<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wing Captive Portal with radius accounting (Access Duration) in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-with-radius-accounting-access-duration/m-p/69856#M6313</link>
    <description>&lt;P&gt;I have the same problem. Did you solve it?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Aug 2021 16:24:02 GMT</pubDate>
    <dc:creator>a_socias</dc:creator>
    <dc:date>2021-08-05T16:24:02Z</dc:date>
    <item>
      <title>Wing Captive Portal with radius accounting (Access Duration)</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-with-radius-accounting-access-duration/m-p/69855#M6312</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;I have setup a lab for testing wing (5.9) using RFS4000 and a small AP7612.&lt;/P&gt; &lt;P&gt;I want to enable captive portal with limited life time of a guest user account - X time from when the user first logins.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;I have a working captive portal with radius authentication and only the radius accounting is missing or miss-configured i believe..?&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;What happens now is i can login but the time showing on splash page is not what i set in access duration.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Configuration:&lt;/P&gt; &lt;PRE&gt;&lt;CODE&gt;rfs4000-FB6D71#show run device self &lt;BR /&gt;!&lt;BR /&gt;version 2.6&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;client-identity-group default&lt;BR /&gt; load default-fingerprints&lt;BR /&gt;!&lt;BR /&gt;firewall-policy FW-POLICY&lt;BR /&gt; no ip dos smurf&lt;BR /&gt; no ip dos twinge&lt;BR /&gt; no ip dos invalid-protocol&lt;BR /&gt; no ip dos router-advt&lt;BR /&gt; no ip dos router-solicit&lt;BR /&gt; no ip dos option-route&lt;BR /&gt; no ip dos ascend&lt;BR /&gt; no ip dos chargen&lt;BR /&gt; no ip dos fraggle&lt;BR /&gt; no ip dos snork&lt;BR /&gt; no ip dos ftp-bounce&lt;BR /&gt; no ip dos tcp-intercept&lt;BR /&gt; no ip dos broadcast-multicast-icmp&lt;BR /&gt; no ip dos land&lt;BR /&gt; no ip dos tcp-xmas-scan&lt;BR /&gt; no ip dos tcp-null-scan&lt;BR /&gt; no ip dos winnuke&lt;BR /&gt; no ip dos tcp-fin-scan&lt;BR /&gt; no ip dos udp-short-hdr&lt;BR /&gt; no ip dos tcp-post-syn&lt;BR /&gt; no ip dos tcphdrfrag&lt;BR /&gt; no ip dos ip-ttl-zero&lt;BR /&gt; no ip dos ipspoof&lt;BR /&gt; no ip dos tcp-bad-sequence&lt;BR /&gt; no ip dos tcp-sequence-past-window&lt;BR /&gt; no ip-mac conflict&lt;BR /&gt; no ip-mac routing conflict&lt;BR /&gt; dhcp-offer-convert&lt;BR /&gt; no stateful-packet-inspection-l2&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;mint-policy global-default&lt;BR /&gt;!&lt;BR /&gt;aaa-policy AAA-POLICY&lt;BR /&gt; authentication server 1 onboard controller&lt;BR /&gt; accounting server 1 onboard controller&lt;BR /&gt; accounting type start-interim-stop&lt;BR /&gt; accounting interim interval 60&lt;BR /&gt;! &lt;BR /&gt;captive-portal CAPTIVE-PORTAL-POLICY-GUEST&lt;BR /&gt; server host 192.168.2.2&lt;BR /&gt; server mode centralized&lt;BR /&gt; use aaa-policy AAA-POLICY&lt;BR /&gt; bypass captive-portal-detection&lt;BR /&gt; webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt; webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt; webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt; webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt; webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt; webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt; webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt; webpage internal registration field email type e-address enable mandatory label "Email" placeholder "you@domain.com"&lt;BR /&gt; webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;!&lt;BR /&gt;radius-group RADIUS-GROUP-POLICY-GUEST&lt;BR /&gt; guest&lt;BR /&gt; policy ssid THE-KRAKEN&lt;BR /&gt; policy day mo&lt;BR /&gt; policy day tu&lt;BR /&gt; policy day we&lt;BR /&gt; policy day th&lt;BR /&gt; policy day fr&lt;BR /&gt; policy day sa&lt;BR /&gt; policy day su&lt;BR /&gt;!&lt;BR /&gt;radius-user-pool-policy USER-POOL-GUEST&lt;BR /&gt; user a password 0 a group RADIUS-GROUP-POLICY-GUEST guest expiry-time 14:04 expiry-date 12/19/2019 start-time 14:04 start-date 12/17/2019 access-duration 15&lt;BR /&gt;!&lt;BR /&gt;radius-server-policy RADIUS-SERVER-POLICY&lt;BR /&gt; use radius-user-pool-policy USER-POOL-GUEST&lt;BR /&gt; chase-referral&lt;BR /&gt;!&lt;BR /&gt;dhcp-server-policy DHCP&lt;BR /&gt; option AP-adoption 191 ascii&lt;BR /&gt; dhcp-pool WING-MGMT&lt;BR /&gt; network 172.16.7.0/24&lt;BR /&gt; address range 172.16.7.10 172.16.7.50 &lt;BR /&gt; default-router 172.16.7.1&lt;BR /&gt; dns-server 8.8.8.8&lt;BR /&gt; dhcp-pool WING-CLIENTS&lt;BR /&gt; network 192.168.2.0/24&lt;BR /&gt; address range 192.168.2.10 192.168.2.50 &lt;BR /&gt; default-router 192.168.2.1&lt;BR /&gt; dns-server 8.8.8.8&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;management-policy MANAGEMENT-POLICY&lt;BR /&gt; no telnet&lt;BR /&gt; http server&lt;BR /&gt; https server&lt;BR /&gt; rest-server&lt;BR /&gt; ssh&lt;BR /&gt; user admin password 1 5bb2c75fdb4404c6fd063a3b939f5507bcc66ba75afcbca97150d60e947e3770 role superuser access all&lt;BR /&gt; user manager password 1 87e8acd35619b384182b2163e81e51ca3c09cc8e0a7136e90f0597cd82eddec6 role web-user-admin &lt;BR /&gt;!&lt;BR /&gt;ex3500-management-policy default&lt;BR /&gt; snmp-server community public ro&lt;BR /&gt; snmp-server community private rw&lt;BR /&gt; snmp-server notify-filter 1 remote 127.0.0.1&lt;BR /&gt; snmp-server view defaultview 1 included&lt;BR /&gt;!&lt;BR /&gt;nsight-policy NSIGHT-POLICY&lt;BR /&gt; server host 172.16.7.200 https&lt;BR /&gt;!&lt;BR /&gt;rfs4000 B4-C7-99-FB-6D-71&lt;BR /&gt; use rf-domain LABB-NMC&lt;BR /&gt; license AP DEFAULT-6AP-LICENSE&lt;BR /&gt; license ADSEC DEFAULT-ADV-SEC-LICENSE&lt;BR /&gt; country-code se&lt;BR /&gt; use nsight-policy NSIGHT-POLICY&lt;BR /&gt; no wep-shared-key-auth&lt;BR /&gt; no legacy-auto-update ap650&lt;BR /&gt; no service wireless ap650 legacy-auto-update-image&lt;BR /&gt; no legacy-auto-update ap71xx image&lt;BR /&gt; no service wireless ap300 image&lt;BR /&gt; service wireless wispe-controller-port 24576&lt;BR /&gt; service wireless ap300 flush-ps-packet-timeout 86400&lt;BR /&gt; legacy-auto-downgrade&lt;BR /&gt; no radius nas-identifier&lt;BR /&gt; no radius nas-port-id&lt;BR /&gt; no sku-bypass&lt;BR /&gt; service wireless rate-scaling-mode histogram&lt;BR /&gt; neighbor-info-interval 10&lt;BR /&gt; neighbor-inactivity-timeout 30&lt;BR /&gt; meshpoint-monitor-interval 30&lt;BR /&gt; service rss-timeout 300&lt;BR /&gt; no service power-config force-3at&lt;BR /&gt; no service power-config 3af-out&lt;BR /&gt; service wireless cred-cache-sync never&lt;BR /&gt; service wireless cred-cache-sync interval 1200&lt;BR /&gt; no service wireless test min-rate&lt;BR /&gt; no service wireless test max-rate&lt;BR /&gt; service wireless test max-retries 0&lt;BR /&gt; service wireless client tx-deauth on-radar-detect&lt;BR /&gt; service radius dynamic-authorization additional-port 3799&lt;BR /&gt; service global-association-list blacklist-interval 60&lt;BR /&gt; no service wireless reconfig-on-rx-stall&lt;BR /&gt; service wireless reboot-on-rx-stall&lt;BR /&gt; service wireless noise-immunity&lt;BR /&gt; no service wireless inter-ap-key&lt;BR /&gt; no service wireless qos-map-ignore&lt;BR /&gt; otls forward 5GHz disable&lt;BR /&gt; otls forward 2.4GHz disable&lt;BR /&gt; otls server-ip 0.0.0.0&lt;BR /&gt; otls control-port 0&lt;BR /&gt; otls data-port 2.4GHz 0&lt;BR /&gt; otls data-port 5GHz 0&lt;BR /&gt; otls apid 0&lt;BR /&gt; ip name-server 8.8.8.8&lt;BR /&gt; ip default-gateway 172.16.7.1&lt;BR /&gt; ip route 172.16.6.0/24 172.16.7.1&lt;BR /&gt; autoinstall configuration&lt;BR /&gt; autoinstall firmware&lt;BR /&gt; no device-upgrade auto&lt;BR /&gt; use radius-server-policy RADIUS-SERVER-POLICY&lt;BR /&gt; crypto ikev1 policy ikev1-default &lt;BR /&gt; isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt; crypto ikev2 policy ikev2-default &lt;BR /&gt; isakmp-proposal default encryption aes-256 group 2 hash sha &lt;BR /&gt; crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt; crypto ikev1 remote-vpn&lt;BR /&gt; crypto ikev2 remote-vpn&lt;BR /&gt; crypto auto-ipsec-secure&lt;BR /&gt; crypto remote-vpn-client&lt;BR /&gt; interface up1&lt;BR /&gt; switchport mode trunk&lt;BR /&gt; switchport trunk allowed vlan 100,102&lt;BR /&gt; switchport trunk native vlan 100&lt;BR /&gt; interface ge1&lt;BR /&gt; switchport mode trunk&lt;BR /&gt; switchport trunk allowed vlan 100,102&lt;BR /&gt; switchport trunk native vlan 100&lt;BR /&gt; interface ge2&lt;BR /&gt; interface ge3&lt;BR /&gt; interface ge4&lt;BR /&gt; interface ge5&lt;BR /&gt; interface vlan100&lt;BR /&gt; description WING-MGMT&lt;BR /&gt; ip address 172.16.7.3/24&lt;BR /&gt; dhcp-relay-incoming&lt;BR /&gt; interface vlan102&lt;BR /&gt; description CLIENTS&lt;BR /&gt; ip address 192.168.2.2/24&lt;BR /&gt; interface wwan1&lt;BR /&gt; interface pppoe1&lt;BR /&gt; use management-policy MANAGEMENT-POLICY&lt;BR /&gt; use dhcp-server-policy DHCP&lt;BR /&gt; use firewall-policy FW-POLICY&lt;BR /&gt; use captive-portal server CAPTIVE-PORTAL-POLICY-GUEST&lt;BR /&gt; use client-identity-group default&lt;BR /&gt; logging on&lt;BR /&gt; logging console debugging&lt;BR /&gt; logging buffered debugging&lt;BR /&gt; logging syslog debugging&lt;BR /&gt; enforce-version adoption none&lt;BR /&gt; service pm sys-restart&lt;BR /&gt; router ospf&lt;BR /&gt; router bgp&lt;BR /&gt; no upgrade opcode auto&lt;BR /&gt; no upgrade opcode path &lt;BR /&gt; no upgrade opcode reload&lt;BR /&gt; adoption-mode controller&lt;BR /&gt;!&lt;/CODE&gt;&lt;/PRE&gt; &lt;P&gt;I can see guest user info but again it is not working as i expect nor want it with splash screen (portal login) showing far more time left then the set 15 min.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;PRE&gt;&lt;CODE&gt;show radius guest-users &lt;BR /&gt; TIME (DD:HH:MM:SS) DATA (kilobytes) BANDWIDTH (kbps) &lt;BR /&gt;GUEST USER CONFIGURED REMAINING CONFIGURED REMAINING CFGD DN CURR DN CFGD UP CURR UP&lt;BR /&gt;a 0:00:15:00 0:00:08:59 unlimited unlimited&lt;BR /&gt;Current time: 13:44:01&lt;/CODE&gt;&lt;/PRE&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Any help in this topic is greatly appreciated!&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;BR,&lt;/P&gt; &lt;P&gt;Cristian&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2019 21:24:35 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-with-radius-accounting-access-duration/m-p/69855#M6312</guid>
      <dc:creator>cristiannilsson</dc:creator>
      <dc:date>2019-12-18T21:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Wing Captive Portal with radius accounting (Access Duration)</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-with-radius-accounting-access-duration/m-p/69856#M6313</link>
      <description>&lt;P&gt;I have the same problem. Did you solve it?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 16:24:02 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-captive-portal-with-radius-accounting-access-duration/m-p/69856#M6313</guid>
      <dc:creator>a_socias</dc:creator>
      <dc:date>2021-08-05T16:24:02Z</dc:date>
    </item>
  </channel>
</rss>

