Alcatel-Lucent IAP93 Podręcznik Użytkownika Strona 126

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 125
(Instant Access Point)(Access Rule <Name>)# end
(Instant Access Point)# commit apply
Configuring Walled Garden Access
On the Internet, a walled garden typically controls access to web content and services. The Walled garden access is
required when an external Captive portal is used. For example, a hotel environment where the unauthenticated users
are allowed to navigate to a designated login page (for example, a hotel website) and all its contents.
The users who do not sign up for the Internet service can view the “allowed Websites (typically hotel property
Websites). The Website names must be DNS-based and support the option to define wildcards. This works for client
devices with or without HTTP proxy settings.
When a user attempts to navigate to other Websites, which are not in the whitelist of the walled garden profile, the
user is redirected to the login page. In addition, a blacklisted walled garden profile can also be configured to explicitly
block the unauthenticated users from accessing some Websites.
You can create a walled garden access in AOS-W Instant UI or CLI.
In the AOS-W Instant UI
To create a Walled Garden access:
1. Click the Security link at the top right corner of the AOS-W Instant main window and click Walled Garden. The
Walled Garden tab contents are displayed.
2. To allow users to access a specific domain, click New and enter the domain name or URL in the Whitelist
section of the window. This allows access to a domain while the user remains unauthenticated. Specify a POSIX
regular expression (regex(7)). For example:
l yahoo.com matches various domains such as news.yahoo.com, travel.yahoo.com and finance.yahoo.com
l www.apple.com/library/test is a subset of www.apple.com site corresponding to path /library/test/*
l favicon.ico allows access to /favicon.ico from all domains.
3. To deny users access to a domain, click New and enter the domain name or URL in the Blacklist section of the
window. This prevents the unauthenticated users from viewing specific Websites. When a URL specified in the
blacklist is accessed by an unauthenticated user, OAW-IAP sends an HTTP 403 response to the client with a
simple error message.
If the requested URL does not appear on the blacklist or whitelist list, the request is redirected to the external
Captive portal.
4. Select the domain name/URL and click Edit to modify or Delete to remove the entry from the list.
5. Click OK to apply the changes.
In the CLI
To create a Walled Garden access:
(Instant Access Point)(config)# wlan walled-garden
(Instant Access Point)(Walled Garden)# white-list <domain>
(Instant Access Point)(Walled Garden)# black-list <domain>
(Instant Access Point)(Walled Garden)# end
(Instant Access Point)# commit apply
Disabling Captive Portal Authentication
To disable captive portal authentication, perform the following steps:
1. Select an existing wireless or wired profile. Depending on the network profile selected, the Edit <WLAN-Profile>
or Edit Wired Network window is displayed.
AOS-W Instant 6.3.1.1-4.0 | User Guide Captive Portal for Guest Access | 126
Przeglądanie stron 125
1 2 ... 121 122 123 124 125 126 127 128 129 130 131 ... 334 335

Komentarze do niniejszej Instrukcji

Brak uwag