cancel
Showing results for 
Search instead for 
Did you mean: 

Wired Captive Portal Authentication - Roles and Services

Wired Captive Portal Authentication - Roles and Services

Niko_P
New Contributor II

Hi everyone!

I want to authenticate wired clients with the control captive portal.
I got universal 5420F Switches running EXOS/Switch Engine.

The goal is:
All unregistered clients shall be moved to VLAN 400 and redirected to the portal.
After portal login, the switch needs to apply a different role/policy to the client, based on user groups, to limit network access.
The VLAN dose not change.

What I got:
I created a role “Unregistriert”, which uses “Contain to VLAN 400” and “HTTP redirect”.
The role has some services/rules attached to allow arp, dhcp, dns and traffic to the portal. Last rule should deny all ipv4 traffic.  (See Screenshots)

A client connects, the switch applys "Unregistriert", client is moved to VLAN 400 and gets redirect to the portal, this is working.

But even without logging in to the portal, the client has full network and internet access.

Do you know what is wrong?

172.17.32.0/20 is the Client subnet in VLAN 400

172.31.2.31 is the control engine.

Niko_P_2-1736346570530.png

Niko_P_0-1736346454660.png

 

Best regards
Niko

1 ACCEPTED SOLUTION

Niko_P
New Contributor II

Problem is solved!

First:
I had set "Global Domain Settings" to "Role ACL Mode".
I unchecked that.

Second:
I changed the "Unregistriert" Role - Access Control to Deny Traffic

Third:
I use the RFC 3580 - VLAN ID
Which sets the VLAN via Accept Policy

And last I changed some of the services.

Best Regards
Niko

 

Niko_P_0-1736437195812.png

Niko_P_1-1736437246060.png

Niko_P_2-1736437297038.png

Niko_P_3-1736437377692.png

 

Niko_P_4-1736437454160.png

 

Niko_P_5-1736437491594.png

 

Niko_P_0-1736437930720.png

 

View solution in original post

1 REPLY 1

Niko_P
New Contributor II

Problem is solved!

First:
I had set "Global Domain Settings" to "Role ACL Mode".
I unchecked that.

Second:
I changed the "Unregistriert" Role - Access Control to Deny Traffic

Third:
I use the RFC 3580 - VLAN ID
Which sets the VLAN via Accept Policy

And last I changed some of the services.

Best Regards
Niko

 

Niko_P_0-1736437195812.png

Niko_P_1-1736437246060.png

Niko_P_2-1736437297038.png

Niko_P_3-1736437377692.png

 

Niko_P_4-1736437454160.png

 

Niko_P_5-1736437491594.png

 

Niko_P_0-1736437930720.png

 

GTM-P2G8KFN