<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wing Ap410 Captive portal in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72007#M6600</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;A href="https://ext.connectedcommunity.org/profile?UserKey=4fcd813e-74ea-436e-a2c8-a52e89a58020" target="_self" rel="noreferrer"&gt;Ovais Qayyum&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #3498db"&gt;default-ap410&amp;nbsp;on the virtual controller AP.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3498db"&gt;use radius-server-policy default&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #3498db"&gt;use dhcp-server-policy default&lt;BR /&gt;use captive-portal server default-onboard&lt;BR /&gt;use captive-portal server default-onboard2&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Ok I moved this&amp;nbsp;to profile:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3498db"&gt;connection-mode https&lt;/SPAN&gt; - &amp;gt; I backed to http&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3498db"&gt;radius-group ST-Gosc &lt;/SPAN&gt;→&amp;nbsp;I&amp;nbsp;removed this radius-group and left only default.&lt;/P&gt;&lt;P&gt;At now situation look like that&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;when I connect to radio on main AP working as constroler the Captive portal is availabe and i can log by&amp;nbsp;radius and to wifi&lt;/LI&gt;	&lt;LI&gt;When I connect to radio on any other AP the web page Captive portal is not availiable&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Actual configutration&lt;/P&gt;&lt;P&gt;sh running-config&lt;BR /&gt;!&lt;BR /&gt;! Configuration of AP410 version 7.3.0.0-038R&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;version 2.7&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;client-identity-group default&lt;BR /&gt;&amp;nbsp;load default-fingerprints&lt;BR /&gt;!&lt;BR /&gt;ip access-list BROADCAST-MULTICAST-CONTROL&lt;BR /&gt;&amp;nbsp;permit tcp any any rule-precedence 10 rule-description "permit all TCP traffic"&lt;BR /&gt;&amp;nbsp;permit udp any eq 67 any eq dhcpc rule-precedence 11 rule-description "permit DHCP replies"&lt;BR /&gt;&amp;nbsp;deny udp any range 137 138 any range 137 138 rule-precedence 20 rule-description "deny windows netbios"&lt;BR /&gt;&amp;nbsp;deny ip any 224.0.0.0/4 rule-precedence 21 rule-description "deny IP multicast"&lt;BR /&gt;&amp;nbsp;deny ip any host 255.255.255.255 rule-precedence 22 rule-description "deny IP local broadcast"&lt;BR /&gt;&amp;nbsp;permit ip any any rule-precedence 100 rule-description "permit all IP traffic"&lt;BR /&gt;!&lt;BR /&gt;mac access-list PERMIT-ARP-AND-IPv4&lt;BR /&gt;&amp;nbsp;permit any any type ip rule-precedence 10 rule-description "permit all IPv4 traffic"&lt;BR /&gt;&amp;nbsp;permit any any type arp rule-precedence 20 rule-description "permit all ARP traffic"&lt;BR /&gt;!&lt;BR /&gt;ip snmp-access-list default&lt;BR /&gt;&amp;nbsp;permit any&lt;BR /&gt;!&lt;BR /&gt;firewall-policy default&lt;BR /&gt;&amp;nbsp;no ip dos tcp-sequence-past-window&lt;BR /&gt;&amp;nbsp;no stateful-packet-inspection-l2&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1400&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;mint-policy global-default&lt;BR /&gt;!&lt;BR /&gt;wlan-qos-policy default&lt;BR /&gt;&amp;nbsp;qos trust dscp&lt;BR /&gt;&amp;nbsp;qos trust wmm&lt;BR /&gt;!&lt;BR /&gt;radio-qos-policy default&lt;BR /&gt;!&lt;BR /&gt;aaa-policy default-onboard&lt;BR /&gt;&amp;nbsp;authentication server 1 onboard self&lt;BR /&gt;!&lt;BR /&gt;captive-portal default-onboard&lt;BR /&gt;&amp;nbsp;server host guest-access.net&lt;BR /&gt;&amp;nbsp;webpage internal org-name Startowa&lt;BR /&gt;&amp;nbsp;use aaa-policy default-onboard&lt;BR /&gt;&amp;nbsp;webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt;&amp;nbsp;webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt;&amp;nbsp;webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt;&amp;nbsp;webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt;&amp;nbsp;webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt;&amp;nbsp;webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt;&amp;nbsp;webpage internal registration field email type e-address enable mandatory label "Email" placeholder "you@domain.com"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;!&lt;BR /&gt;captive-portal default-onboard2&lt;BR /&gt;&amp;nbsp;server host guest-access.net&lt;BR /&gt;&amp;nbsp;webpage internal org-name Startowa&lt;BR /&gt;&amp;nbsp;webpage internal login header Witamy w sieci Startowa Gosc&lt;BR /&gt;&amp;nbsp;use aaa-policy default-onboard&lt;BR /&gt;&amp;nbsp;webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt;&amp;nbsp;webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt;&amp;nbsp;webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt;&amp;nbsp;webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt;&amp;nbsp;webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt;&amp;nbsp;webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt;&amp;nbsp;webpage internal registration field email type e-address enable mandatory label "Email" placeholder "you@domain.com"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;!&lt;BR /&gt;wlan ST-Test&lt;BR /&gt;&amp;nbsp;ssid ST-Test&lt;BR /&gt;&amp;nbsp;vlan 3&lt;BR /&gt;&amp;nbsp;bridging-mode local&lt;BR /&gt;&amp;nbsp;encryption-type none&lt;BR /&gt;&amp;nbsp;authentication-type none&lt;BR /&gt;&amp;nbsp;no multi-band-operation&lt;BR /&gt;&amp;nbsp;no protected-mgmt-frames&lt;BR /&gt;!&lt;BR /&gt;wlan wlan1&lt;BR /&gt;&amp;nbsp;ssid ST-EDU&lt;BR /&gt;&amp;nbsp;vlan 2&lt;BR /&gt;&amp;nbsp;bridging-mode local&lt;BR /&gt;&amp;nbsp;encryption-type none&lt;BR /&gt;&amp;nbsp;authentication-type none&lt;BR /&gt;&amp;nbsp;no multi-band-operation&lt;BR /&gt;&amp;nbsp;no protected-mgmt-frames&lt;BR /&gt;&amp;nbsp;use captive-portal default-onboard&lt;BR /&gt;&amp;nbsp;captive-portal-enforcement&lt;BR /&gt;!&lt;BR /&gt;wlan wlan2&lt;BR /&gt;&amp;nbsp;ssid ST-Gosc&lt;BR /&gt;&amp;nbsp;vlan 3&lt;BR /&gt;&amp;nbsp;bridging-mode local&lt;BR /&gt;&amp;nbsp;encryption-type none&lt;BR /&gt;&amp;nbsp;authentication-type none&lt;BR /&gt;&amp;nbsp;no multi-band-operation&lt;BR /&gt;&amp;nbsp;no protected-mgmt-frames&lt;BR /&gt;&amp;nbsp;use captive-portal default-onboard2&lt;BR /&gt;&amp;nbsp;captive-portal-enforcement&lt;BR /&gt;!&lt;BR /&gt;smart-rf-policy default&lt;BR /&gt;&amp;nbsp;no select-shutdown&lt;BR /&gt;&amp;nbsp;no smart-sensor&lt;BR /&gt;&amp;nbsp;smart-sensor auto-trigger&lt;BR /&gt;&amp;nbsp;smart-sensor band smart-band-5GHz&lt;BR /&gt;!&lt;BR /&gt;radius-group default&lt;BR /&gt;!&lt;BR /&gt;radius-user-pool-policy default&lt;BR /&gt;&amp;nbsp;user Gosc password 0 654321 group default&lt;BR /&gt;&amp;nbsp;user r.duszczyk password 0 123456 default&lt;BR /&gt;!&lt;BR /&gt;radius-server-policy default&lt;BR /&gt;&amp;nbsp;use radius-user-pool-policy default&lt;BR /&gt;!&lt;BR /&gt;dhcp-server-policy default&lt;BR /&gt;&amp;nbsp;dhcp-pool DHCP-EDU-Vlan2&lt;BR /&gt;&amp;nbsp; network 10.10.10.0/24&lt;BR /&gt;&amp;nbsp; address range 10.10.10.20 10.10.10.200&lt;BR /&gt;&amp;nbsp; default-router 10.10.10.11&lt;BR /&gt;&amp;nbsp; dns-server &amp;nbsp;10.10.10.11&lt;BR /&gt;&amp;nbsp;dhcp-pool DCHP-Gosc-Vlan3&lt;BR /&gt;&amp;nbsp; network 10.10.11.0/24&lt;BR /&gt;&amp;nbsp; address range 10.10.11.20 10.10.11.200&lt;BR /&gt;&amp;nbsp; lease 0 1&lt;BR /&gt;&amp;nbsp; default-router 10.10.11.11&lt;BR /&gt;&amp;nbsp; dns-server &amp;nbsp;10.10.11.11&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;management-policy default&lt;BR /&gt;&amp;nbsp;telnet&lt;BR /&gt;&amp;nbsp;no http server&lt;BR /&gt;&amp;nbsp;https server&lt;BR /&gt;&amp;nbsp;rest-server&lt;BR /&gt;&amp;nbsp;ssh&lt;BR /&gt;&amp;nbsp;user admin password 1 bffa8-----------------------------------7199 role superuser access all&lt;BR /&gt;&amp;nbsp;snmp-server community 0 private rw&lt;BR /&gt;&amp;nbsp;snmp-server community 0 public ro&lt;BR /&gt;&amp;nbsp;snmp-server user snmptrap v3 encrypted des auth md5 0 admin123&lt;BR /&gt;&amp;nbsp;snmp-server user snmpmanager v3 encrypted des auth md5 0 admin123&lt;BR /&gt;!&lt;BR /&gt;event-system-policy default&lt;BR /&gt;!&lt;BR /&gt;profile ap410 default-ap410&lt;BR /&gt;&amp;nbsp;ip name-server 8.8.8.8&lt;BR /&gt;&amp;nbsp;ip name-server 8.8.4.4&lt;BR /&gt;&amp;nbsp;ip default-gateway 192.168.1.254&lt;BR /&gt;&amp;nbsp;autoinstall configuration&lt;BR /&gt;&amp;nbsp;autoinstall firmware&lt;BR /&gt;&amp;nbsp;use radius-server-policy default&lt;BR /&gt;&amp;nbsp;crypto ikev1 policy ikev1-default&lt;BR /&gt;&amp;nbsp; isakmp-proposal default encryption aes-256 group 2 hash sha&lt;BR /&gt;&amp;nbsp;crypto ikev2 policy ikev2-default&lt;BR /&gt;&amp;nbsp; isakmp-proposal default encryption aes-256 group 2 hash sha&lt;BR /&gt;&amp;nbsp;crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;&amp;nbsp;crypto ikev1 remote-vpn&lt;BR /&gt;&amp;nbsp;crypto ikev2 remote-vpn&lt;BR /&gt;&amp;nbsp;crypto auto-ipsec-secure&lt;BR /&gt;&amp;nbsp;crypto load-management&lt;BR /&gt;&amp;nbsp;crypto remote-vpn-client&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; wlan wlan1 bss 2 primary&lt;BR /&gt;&amp;nbsp; wlan wlan2 bss 3 primary&lt;BR /&gt;&amp;nbsp; antenna-mode 2x2&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; wlan wlan1 bss 1 primary&lt;BR /&gt;&amp;nbsp; wlan wlan2 bss 2 primary&lt;BR /&gt;&amp;nbsp; antenna-mode 2x2&lt;BR /&gt;&amp;nbsp;interface radio3&lt;BR /&gt;&amp;nbsp;interface bluetooth1&lt;BR /&gt;&amp;nbsp; shutdown&lt;BR /&gt;&amp;nbsp; mode le-sensor&lt;BR /&gt;&amp;nbsp;interface ge1&lt;BR /&gt;&amp;nbsp; switchport mode trunk&lt;BR /&gt;&amp;nbsp; switchport trunk allowed vlan 1-3&lt;BR /&gt;&amp;nbsp;interface ge2&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; ip address dhcp&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp; ip dhcp client request options all&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; description "Cap ST-EDU"&lt;BR /&gt;&amp;nbsp; ip nat inside&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; description "Cap ST-Gosc"&lt;BR /&gt;&amp;nbsp; ip nat inside&lt;BR /&gt;&amp;nbsp;use dhcp-server-policy default&lt;BR /&gt;&amp;nbsp;use firewall-policy default&lt;BR /&gt;&amp;nbsp;use captive-portal server default-onboard&lt;BR /&gt;&amp;nbsp;use captive-portal server default-onboard2&lt;BR /&gt;&amp;nbsp;use client-identity-group default&lt;BR /&gt;&amp;nbsp;logging on&lt;BR /&gt;&amp;nbsp;ip nat inside source list BROADCAST-MULTICAST-CONTROL precedence 1 interface vlan1 overload&lt;BR /&gt;&amp;nbsp;service pm sys-restart&lt;BR /&gt;&amp;nbsp;router ospf&lt;BR /&gt;&amp;nbsp;adoption-mode controller&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;rf-domain default&lt;BR /&gt;&amp;nbsp;location Hol&lt;BR /&gt;&amp;nbsp;contact raddus@wp.pl&lt;BR /&gt;&amp;nbsp;timezone Etc/GMT+1&lt;BR /&gt;&amp;nbsp;country-code pl&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;ap410 AA-AA-AA-AA-AA-AA&lt;BR /&gt;&amp;nbsp;use profile default-ap410&lt;BR /&gt;&amp;nbsp;use rf-domain default&lt;BR /&gt;&amp;nbsp;hostname ST-AP01&lt;BR /&gt;&amp;nbsp;area Wysoki&lt;BR /&gt;&amp;nbsp;floor Ip&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.12/24&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.12/24&lt;BR /&gt;&amp;nbsp; no ip nat&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; ip address 10.10.11.12/24&lt;BR /&gt;&amp;nbsp;ip dns-server-forward&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;ap410 BB-BB-BB-BB-BB-BB&lt;BR /&gt;&amp;nbsp;use profile default-ap410&lt;BR /&gt;&amp;nbsp;use rf-domain default&lt;BR /&gt;&amp;nbsp;hostname ST-AP01&lt;BR /&gt;&amp;nbsp;area Wysoki&lt;BR /&gt;&amp;nbsp;floor Ip&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.12/24&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.12/24&lt;BR /&gt;&amp;nbsp; no ip nat&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; ip address 10.10.11.12/24&lt;BR /&gt;&amp;nbsp;ip dns-server-forward&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;ap410 CC-CC-CC-CC-CC-CC&lt;BR /&gt;&amp;nbsp;use profile default-ap410&lt;BR /&gt;&amp;nbsp;use rf-domain default&lt;BR /&gt;&amp;nbsp;hostname ST-CON0&lt;BR /&gt;&amp;nbsp;area Aula&lt;BR /&gt;&amp;nbsp;floor Parter&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; description "Virtual Interface for LAN by Wizard"&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.11/24&lt;BR /&gt;&amp;nbsp; no ip dhcp client request options all&lt;BR /&gt;&amp;nbsp; no ip nat&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.11/24&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; ip address 10.10.11.11/24&lt;BR /&gt;&amp;nbsp;virtual-controller&lt;BR /&gt;&amp;nbsp;rf-domain-manager capable&lt;BR /&gt;&amp;nbsp;ip dns-server-forward&lt;BR /&gt;&amp;nbsp;no adoption-mode&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;&amp;nbsp;end&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Nov 2020 05:15:25 GMT</pubDate>
    <dc:creator>Radoslaw</dc:creator>
    <dc:date>2020-11-25T05:15:25Z</dc:date>
    <item>
      <title>Wing Ap410 Captive portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72005#M6598</link>
      <description>&lt;P&gt;&amp;nbsp;Hi,&lt;/P&gt;&lt;P&gt;I want to implement two Wifi with captive portal on three AP410. On one AP410 i got working everything ok, this AP is work as controller. DHCP, Captive Portal, Radius. But on other two AP only work DHCP, but&amp;nbsp;i can’t connect with webpage to authorization.&lt;/P&gt;&lt;P&gt;Can you tell me what i miss? Any sugestion?&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="f9d5200fd58542888d56b0bcc3bb0444_69bcdb37-2bf2-42f7-bbfc-59cc5d309c48.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5108i0860FAE5B7B7A0D9/image-size/large?v=v2&amp;amp;px=999" role="button" title="f9d5200fd58542888d56b0bcc3bb0444_69bcdb37-2bf2-42f7-bbfc-59cc5d309c48.png" alt="f9d5200fd58542888d56b0bcc3bb0444_69bcdb37-2bf2-42f7-bbfc-59cc5d309c48.png" /&gt;&lt;/span&gt;&lt;FIGCAPTION&gt;Conception draft&lt;/FIGCAPTION&gt;&lt;/FIGURE&gt;&lt;P&gt;My configuration:&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;! Configuration of AP410 version 7.3.0.0-038R&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;version 2.7&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;client-identity-group default&lt;BR /&gt;&amp;nbsp;load default-fingerprints&lt;BR /&gt;!&lt;BR /&gt;ip access-list BROADCAST-MULTICAST-CONTROL&lt;BR /&gt;&amp;nbsp;permit tcp any any rule-precedence 10 rule-description "permit all TCP traffic"&lt;BR /&gt;&amp;nbsp;permit udp any eq 67 any eq dhcpc rule-precedence 11 rule-description "permit DHCP replies"&lt;BR /&gt;&amp;nbsp;deny udp any range 137 138 any range 137 138 rule-precedence 20 rule-description "deny windows netbios"&lt;BR /&gt;&amp;nbsp;deny ip any 224.0.0.0/4 rule-precedence 21 rule-description "deny IP multicast"&lt;BR /&gt;&amp;nbsp;deny ip any host 255.255.255.255 rule-precedence 22 rule-description "deny IP local broadcast"&lt;BR /&gt;&amp;nbsp;permit ip any any rule-precedence 100 rule-description "permit all IP traffic"&lt;BR /&gt;!&lt;BR /&gt;mac access-list PERMIT-ARP-AND-IPv4&lt;BR /&gt;&amp;nbsp;permit any any type ip rule-precedence 10 rule-description "permit all IPv4 traffic"&lt;BR /&gt;&amp;nbsp;permit any any type arp rule-precedence 20 rule-description "permit all ARP traffic"&lt;BR /&gt;!&lt;BR /&gt;ip snmp-access-list default&lt;BR /&gt;&amp;nbsp;permit any&lt;BR /&gt;!&lt;BR /&gt;firewall-policy default&lt;BR /&gt;&amp;nbsp;no ip dos tcp-sequence-past-window&lt;BR /&gt;&amp;nbsp;no stateful-packet-inspection-l2&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1400&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;mint-policy global-default&lt;BR /&gt;!&lt;BR /&gt;wlan-qos-policy default&lt;BR /&gt;&amp;nbsp;qos trust dscp&lt;BR /&gt;&amp;nbsp;qos trust wmm&lt;BR /&gt;!&lt;BR /&gt;radio-qos-policy default&lt;BR /&gt;!&lt;BR /&gt;aaa-policy default-onboard&lt;BR /&gt;&amp;nbsp;authentication server 1 onboard self&lt;BR /&gt;!&lt;BR /&gt;captive-portal default-onboard&lt;BR /&gt;&amp;nbsp;server host guest-access.net&lt;BR /&gt;&amp;nbsp;webpage internal org-name Startowa&lt;BR /&gt;&amp;nbsp;use aaa-policy default-onboard&lt;BR /&gt;&amp;nbsp;webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt;&amp;nbsp;webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt;&amp;nbsp;webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt;&amp;nbsp;webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt;&amp;nbsp;webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt;&amp;nbsp;webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt;&amp;nbsp;webpage internal registration field email type e-address enable mandatory label "Email" placeholder "you@domain.com"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;!&lt;BR /&gt;captive-portal default-onboard2&lt;BR /&gt;&amp;nbsp;connection-mode https&lt;BR /&gt;&amp;nbsp;server host guest-access.net&lt;BR /&gt;&amp;nbsp;webpage internal org-name Startowa&lt;BR /&gt;&amp;nbsp;webpage internal login description Proszę wpisać Login i Hasło&lt;BR /&gt;&amp;nbsp;webpage internal login header Witamy w sieci Startowa Gosc&lt;BR /&gt;&amp;nbsp;use aaa-policy default-onboard&lt;BR /&gt;&amp;nbsp;webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt;&amp;nbsp;webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt;&amp;nbsp;webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt;&amp;nbsp;webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt;&amp;nbsp;webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt;&amp;nbsp;webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt;&amp;nbsp;webpage internal registration field email type e-address enable mandatory label "Email" placeholder "you@domain.com"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;!&lt;BR /&gt;wlan wlan1&lt;BR /&gt;&amp;nbsp;ssid ST-EDU&lt;BR /&gt;&amp;nbsp;vlan 2&lt;BR /&gt;&amp;nbsp;bridging-mode local&lt;BR /&gt;&amp;nbsp;encryption-type none&lt;BR /&gt;&amp;nbsp;authentication-type none&lt;BR /&gt;&amp;nbsp;no multi-band-operation&lt;BR /&gt;&amp;nbsp;no protected-mgmt-frames&lt;BR /&gt;&amp;nbsp;use captive-portal default-onboard&lt;BR /&gt;&amp;nbsp;captive-portal-enforcement&lt;BR /&gt;!&lt;BR /&gt;wlan wlan2&lt;BR /&gt;&amp;nbsp;ssid ST-Gosc&lt;BR /&gt;&amp;nbsp;vlan 3&lt;BR /&gt;&amp;nbsp;bridging-mode local&lt;BR /&gt;&amp;nbsp;encryption-type none&lt;BR /&gt;&amp;nbsp;authentication-type none&lt;BR /&gt;&amp;nbsp;no multi-band-operation&lt;BR /&gt;&amp;nbsp;no protected-mgmt-frames&lt;BR /&gt;&amp;nbsp;use captive-portal default-onboard2&lt;BR /&gt;&amp;nbsp;captive-portal-enforcement&lt;BR /&gt;!&lt;BR /&gt;smart-rf-policy default&lt;BR /&gt;&amp;nbsp;no select-shutdown&lt;BR /&gt;&amp;nbsp;no smart-sensor&lt;BR /&gt;&amp;nbsp;smart-sensor auto-trigger&lt;BR /&gt;&amp;nbsp;smart-sensor band smart-band-5GHz&lt;BR /&gt;!&lt;BR /&gt;radius-group ST-Gosc&lt;BR /&gt;&amp;nbsp;guest&lt;BR /&gt;&amp;nbsp;policy vlan 3&lt;BR /&gt;&amp;nbsp;policy ssid ST-Gosc&lt;BR /&gt;&amp;nbsp;rate-limit from-air 100000&lt;BR /&gt;&amp;nbsp;rate-limit to-air 100000&lt;BR /&gt;!&lt;BR /&gt;radius-group default&lt;BR /&gt;!&lt;BR /&gt;radius-user-pool-policy default&lt;BR /&gt;&amp;nbsp;user Gosc password 0 654321 group default&lt;BR /&gt;&amp;nbsp;user r.duszczyk password 0 123456 group default&lt;BR /&gt;!&lt;BR /&gt;radius-server-policy default&lt;BR /&gt;&amp;nbsp;use radius-user-pool-policy default&lt;BR /&gt;!&lt;BR /&gt;dhcp-server-policy default&lt;BR /&gt;&amp;nbsp;dhcp-pool DHCP-EDU-Vlan2&lt;BR /&gt;&amp;nbsp; network 10.10.10.0/24&lt;BR /&gt;&amp;nbsp; address range 10.10.10.20 10.10.10.200&lt;BR /&gt;&amp;nbsp; default-router 10.10.10.11&lt;BR /&gt;&amp;nbsp; dns-server &amp;nbsp;10.10.10.11&lt;BR /&gt;&amp;nbsp;dhcp-pool DCHP-Gosc-Vlan3&lt;BR /&gt;&amp;nbsp; network 10.10.11.0/24&lt;BR /&gt;&amp;nbsp; address range 10.10.11.20 10.10.11.200&lt;BR /&gt;&amp;nbsp; lease 0 1&lt;BR /&gt;&amp;nbsp; default-router 10.10.11.11&lt;BR /&gt;&amp;nbsp; dns-server &amp;nbsp;10.10.11.11&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;management-policy default&lt;BR /&gt;&amp;nbsp;telnet&lt;BR /&gt;&amp;nbsp;no http server&lt;BR /&gt;&amp;nbsp;https server&lt;BR /&gt;&amp;nbsp;rest-server&lt;BR /&gt;&amp;nbsp;ssh&lt;BR /&gt;&amp;nbsp;user admin password 1 bffa8-----------------------------------7199 role superuser access all&lt;BR /&gt;&amp;nbsp;snmp-server community 0 private rw&lt;BR /&gt;&amp;nbsp;snmp-server community 0 public ro&lt;BR /&gt;&amp;nbsp;snmp-server user snmptrap v3 encrypted des auth md5 0 admin123&lt;BR /&gt;&amp;nbsp;snmp-server user snmpmanager v3 encrypted des auth md5 0 admin123&lt;BR /&gt;!&lt;BR /&gt;event-system-policy default&lt;BR /&gt;!&lt;BR /&gt;profile ap410 default-ap410&lt;BR /&gt;&amp;nbsp;ip name-server 8.8.8.8&lt;BR /&gt;&amp;nbsp;ip name-server 8.8.4.4&lt;BR /&gt;&amp;nbsp;ip default-gateway 192.168.1.254&lt;BR /&gt;&amp;nbsp;autoinstall configuration&lt;BR /&gt;&amp;nbsp;autoinstall firmware&lt;BR /&gt;&amp;nbsp;crypto ikev1 policy ikev1-default&lt;BR /&gt;&amp;nbsp; isakmp-proposal default encryption aes-256 group 2 hash sha&lt;BR /&gt;&amp;nbsp;crypto ikev2 policy ikev2-default&lt;BR /&gt;&amp;nbsp; isakmp-proposal default encryption aes-256 group 2 hash sha&lt;BR /&gt;&amp;nbsp;crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;&amp;nbsp;crypto ikev1 remote-vpn&lt;BR /&gt;&amp;nbsp;crypto ikev2 remote-vpn&lt;BR /&gt;&amp;nbsp;crypto auto-ipsec-secure&lt;BR /&gt;&amp;nbsp;crypto load-management&lt;BR /&gt;&amp;nbsp;crypto remote-vpn-client&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; wlan wlan1 bss 2 primary&lt;BR /&gt;&amp;nbsp; wlan wlan2 bss 3 primary&lt;BR /&gt;&amp;nbsp; antenna-mode 2x2&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; wlan wlan1 bss 1 primary&lt;BR /&gt;&amp;nbsp; wlan wlan2 bss 2 primary&lt;BR /&gt;&amp;nbsp; antenna-mode 2x2&lt;BR /&gt;&amp;nbsp;interface radio3&lt;BR /&gt;&amp;nbsp;interface bluetooth1&lt;BR /&gt;&amp;nbsp; shutdown&lt;BR /&gt;&amp;nbsp; mode le-sensor&lt;BR /&gt;&amp;nbsp;interface ge1&lt;BR /&gt;&amp;nbsp; switchport mode trunk&lt;BR /&gt;&amp;nbsp; switchport trunk allowed vlan 1-3&lt;BR /&gt;&amp;nbsp;interface ge2&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; ip address dhcp&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp; ip dhcp client request options all&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; description "Cap ST-EDU"&lt;BR /&gt;&amp;nbsp; ip nat inside&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; description "Cap ST-Gosc"&lt;BR /&gt;&amp;nbsp; ip nat inside&lt;BR /&gt;&amp;nbsp;use firewall-policy default&lt;BR /&gt;&amp;nbsp;use client-identity-group default&lt;BR /&gt;&amp;nbsp;logging on&lt;BR /&gt;&amp;nbsp;ip nat inside source list BROADCAST-MULTICAST-CONTROL precedence 1 interface vlan1 overload&lt;BR /&gt;&amp;nbsp;service pm sys-restart&lt;BR /&gt;&amp;nbsp;router ospf&lt;BR /&gt;&amp;nbsp;adoption-mode controller&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;rf-domain default&lt;BR /&gt;&amp;nbsp;location Hol&lt;BR /&gt;&amp;nbsp;contact mail@wp.pl&lt;BR /&gt;&amp;nbsp;timezone Etc/GMT+1&lt;BR /&gt;&amp;nbsp;country-code pl&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;&amp;nbsp;ap410 AA-AA-AA-AA-AA-AA&lt;BR /&gt;&amp;nbsp;use profile default-ap410&lt;BR /&gt;&amp;nbsp;use rf-domain default&lt;BR /&gt;&amp;nbsp;hostname ST-AP01&lt;BR /&gt;&amp;nbsp;area 2C&lt;BR /&gt;&amp;nbsp;floor Ip&lt;BR /&gt;&amp;nbsp;use radius-server-policy default&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; shutdown&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; shutdown&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.13/24&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.13/24&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; ip address 10.10.11.13/24&lt;BR /&gt;&amp;nbsp;use dhcp-server-policy default&lt;BR /&gt;&amp;nbsp;use captive-portal server default-onboard&lt;BR /&gt;&amp;nbsp;use captive-portal server default-onboard2&lt;BR /&gt;&amp;nbsp;ip dns-server-forward&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;ap410 BB-BB-BB-BB-BB-BB&lt;BR /&gt;&amp;nbsp;use profile default-ap410&lt;BR /&gt;&amp;nbsp;use rf-domain default&lt;BR /&gt;&amp;nbsp;hostname ST-AP01&lt;BR /&gt;&amp;nbsp;area Wysoki&lt;BR /&gt;&amp;nbsp;floor Ip&lt;BR /&gt;&amp;nbsp;use radius-server-policy default&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; shutdown&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; shutdown&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.12/24&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.12/24&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; ip address 10.10.11.12/24&lt;BR /&gt;&amp;nbsp;use dhcp-server-policy default&lt;BR /&gt;&amp;nbsp;use captive-portal server default-onboard&lt;BR /&gt;&amp;nbsp;use captive-portal server default-onboard2&lt;BR /&gt;&amp;nbsp;ip dns-server-forward&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;ap410 CC-CC-CC-CC-CC-CC&lt;BR /&gt;&amp;nbsp;use profile default-ap410&lt;BR /&gt;&amp;nbsp;use rf-domain default&lt;BR /&gt;&amp;nbsp;hostname ST-CON0&lt;BR /&gt;&amp;nbsp;area Aula&lt;BR /&gt;&amp;nbsp;floor Parter&lt;BR /&gt;&amp;nbsp;use radius-server-policy default&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; description "Virtual Interface for LAN by Wizard"&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.11/24&lt;BR /&gt;&amp;nbsp; no ip dhcp client request options all&lt;BR /&gt;&amp;nbsp; no ip nat&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.11/24&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; ip address 10.10.11.11/24&lt;BR /&gt;&amp;nbsp;use dhcp-server-policy default&lt;BR /&gt;&amp;nbsp;use captive-portal server default-onboard&lt;BR /&gt;&amp;nbsp;use captive-portal server default-onboard2&lt;BR /&gt;&amp;nbsp;virtual-controller&lt;BR /&gt;&amp;nbsp;rf-domain-manager capable&lt;BR /&gt;&amp;nbsp;ip dns-server-forward&lt;BR /&gt;&amp;nbsp;no adoption-mode&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;&amp;nbsp;end&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 16:46:49 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72005#M6598</guid>
      <dc:creator>Radoslaw</dc:creator>
      <dc:date>2020-11-23T16:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Wing Ap410 Captive portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72006#M6599</link>
      <description>&lt;P&gt;Hi Radoslaw,&lt;/P&gt;&lt;P&gt;Do you even see the splash page when you connect to the other two APs? or you see the page but authentication fails?&lt;/P&gt;&lt;P&gt;I would recommend you to use the profile based configuration on the virtual controller AP to make things easier for you to configure and troubleshoot. I see that you have the following&amp;nbsp;4&amp;nbsp;parameters configured as overrides on every AP; remove these&amp;nbsp;overrides and move them to the &lt;SPAN style="color:#8e44ad;"&gt;profile ap410 default-ap410&lt;/SPAN&gt; on the virtual controller AP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#8e44ad;"&gt;use radius-server-policy default&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#8e44ad;"&gt;use dhcp-server-policy default&lt;BR /&gt;use captive-portal server default-onboard&lt;BR /&gt;use captive-portal server default-onboard2&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You also need to make&amp;nbsp;the following configuration changes:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#8e44ad;"&gt;connection-mode https&amp;nbsp; &lt;/SPAN&gt;→&amp;nbsp;do you have a captive portal certificate loaded on the AP trust point? if not, use the default HTTP connection mode to avoid HTTPS cert error every time you connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#8e44ad;"&gt;radius-group ST-Gosc&lt;BR /&gt;&amp;nbsp;guest&lt;BR /&gt;&amp;nbsp;policy vlan 3&lt;/SPAN&gt; →&amp;nbsp;you can remove the VLAN definition&lt;BR /&gt;&lt;SPAN style="color:#8e44ad;"&gt;&amp;nbsp;policy ssid ST-Gosc &lt;/SPAN&gt;→&amp;nbsp;add your&amp;nbsp;ssid ST-EDU&amp;nbsp;here in the list as well&lt;BR /&gt;&lt;SPAN style="color:#8e44ad;"&gt;&amp;nbsp;rate-limit from-air 100000&lt;BR /&gt;&amp;nbsp;rate-limit to-air 100000&lt;BR /&gt;!&lt;BR /&gt;radius-user-pool-policy default&lt;BR /&gt;&amp;nbsp;user Gosc password 0 654321 &lt;/SPAN&gt;&lt;SPAN style="color:#e74c3c;"&gt;group default &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color:#8e44ad;"&gt;&amp;nbsp;user r.duszczyk password 0 123456 &lt;/SPAN&gt;&lt;SPAN style="color:#e74c3c;"&gt;group default&amp;nbsp;&lt;/SPAN&gt;→&amp;nbsp;both of these users are created under the default user group whereas your SSIDs are defined under ST-Gosc group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know how it goes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ovais&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 11:10:40 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72006#M6599</guid>
      <dc:creator>Ovais_Qayyum</dc:creator>
      <dc:date>2020-11-24T11:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Wing Ap410 Captive portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72007#M6600</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;A href="https://ext.connectedcommunity.org/profile?UserKey=4fcd813e-74ea-436e-a2c8-a52e89a58020" target="_self" rel="noreferrer"&gt;Ovais Qayyum&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #3498db"&gt;default-ap410&amp;nbsp;on the virtual controller AP.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3498db"&gt;use radius-server-policy default&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #3498db"&gt;use dhcp-server-policy default&lt;BR /&gt;use captive-portal server default-onboard&lt;BR /&gt;use captive-portal server default-onboard2&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Ok I moved this&amp;nbsp;to profile:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3498db"&gt;connection-mode https&lt;/SPAN&gt; - &amp;gt; I backed to http&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3498db"&gt;radius-group ST-Gosc &lt;/SPAN&gt;→&amp;nbsp;I&amp;nbsp;removed this radius-group and left only default.&lt;/P&gt;&lt;P&gt;At now situation look like that&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;when I connect to radio on main AP working as constroler the Captive portal is availabe and i can log by&amp;nbsp;radius and to wifi&lt;/LI&gt;	&lt;LI&gt;When I connect to radio on any other AP the web page Captive portal is not availiable&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Actual configutration&lt;/P&gt;&lt;P&gt;sh running-config&lt;BR /&gt;!&lt;BR /&gt;! Configuration of AP410 version 7.3.0.0-038R&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;version 2.7&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;client-identity-group default&lt;BR /&gt;&amp;nbsp;load default-fingerprints&lt;BR /&gt;!&lt;BR /&gt;ip access-list BROADCAST-MULTICAST-CONTROL&lt;BR /&gt;&amp;nbsp;permit tcp any any rule-precedence 10 rule-description "permit all TCP traffic"&lt;BR /&gt;&amp;nbsp;permit udp any eq 67 any eq dhcpc rule-precedence 11 rule-description "permit DHCP replies"&lt;BR /&gt;&amp;nbsp;deny udp any range 137 138 any range 137 138 rule-precedence 20 rule-description "deny windows netbios"&lt;BR /&gt;&amp;nbsp;deny ip any 224.0.0.0/4 rule-precedence 21 rule-description "deny IP multicast"&lt;BR /&gt;&amp;nbsp;deny ip any host 255.255.255.255 rule-precedence 22 rule-description "deny IP local broadcast"&lt;BR /&gt;&amp;nbsp;permit ip any any rule-precedence 100 rule-description "permit all IP traffic"&lt;BR /&gt;!&lt;BR /&gt;mac access-list PERMIT-ARP-AND-IPv4&lt;BR /&gt;&amp;nbsp;permit any any type ip rule-precedence 10 rule-description "permit all IPv4 traffic"&lt;BR /&gt;&amp;nbsp;permit any any type arp rule-precedence 20 rule-description "permit all ARP traffic"&lt;BR /&gt;!&lt;BR /&gt;ip snmp-access-list default&lt;BR /&gt;&amp;nbsp;permit any&lt;BR /&gt;!&lt;BR /&gt;firewall-policy default&lt;BR /&gt;&amp;nbsp;no ip dos tcp-sequence-past-window&lt;BR /&gt;&amp;nbsp;no stateful-packet-inspection-l2&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1400&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;mint-policy global-default&lt;BR /&gt;!&lt;BR /&gt;wlan-qos-policy default&lt;BR /&gt;&amp;nbsp;qos trust dscp&lt;BR /&gt;&amp;nbsp;qos trust wmm&lt;BR /&gt;!&lt;BR /&gt;radio-qos-policy default&lt;BR /&gt;!&lt;BR /&gt;aaa-policy default-onboard&lt;BR /&gt;&amp;nbsp;authentication server 1 onboard self&lt;BR /&gt;!&lt;BR /&gt;captive-portal default-onboard&lt;BR /&gt;&amp;nbsp;server host guest-access.net&lt;BR /&gt;&amp;nbsp;webpage internal org-name Startowa&lt;BR /&gt;&amp;nbsp;use aaa-policy default-onboard&lt;BR /&gt;&amp;nbsp;webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt;&amp;nbsp;webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt;&amp;nbsp;webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt;&amp;nbsp;webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt;&amp;nbsp;webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt;&amp;nbsp;webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt;&amp;nbsp;webpage internal registration field email type e-address enable mandatory label "Email" placeholder "you@domain.com"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;!&lt;BR /&gt;captive-portal default-onboard2&lt;BR /&gt;&amp;nbsp;server host guest-access.net&lt;BR /&gt;&amp;nbsp;webpage internal org-name Startowa&lt;BR /&gt;&amp;nbsp;webpage internal login header Witamy w sieci Startowa Gosc&lt;BR /&gt;&amp;nbsp;use aaa-policy default-onboard&lt;BR /&gt;&amp;nbsp;webpage internal registration field city type text enable label "City" placeholder "Enter City"&lt;BR /&gt;&amp;nbsp;webpage internal registration field street type text enable label "Address" placeholder "123 Any Street"&lt;BR /&gt;&amp;nbsp;webpage internal registration field name type text enable label "Full Name" placeholder "Enter First Name, Last Name"&lt;BR /&gt;&amp;nbsp;webpage internal registration field zip type number enable label "Zip" placeholder "Zip"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-sms type checkbox enable title "SMS Preferred"&lt;BR /&gt;&amp;nbsp;webpage internal registration field mobile type number enable label "Mobile" placeholder "Mobile Number with Country code"&lt;BR /&gt;&amp;nbsp;webpage internal registration field age-range type dropdown-menu enable label "Age Range" title "Age Range"&lt;BR /&gt;&amp;nbsp;webpage internal registration field email type e-address enable mandatory label "Email" placeholder "you@domain.com"&lt;BR /&gt;&amp;nbsp;webpage internal registration field via-email type checkbox enable title "Email Preferred"&lt;BR /&gt;!&lt;BR /&gt;wlan ST-Test&lt;BR /&gt;&amp;nbsp;ssid ST-Test&lt;BR /&gt;&amp;nbsp;vlan 3&lt;BR /&gt;&amp;nbsp;bridging-mode local&lt;BR /&gt;&amp;nbsp;encryption-type none&lt;BR /&gt;&amp;nbsp;authentication-type none&lt;BR /&gt;&amp;nbsp;no multi-band-operation&lt;BR /&gt;&amp;nbsp;no protected-mgmt-frames&lt;BR /&gt;!&lt;BR /&gt;wlan wlan1&lt;BR /&gt;&amp;nbsp;ssid ST-EDU&lt;BR /&gt;&amp;nbsp;vlan 2&lt;BR /&gt;&amp;nbsp;bridging-mode local&lt;BR /&gt;&amp;nbsp;encryption-type none&lt;BR /&gt;&amp;nbsp;authentication-type none&lt;BR /&gt;&amp;nbsp;no multi-band-operation&lt;BR /&gt;&amp;nbsp;no protected-mgmt-frames&lt;BR /&gt;&amp;nbsp;use captive-portal default-onboard&lt;BR /&gt;&amp;nbsp;captive-portal-enforcement&lt;BR /&gt;!&lt;BR /&gt;wlan wlan2&lt;BR /&gt;&amp;nbsp;ssid ST-Gosc&lt;BR /&gt;&amp;nbsp;vlan 3&lt;BR /&gt;&amp;nbsp;bridging-mode local&lt;BR /&gt;&amp;nbsp;encryption-type none&lt;BR /&gt;&amp;nbsp;authentication-type none&lt;BR /&gt;&amp;nbsp;no multi-band-operation&lt;BR /&gt;&amp;nbsp;no protected-mgmt-frames&lt;BR /&gt;&amp;nbsp;use captive-portal default-onboard2&lt;BR /&gt;&amp;nbsp;captive-portal-enforcement&lt;BR /&gt;!&lt;BR /&gt;smart-rf-policy default&lt;BR /&gt;&amp;nbsp;no select-shutdown&lt;BR /&gt;&amp;nbsp;no smart-sensor&lt;BR /&gt;&amp;nbsp;smart-sensor auto-trigger&lt;BR /&gt;&amp;nbsp;smart-sensor band smart-band-5GHz&lt;BR /&gt;!&lt;BR /&gt;radius-group default&lt;BR /&gt;!&lt;BR /&gt;radius-user-pool-policy default&lt;BR /&gt;&amp;nbsp;user Gosc password 0 654321 group default&lt;BR /&gt;&amp;nbsp;user r.duszczyk password 0 123456 default&lt;BR /&gt;!&lt;BR /&gt;radius-server-policy default&lt;BR /&gt;&amp;nbsp;use radius-user-pool-policy default&lt;BR /&gt;!&lt;BR /&gt;dhcp-server-policy default&lt;BR /&gt;&amp;nbsp;dhcp-pool DHCP-EDU-Vlan2&lt;BR /&gt;&amp;nbsp; network 10.10.10.0/24&lt;BR /&gt;&amp;nbsp; address range 10.10.10.20 10.10.10.200&lt;BR /&gt;&amp;nbsp; default-router 10.10.10.11&lt;BR /&gt;&amp;nbsp; dns-server &amp;nbsp;10.10.10.11&lt;BR /&gt;&amp;nbsp;dhcp-pool DCHP-Gosc-Vlan3&lt;BR /&gt;&amp;nbsp; network 10.10.11.0/24&lt;BR /&gt;&amp;nbsp; address range 10.10.11.20 10.10.11.200&lt;BR /&gt;&amp;nbsp; lease 0 1&lt;BR /&gt;&amp;nbsp; default-router 10.10.11.11&lt;BR /&gt;&amp;nbsp; dns-server &amp;nbsp;10.10.11.11&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;management-policy default&lt;BR /&gt;&amp;nbsp;telnet&lt;BR /&gt;&amp;nbsp;no http server&lt;BR /&gt;&amp;nbsp;https server&lt;BR /&gt;&amp;nbsp;rest-server&lt;BR /&gt;&amp;nbsp;ssh&lt;BR /&gt;&amp;nbsp;user admin password 1 bffa8-----------------------------------7199 role superuser access all&lt;BR /&gt;&amp;nbsp;snmp-server community 0 private rw&lt;BR /&gt;&amp;nbsp;snmp-server community 0 public ro&lt;BR /&gt;&amp;nbsp;snmp-server user snmptrap v3 encrypted des auth md5 0 admin123&lt;BR /&gt;&amp;nbsp;snmp-server user snmpmanager v3 encrypted des auth md5 0 admin123&lt;BR /&gt;!&lt;BR /&gt;event-system-policy default&lt;BR /&gt;!&lt;BR /&gt;profile ap410 default-ap410&lt;BR /&gt;&amp;nbsp;ip name-server 8.8.8.8&lt;BR /&gt;&amp;nbsp;ip name-server 8.8.4.4&lt;BR /&gt;&amp;nbsp;ip default-gateway 192.168.1.254&lt;BR /&gt;&amp;nbsp;autoinstall configuration&lt;BR /&gt;&amp;nbsp;autoinstall firmware&lt;BR /&gt;&amp;nbsp;use radius-server-policy default&lt;BR /&gt;&amp;nbsp;crypto ikev1 policy ikev1-default&lt;BR /&gt;&amp;nbsp; isakmp-proposal default encryption aes-256 group 2 hash sha&lt;BR /&gt;&amp;nbsp;crypto ikev2 policy ikev2-default&lt;BR /&gt;&amp;nbsp; isakmp-proposal default encryption aes-256 group 2 hash sha&lt;BR /&gt;&amp;nbsp;crypto ipsec transform-set default esp-aes-256 esp-sha-hmac&lt;BR /&gt;&amp;nbsp;crypto ikev1 remote-vpn&lt;BR /&gt;&amp;nbsp;crypto ikev2 remote-vpn&lt;BR /&gt;&amp;nbsp;crypto auto-ipsec-secure&lt;BR /&gt;&amp;nbsp;crypto load-management&lt;BR /&gt;&amp;nbsp;crypto remote-vpn-client&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; wlan wlan1 bss 2 primary&lt;BR /&gt;&amp;nbsp; wlan wlan2 bss 3 primary&lt;BR /&gt;&amp;nbsp; antenna-mode 2x2&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; wlan wlan1 bss 1 primary&lt;BR /&gt;&amp;nbsp; wlan wlan2 bss 2 primary&lt;BR /&gt;&amp;nbsp; antenna-mode 2x2&lt;BR /&gt;&amp;nbsp;interface radio3&lt;BR /&gt;&amp;nbsp;interface bluetooth1&lt;BR /&gt;&amp;nbsp; shutdown&lt;BR /&gt;&amp;nbsp; mode le-sensor&lt;BR /&gt;&amp;nbsp;interface ge1&lt;BR /&gt;&amp;nbsp; switchport mode trunk&lt;BR /&gt;&amp;nbsp; switchport trunk allowed vlan 1-3&lt;BR /&gt;&amp;nbsp;interface ge2&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; ip address dhcp&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp; ip dhcp client request options all&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; description "Cap ST-EDU"&lt;BR /&gt;&amp;nbsp; ip nat inside&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; description "Cap ST-Gosc"&lt;BR /&gt;&amp;nbsp; ip nat inside&lt;BR /&gt;&amp;nbsp;use dhcp-server-policy default&lt;BR /&gt;&amp;nbsp;use firewall-policy default&lt;BR /&gt;&amp;nbsp;use captive-portal server default-onboard&lt;BR /&gt;&amp;nbsp;use captive-portal server default-onboard2&lt;BR /&gt;&amp;nbsp;use client-identity-group default&lt;BR /&gt;&amp;nbsp;logging on&lt;BR /&gt;&amp;nbsp;ip nat inside source list BROADCAST-MULTICAST-CONTROL precedence 1 interface vlan1 overload&lt;BR /&gt;&amp;nbsp;service pm sys-restart&lt;BR /&gt;&amp;nbsp;router ospf&lt;BR /&gt;&amp;nbsp;adoption-mode controller&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;rf-domain default&lt;BR /&gt;&amp;nbsp;location Hol&lt;BR /&gt;&amp;nbsp;contact raddus@wp.pl&lt;BR /&gt;&amp;nbsp;timezone Etc/GMT+1&lt;BR /&gt;&amp;nbsp;country-code pl&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;ap410 AA-AA-AA-AA-AA-AA&lt;BR /&gt;&amp;nbsp;use profile default-ap410&lt;BR /&gt;&amp;nbsp;use rf-domain default&lt;BR /&gt;&amp;nbsp;hostname ST-AP01&lt;BR /&gt;&amp;nbsp;area Wysoki&lt;BR /&gt;&amp;nbsp;floor Ip&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.12/24&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.12/24&lt;BR /&gt;&amp;nbsp; no ip nat&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; ip address 10.10.11.12/24&lt;BR /&gt;&amp;nbsp;ip dns-server-forward&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;ap410 BB-BB-BB-BB-BB-BB&lt;BR /&gt;&amp;nbsp;use profile default-ap410&lt;BR /&gt;&amp;nbsp;use rf-domain default&lt;BR /&gt;&amp;nbsp;hostname ST-AP01&lt;BR /&gt;&amp;nbsp;area Wysoki&lt;BR /&gt;&amp;nbsp;floor Ip&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.12/24&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.12/24&lt;BR /&gt;&amp;nbsp; no ip nat&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; ip address 10.10.11.12/24&lt;BR /&gt;&amp;nbsp;ip dns-server-forward&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;ap410 CC-CC-CC-CC-CC-CC&lt;BR /&gt;&amp;nbsp;use profile default-ap410&lt;BR /&gt;&amp;nbsp;use rf-domain default&lt;BR /&gt;&amp;nbsp;hostname ST-CON0&lt;BR /&gt;&amp;nbsp;area Aula&lt;BR /&gt;&amp;nbsp;floor Parter&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; description "Virtual Interface for LAN by Wizard"&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.11/24&lt;BR /&gt;&amp;nbsp; no ip dhcp client request options all&lt;BR /&gt;&amp;nbsp; no ip nat&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.11/24&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; ip address 10.10.11.11/24&lt;BR /&gt;&amp;nbsp;virtual-controller&lt;BR /&gt;&amp;nbsp;rf-domain-manager capable&lt;BR /&gt;&amp;nbsp;ip dns-server-forward&lt;BR /&gt;&amp;nbsp;no adoption-mode&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;&amp;nbsp;end&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 05:15:25 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72007#M6600</guid>
      <dc:creator>Radoslaw</dc:creator>
      <dc:date>2020-11-25T05:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Wing Ap410 Captive portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72008#M6601</link>
      <description>&lt;P&gt;&lt;A href="https://ext.connectedcommunity.org/profile?UserKey=c3d8046e-f38a-4684-b7be-e51d9b5b0bb6" target="_self" rel="noreferrer"&gt;Radoslaw&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;Can you confirm if the&amp;nbsp;other two APs are running the same firmware version as the VC controller AP? you can run the command “show adoption status” on the controller AP and check if any of the APs display&amp;nbsp;“version-mismatch”. If yes, then you need to upgrade the APs to the same version. Why is it important? APs that are not on the same version as the controller won’t receive configuration updates, this could be one of the reasons why the captive portal and radius configuration is not pushed to the APs.&lt;/P&gt;&lt;P&gt;Additionally, following is your profile config for the VLAN interfaces, I noticed that the interface NAT&amp;nbsp;configuration conflicts with your AP device config for the same VLANs:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Profile configuration:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;interface vlan1 &lt;SPAN style="color: #e74c3c"&gt;(add “IP nat outside” for VLAN 1)&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; ip address dhcp&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp; ip dhcp client request options all&lt;BR /&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; description "Cap ST-EDU"&lt;BR /&gt;&amp;nbsp;&lt;SPAN style="color: #8e44ad"&gt; ip nat inside&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;interface vlan3&lt;BR /&gt;&amp;nbsp; description "Cap ST-Gosc"&lt;BR /&gt;&amp;nbsp;&lt;SPAN style="color: #8e44ad"&gt; ip nat inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;APs’ device context:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.12/24&lt;BR /&gt;&amp;nbsp; &lt;SPAN style="color: #9b59b6"&gt;no ip nat&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.12/24&lt;BR /&gt;&amp;nbsp; &lt;SPAN style="color: #9b59b6"&gt;no ip nat&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; description "Virtual Interface for LAN by Wizard"&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.11/24&lt;BR /&gt;&amp;nbsp; no ip dhcp client request options all&lt;BR /&gt;&amp;nbsp;&lt;SPAN style="color: #9b59b6"&gt; no ip nat&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ovais&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 02:01:13 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72008#M6601</guid>
      <dc:creator>Ovais_Qayyum</dc:creator>
      <dc:date>2020-11-26T02:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Wing Ap410 Captive portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72009#M6602</link>
      <description>&lt;P&gt;Hi Ovais&lt;/P&gt;&lt;P&gt;Adoption look ok.&lt;BR /&gt;I corrected configuration.&lt;BR /&gt;I think I found the problem.&lt;BR /&gt;I created third wlan with captive portal on vlan 1 and I set the captive portal on ip of controler AP. Everything is working correctly.&lt;BR /&gt;I think the issue in vlan 2 and 3, between APs i cant ping the sets IP on interfaces. Can you look why the vlans is not availible between APs?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 01:48:57 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72009#M6602</guid>
      <dc:creator>Radoslaw</dc:creator>
      <dc:date>2020-11-27T01:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Wing Ap410 Captive portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72010#M6603</link>
      <description>&lt;P&gt;Hi Radoslaw,&lt;/P&gt;&lt;P&gt;You shouldn’t have to point the captive portal server host to the IP address of the controller, this is required for the captive portal “centralized mode” where the captive portal runs on a central controller. In case of “internal(self)” the captive portal runs on the AP, and the AP will use the IP interface of the VLAN which is defined in the SSID settings for capture and redirection. If the VLAN IP interface is not defined on the AP and there is&lt;STRONG&gt;&amp;nbsp;no virtual server host FQDN configured&lt;/STRONG&gt;, the captive portal will use the IP address of&amp;nbsp;&lt;STRONG&gt;1.1.1.1&lt;/STRONG&gt;&amp;nbsp;to perform redirection.&amp;nbsp;As&amp;nbsp;IP 1.1.1.1 has now got resolvable to CloudFare, it’s best practice to update the captive portal Server hostname to make sure that process is working correctly.&lt;/P&gt;&lt;P&gt;Looks like you have an IP conflict due to your configuration; both APs have the same IP addresses for VLAN2 and VLAN3. This would also create problems with the captive portal capture and redirection on interface VLAN2 and VLAN3. I would say you fix the IPs, set the virtual server host settings in the captive portal back to the FQDN you had earlier instead of pointing it to the VLAN1 IP of the controller AP, and it should work.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ap410 AA-AA-AA-AA-AA-AA&lt;BR /&gt;&amp;nbsp;use profile default-ap410&lt;BR /&gt;&amp;nbsp;use rf-domain default&lt;BR /&gt;&amp;nbsp;hostname ST-AP01&lt;BR /&gt;&amp;nbsp;area Wysoki&lt;BR /&gt;&amp;nbsp;floor Ip&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.12/24&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp;&lt;SPAN style="color:#e74c3c;"&gt;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.12/24&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; no ip nat&lt;BR /&gt;&amp;nbsp;&lt;SPAN style="color:#e74c3c;"&gt;interface vlan3&lt;BR /&gt;&amp;nbsp; ip address 10.10.11.12/24&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;ip dns-server-forward&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;ap410 BB-BB-BB-BB-BB-BB&lt;BR /&gt;&amp;nbsp;use profile default-ap410&lt;BR /&gt;&amp;nbsp;use rf-domain default&lt;BR /&gt;&amp;nbsp;hostname ST-AP01&lt;BR /&gt;&amp;nbsp;area Wysoki&lt;BR /&gt;&amp;nbsp;floor Ip&lt;BR /&gt;&amp;nbsp;interface radio1&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface radio2&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp;interface vlan1&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.12/24&lt;BR /&gt;&amp;nbsp; ip address zeroconf secondary&lt;BR /&gt;&amp;nbsp;&lt;SPAN style="color:#e74c3c;"&gt;interface vlan2&lt;BR /&gt;&amp;nbsp; ip address 10.10.10.12/24&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; no ip nat&lt;BR /&gt;&amp;nbsp;&lt;SPAN style="color:#e74c3c;"&gt;interface vlan3&lt;BR /&gt;&amp;nbsp; ip address 10.10.11.12/24&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;ip dns-server-forward&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ovais&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 02:22:34 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72010#M6603</guid>
      <dc:creator>Ovais_Qayyum</dc:creator>
      <dc:date>2020-11-27T02:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Wing Ap410 Captive portal</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72011#M6604</link>
      <description>&lt;P&gt;Hi, thanks for help. The biggest problem was on switch, it not allow communication on diffrent Vlan than 1. At now every think work OK. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 03:28:17 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-ap410-captive-portal/m-p/72011#M6604</guid>
      <dc:creator>Radoslaw</dc:creator>
      <dc:date>2020-12-04T03:28:17Z</dc:date>
    </item>
  </channel>
</rss>

