use aaa-policy &lt;B&gt;RADIUS&lt;/B&gt;&lt;BR /&gt;
  use captive-portal &lt;B&gt;RADIUS&lt;/B&gt;&lt;BR /&gt;
  captive-portal-enforcement &lt;B&gt;fall-back&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
Then connecting to SSID I see in logs that system first tries to authenticate client against AAA / RADIUS and then failover to Captive Portal&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-32907-153fjwj-Radius1_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5853i3D359399C22A0728/image-size/large?v=v2&amp;amp;px=999" role="button" title="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-32907-153fjwj-Radius1_inline.png" alt="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-32907-153fjwj-Radius1_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Then successful authentication via Captive Portal pages against same RADIUS server&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-36736-1wbbwaf-Radius2_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5665iE695D0A093824C64/image-size/large?v=v2&amp;amp;px=999" role="button" title="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-36736-1wbbwaf-Radius2_inline.png" alt="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-36736-1wbbwaf-Radius2_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
So in theory this will work fine as you see first attempt goes to RADIUS.&lt;BR /&gt;
You might noticed a problem though - AAA policy asks to authenticate user 38-F2-3E-18-5B-04&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-18418-i7at8v-Radius3_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4861i6D0BFCEDC4C676A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-18418-i7at8v-Radius3_inline.png" alt="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-18418-i7at8v-Radius3_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
This is result of having authentication method &lt;B&gt;MAC.&lt;BR /&gt;
&lt;BR /&gt;
&lt;/B&gt;So here we go with a fork:&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;either you have to create a user database based on clients' MAC addresses instead of username and password &lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt; 
&lt;LI&gt;or you will use &lt;A href="https://extremenetworks2com-my.sharepoint.com/personal/vdementyev_extremenetworks_com/Documents/ExtremeWiNG-Summit-November2016/WING5-DOCS/WiNG5_CaptivePortal_External_Self_Registration-RevB.pdf" target="_blank" rel="nofollow noreferrer noopener"&gt;Captive portal guest registration&lt;/A&gt; based on your VX-9000&lt;/LI&gt;&lt;/UL&gt;Problem here is that using authentication we need to send a username to question database. With MAC based authentication we use MAC as one and do not actually link it with a RADIUS user account provided through Captive Portal credentials fields. However it works as correctly, it is not designed to be used with anything else than Guest registration.&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Ondrej&lt;BR /&gt;
&lt;BR /&gt;
EDIT: Just checked RADIUS group policy for timeout options and I have some bad news - it is also limited to 86400 seconds&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-19267-11tzm7b-Radius4_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2773i4A5F2DF6742E231F/image-size/large?v=v2&amp;amp;px=999" role="button" title="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-19267-11tzm7b-Radius4_inline.png" alt="6c4b47eeaf8c4ea78abecdb7c4b051f8_RackMultipart20170221-19267-11tzm7b-Radius4_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
However &lt;A href="https://tools.ietf.org/html/rfc2865#section-5.28" target="_blank" rel="nofollow noreferrer noopener"&gt;RFC2865&lt;/A&gt; does specify its maximum as 32-bit integer, we have limitation for a day in WiNG&lt;/OMITTED&gt;&lt;/OMITTED&gt;</description>
      <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59018#M4688</guid>
      <dc:creator>Ondrej_Lepa</dc:creator>
      <dc:date>2017-02-20T18:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59019#M4689</link>
      <description>Hi Ondrej,  Thank you for your detailed answer and testing. Really helpful information, good job!  My use case is site visitors that are being handed out pre-printed vouchers with username/passwords in order to authenticate and being able to access the WLAN, so there is no previous knowledge of the MAC address, hence the first fork does not fit, please correct me if i am wrong.  About the second fork, I can not download the document because it takes my to your sharepoint  cloud server. So I need your aid with the following:  1. Does self registration allow anyone to access the WLAN?  (That would be a problem in this case) 2. Is it possible to provide a username/password (CP) and then the user enter his own mac (AAA)?   If the second is possible then the inactivity timeout of the RADIUS  holding MAC addresses, would not be a problem since it happens automatically.</description>
      <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59019#M4689</guid>
      <dc:creator>gluo</dc:creator>
      <dc:date>2017-02-20T18:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59020#M4690</link>
      <description>Hi Konstantinos,&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://extremenetworks2com-my.sharepoint.com/personal/olepa_extremenetworks_com/_layouts/15/guestaccess.aspx?docid=1e7053a0a61934cd2a17679e713f0583e&amp;amp;#38;authkey=AaTXEIEGp2k1JzqFYWB200s" target="_blank" rel="nofollow noreferrer noopener"&gt;here&lt;/A&gt; is new link - I probably checked wrong access rights.&lt;BR /&gt;
&lt;BR /&gt;
Anyway, you are right about the self-registration. This allows everyone to access under condition client finishes registration. Might be OAUTH, Click&amp;amp;Tell etc...&lt;BR /&gt;
&lt;BR /&gt;
If you provide the username / password you will capture MAC automatically as it is being recorded by Captive Portal. However, here we are hitting the limit of 86400 seconds.&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="cb7cae988742424fad66aa23025aad09_RackMultipart20170223-10115-lcz2wm-Radius5_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3367i9A4375DD4CC59E40/image-size/large?v=v2&amp;amp;px=999" role="button" title="cb7cae988742424fad66aa23025aad09_RackMultipart20170223-10115-lcz2wm-Radius5_inline.png" alt="cb7cae988742424fad66aa23025aad09_RackMultipart20170223-10115-lcz2wm-Radius5_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Then, yet another issue - if you select AAA policy to be used here, it does not receive any EAP ID from client - remember this is not set on client!&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="cb7cae988742424fad66aa23025aad09_RackMultipart20170223-84073-1j4jr3z-Radius6_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4013iC5FAD29E0A93509B/image-size/large?v=v2&amp;amp;px=999" role="button" title="cb7cae988742424fad66aa23025aad09_RackMultipart20170223-84073-1j4jr3z-Radius6_inline.png" alt="cb7cae988742424fad66aa23025aad09_RackMultipart20170223-84073-1j4jr3z-Radius6_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Any authentication method (other than MAC) requires client to be induced in identification. But with open network client does not provide any.&lt;BR /&gt;
So in the end authentication request will failover back to Captive Portal.&lt;BR /&gt;
&lt;BR /&gt;
I am afraid there is only solution for this use case - externally hosted custom pages capturing the MAC used with an CP voucher and creating a &lt;I&gt;﻿fake &lt;/I&gt;﻿RADIUS guest user account based on the MAC address - quite demanding one.&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Ondrej</description>
      <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59020#M4690</guid>
      <dc:creator>Ondrej_Lepa</dc:creator>
      <dc:date>2017-02-20T18:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59021#M4691</link>
      <description>Thank you Ondrej. Your help was enlightening!</description>
      <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59021#M4691</guid>
      <dc:creator>gluo</dc:creator>
      <dc:date>2017-02-20T18:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: WiNG captive portal re-authentication timeout</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59022#M4692</link>
      <description>Glad to help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Ondrej</description>
      <pubDate>Mon, 20 Feb 2017 18:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-re-authentication-timeout/m-p/59022#M4692</guid>
      <dc:creator>Ondrej_Lepa</dc:creator>
      <dc:date>2017-02-20T18:01:00Z</dc:date>
    </item>
  </channel>
</rss>

