This article explains setting up a Cisco Wireless Controller (9800 IOS-XE) with Cloudpath Enrollment System for redirection of on-boarding SSID.
NOTE: This document does not include Cloudpath workflow setup, it is assumed that workflow is configured on Cloudpath.
Contents
- Prerequisites
- Configure ACL
- Configure Webauth Profile
- Configure AAA Server
- Configure AAA Method List
- Configure WLAN
Prerequisites
Before you can configure Cloudpath and Cisco WLAN Controller for webauth, you must have the following set up in your network.
- Cisco Wireless LAN Controller configured in your network.
- IP address of Cloudpath system.
- A Cloudpath enrollment workflow configured for your network.
Configure ACL(Configuration>>>>Security>>>ACL)
- Click on Add option to configure a pre-authentication ACL to allow access from the controller to and from Cloudpath.
- 1.a Click on the Add button to add acl, from seq number 10 to 40, IP shown in source and destination is Cloudpath IP, rest of the acl same as below.
Configure Web-auth profile(Configuration>>>>Security>>>Web Auth)
- Click on Add option to configure a webauth profile
- 1.a Name the profile.
- 1.b Set Type as webauth.
- 1.c Set Redirect for Log-in as Cloudpath Workflow URL.
- 1.d Portal IPv4 address as Cloudpath IP address
Configure AAA Server(Configuration>>>>Security>>>AAA)
- Click on Add option to add radius server details
- 1.a Name the profile.
- 1.b Set Server Address as Cloudpath IP/hostname.
- 1.c/1.d Set Key/Confirm Key same as configured under radius in Cloudpath.
- 1.e/1.f Set Auth/Acct port as defined under radius in Cloudpath.
Configure AAA Method List(Configuration>>>>Security>>>AAA>>>AAA Method List)
Authentication
- Click on Add option to add radius server details
- 1.a Name the Method List name
- 1.b Assigned Server Groups as created in the previous step.
Authorization
- Click on Add option to add radius server details
- 1.a Name the Method List name
- 1.b Assigned Server Groups as created in the previous step.
Configure WLAN(Configuration>>>>Tags and Profiles>>>WLANs)
Security Layer 2 >>>None
- Add Authorization List created in previous step
Security Layer 3>>>WebPolicy
- Add webauth profile created in AAA Method List above.
- Add Authentication List created AAA Method List above.
Vijay Kuniyal
Staff Technical Support Engineer
CCNA RnS | CCNA Wireless | CWNA | RASZA | Meraki CMNO | RACPA