01-15-2025 06:46 PM
Hello, Community,
I am currently struggling with configuring a CWA (Captive Portal) setup using XIQ-C and Control, and I could really use some help.
Requirements:
XIQ-C :E1120 10.10.02
XIQ-SE&control :24.7.11.22
1. Clients connect to the SSID using EAP-TLS authentication.
2. After that, they are redirected to the Captive Portal.
3. On the portal, they sign in using the "Sign in with Microsoft" button.
However, with my current configuration, clients are not being redirected to the Captive Portal after completing EAP-TLS authentication.
When I tested the radiusd in Control, EAP-TLS completes successfully, but the Access-Accept packet does not include parameters like a redirect URL.
Looking at the End-Systems tab:
Under [Authorization], it shows:
「Filter-Id='Enterasys:version=1:policy=Unregistered', Login-LAT-Port='0'.」
For [Engine] -> [RADIUS Attributes to send], I haven’t manually configured anything, but [Extreme IdentiFi Wireless] is selected (this seems to be the default setting).
I understand that Login-LAT-Port='0' is a parameter interpreted by XIQ-C and is assigned to users who haven’t fully authenticated yet.
The policy=Unregistered setting is associated with a redirect service, which is enabled.
From my understanding, this should result in the client being redirected to the Captive Portal, but it is not working as expected.
01-15-2025 08:29 PM
hi James-san
Upon checking, I found that a similar configuration is also present in the rules on XIQ-C.
I believe this configuration was pushed via policy enforcement from XIQ-SE/Control, which manages XIQ-C.
Or is it necessary to create a separate rule for proper interpretation in this case?
As far as I remember, if a rule is created within XIQ-C, it gets overwritten when enforced by SE.
Even in this case, should I create the rule on the XIQ-C side?