
123 | Captive Portal for Guest Access AOS-W Instant 6.3.1.1-4.0 | User Guide
(Instant Access Point)(Access Rule <name>)# rule <dest> <mask> <match> <protocol> <start-port>
<end-port> {permit |deny | src-nat | dst-nat {<IP-address> <port> | <port>}}[<option1…option
9>]
(Instant Access Point)(Access Rule <name>)# end
(Instant Access Point)# commit apply
To configure access control based on the SSID:
(Instant Access Point)(config)# wlan ssid-profile <name>
(Instant Access Point)(SSID Profile <name># set-role-by-ssid
(Instant Access Point)(SSID Profile <name># end
(Instant Access Point)# commit apply
To configure role assignment rules:
(Instant Access Point)(config)# wlan ssid-profile <name>
(Instant Access Point)(SSID Profile <name># set-role <attribute>{{equals|not-equals|starts-wit
h|ends-with|contains|matches-regular-expression}<operator><role>|value-of}
(Instant Access Point)(SSID Profile <name># end
(Instant Access Point)# commit apply
To configure a pre-authentication role:
(Instant Access Point)(config)# wlan ssid-profile <name>
(Instant Access Point)(SSID Profile <name># set-role-pre-auth <pre-authentication-role>
(Instant Access Point)(SSID Profile <name># end
(Instant Access Point)# commit apply
To configure machine and user authentication roles
(Instant Access Point)(config)# wlan ssid-profile <name>
(Instant Access Point)(SSID Profile <name># set-role-machine-auth <machine-authentication-onl
y> <user-authentication-only>
(Instant Access Point)(SSID Profile <name># end
(Instant Access Point)# commit apply
To configure unrestricted access:
(Instant Access Point)(config)# wlan ssid-profile <name>
(Instant Access Point)(SSID Profile <name># set-role-unrestricted
(Instant Access Point)(SSID Profile <name># end
(Instant Access Point)# commit apply
Configuring Captive Portal Roles for an SSID
You can configure an access rule to enforce Captive portal authentication for SSIDs with 802.1X authentication
enabled. You can configure rules to provide access to external Captive portal, internal Captive portal, or none, so
that some of the clients using this SSID can derive the Captive portal role.
The following conditions apply to the 802.1X and Captive portal authentication configuration:
l If a user role does not have Captive Portal settings configured, the Captive portal settings configured for an SSID
are applied to the client's profile.
l If the SSID does not have Captive Portal settings configured, the Captive portal settings configured for a user
role are applied to the client's profile.
l If Captive portal settings are configured for both SSID and user role, the Captive portal settings configured for a
user role are applied to the client's profile.
You can create a Captive portal role for both Internal-acknowledged and External Authentication Text splash
page types.
To enforce Captive Portal role, use the AOS-W Instant UI or CLI.
Komentarze do niniejszej Instrukcji