
AOS-W Instant 6.3.1.1-4.0 | User Guide Captive Portal for Guest Access | 110
Chapter 11
Captive Portal for Guest Access
This chapter provides the following information:
l Understanding Captive Portal on page 110
l Configuring a WLANSSID for Guest Access on page 111
l Configuring Wired Profile for Guest Access on page 114
l Configuring Internal Captive Portal for Guest Network on page 116
l Configuring External Captive Portal for a Guest Network on page 118
l Configuring External Captive Portal Authentication Using ClearPass Guest on page 121
l Configuring Guest Logon Role and Access Rules for Guest Users on page 122
l Configuring Captive Portal Roles for an SSID on page 123
l Configuring Walled Garden Access on page 126
l Disabling Captive Portal Authentication on page 126
Understanding Captive Portal
AOS-W Instant supports the Captive portal authentication method, where a web page is presented to the guest
users when they try to access the Internet whether in hotels, conference centers or Wi-Fi hotspots. The web page
also prompts the guest users to authenticate or accept the usage policy and terms. Captive portals are used at many
Wi-Fi hotspots and can be used to control wired access as well.
The AOS-W Instant Captive portal solution consists of the following:
l The captive portal web login page hosted by an internal or external server.
l The RADIUS authentication or user authentication against OAW-IAP's internal database.
l The SSID broadcast by the OAW-IAP.
With AOS-W Instant, the administrators can create a wired or WLAN guest network based on Captive portal
authentication for guests, visitors, contractors, and any non-employee users who can use the enterprise Wi-Fi
network. The administrators can also create guest accounts and customize the Captive portal page with
organization-specific logo, terms, and usage policy. With Captive portal authentication and guest profiles, the
devices associating with the guest SSID are assigned an initial role and are assigned IP addresses. When a guest
user tries to access a URL through HTTP or HTTPS, the Captive portal web page prompting the user to authenticate
with a user name and password is displayed.
Types of Captive Portal
AOS-W Instant supports the following types of Captive portal authentication:
l Internal Captive portal — For Internal Captive portal authentication, an internal server is used for hosting the
captive portal service. It supports the following types of authentication:
n Internal Authenticated— When Internal Authenticated is enabled, a guest user must authenticate in the
captive portal page to access the Internet. The guest users who are required to authenticate must already be
added to the user database.
n Internal Acknowledged— When Internal Acknowledged is enabled, a guest user must accept the terms
and conditions to access the Internet.
l External Captive portal— For external Captive portal authentication, an external portal on the cloud or on a
server outside the enterprise network is used.
Comentarios a estos manuales