I have a Virtual Controller (VSZ-H) in version 3.4.x with the configuration of 3 interfaces (Control, Management and Cluster) of course the three IPs are different.
I have configured the hotspot (Wispr) and it works to me locally (Local BD).
When that a AAA server the controller makes the connection with this, but at the moment of providing internet service to the end user, the authentication is done by an invalid IP, that is, it requests permissions and ports for the management plane. I have the control plane in a public domain in order to facilitate the provision process and AP requests as clients and I have configured the control plane as default gateway.
Configuration / system / clusterplanes
There is a way to configure the VSZ-H controller to receive the authentication by the control plane.
The following are the hotspot components and its role in the hotspot portal as seen in Figure 1. • Northbound: Listens on the control and management interface. It is responsible for handling requests from external subscriber portal and authenticates with the AAA server. • Captive portal: Listens on the control interface or UDI. It is responsible for providing a wall garden for web-proxy UE. It blocks UEs, which uses user agents that are listed in the configured black-list and mainly handles high scalable redirecting UEs to the external subscriber portal. • External subscriber portal: Is a Web service. The user sends his/her login credentials (user name and password) through this portal. The authentication is performed through the northbound by user input credential. The external subscriber portal can reach the northbound depending on the type of interface it can reach such as control interface, management interface or both. • AAA server: Is responsible for authenticating the UE through the UE’s login credentials (user name and password).