Guest access – ExtremeCloud IQ

In this topic, you will learn how to configure ExtremeCloud IQ to work together with the Portnox™ Cloud captive portal for guest user authentication.

Before you begin configuring your guest SSID, you must configure the guest network in Portnox Cloud and note down the values of the fields: IP (for walled garden) and Captive Portal URL.

Note:
ExtremeCloud IQ requires a RADIUS server group even for a guest SSID that redirects to an external captive portal, since the access point uses it to confirm that a client has finished authenticating on the captive portal. If you already created a Portnox Cloud external RADIUS server group when configuring employee Wi-Fi access, you can skip the following two sections and select your existing RADIUS server group when you configure the guest SSID.
Important:
This guide gives general instructions for integrating Portnox Cloud with specific third-party devices. We try to provide useful examples for common models, but settings can differ between manufacturers, models, and environments. Because of this, we cannot guarantee these steps will work in every case. For questions or problems with RADIUS setup – which is an industry standard and not specific to Portnox – or with device-specific settings and troubleshooting, we recommend checking the device manufacturer’s documentation and contacting their support team. Portnox Support can help when possible, but detailed setup of third-party devices is usually best handled by the manufacturer. We also recommend updating your NAS device firmware to the latest version, as old firmware can cause issues.
Important:
All values in this configuration are examples. Make sure to adjust the configuration to your individual profile names, RADIUS server addresses, ports, and keys by replacing the values that are presented as underlined italics.
Important:
Do not create the captive web portal object separately through Configure > Common Objects > Authentication > Captive Web Portals. That page does not expose the fields needed for an external captive portal, such as Login URL. Instead, create the captive web portal directly from the SSID configuration screen, as described in this topic.

Create IP objects for the Portnox Cloud RADIUS servers

In this section, you will create IP objects for the Portnox™ Cloud RADIUS servers. ExtremeCloud IQ uses these IP objects to reference IP addresses in external RADIUS server entries, which you will create in the next section.

  1. In the left-hand side menu of the ExtremeCloud IQ web interface, click on the following menu options: Configure > Common Objects > Basic > IP Objects / HostNames or go to https://va.extremecloudiq.com/#/common/ipobjectmanage.

  2. In the IP Objects and Host Names pane, click on the  +  icon in the toolbar to create a new IP object.

  3. In the New IP Object or Host Name pane, configure the new IP object:

    1. In the Name field, enter a display name for this object, for example, the name of the corresponding Portnox Cloud RADIUS server.
    2. Leave the type field set to IP Address.
    3. In the IP Address field of the only row in the table, enter the Cloud RADIUS IP value from Portnox Cloud.
    4. Click on the SAVE IP OBJECT button.
  4. If you use two Cloud RADIUS servers in both regions, repeat the above steps for the second RADIUS server.

    The above screenshot shows an example configuration with two added IP objects, one for each Cloud RADIUS region. Adjust the names and IP addresses to your tenant configuration.

Create the external RADIUS servers

In this section, you will create external RADIUS server entries for the Portnox™ Cloud RADIUS servers, using the IP objects that you created earlier. You will use these servers later when you configure your SSIDs.

  1. In the left-hand side menu of the ExtremeCloud IQ web interface, click on the following menu options: Configure > Common Objects > Authentication > External RADIUS Servers or go to https://va.extremecloudiq.com/#/common/extservers.

  2. In the External RADIUS Servers pane, click on the  +  icon in the toolbar to create a new external RADIUS server.

  3. In the External RADIUS Server pane, enter the details of the Portnox Cloud RADIUS server that you created earlier:

    1. In the Name field, enter a display name for this server.
    2. Leave the Type field set to Standard.
      Note:
      The Type field also offers a RADSEC option. Portnox has not, so far, been able to get this option to work with ExtremeCloud IQ and Extreme community discussions seem to suggest that this option is supported directly only with Extreme RadSec servers. If you need RadSec support for this integration, coordinate with Portnox support and Extreme Networks support on a joint call to resolve this with Extreme.
    3. In the IP/Host Name field, click on the list icon, and select the IP object that you created earlier for this Portnox Cloud RADIUS server.
    4. Activate both the Authentication and Accounting checkboxes in the Server Type field, and in the corresponding Port fields, enter the Authentication Port and Accounting Port values from Portnox Cloud.
    5. In the Shared Secret field, enter the Shared Secret value from Portnox Cloud.
    6. Click on the SAVE EXTERNAL RADIUS button.
  4. If you use two Cloud RADIUS servers in both regions, repeat the above steps for the second RADIUS server.

    The above screenshot shows an example configuration with two external RADIUS server entries, one for each Cloud RADIUS region. Adjust the names, IP objects, and port numbers to your tenant configuration.

Create the guest SSID

In this section, you will create a new open SSID for guest access, and configure it, along with a captive web portal object, to redirect guests to the Portnox Cloud captive portal.

  1. In the left-hand side menu of the ExtremeCloud IQ web interface, click on the following menu options: Configure > Common Objects > Policy > SSIDs or go to https://va.extremecloudiq.com/#/common/ssidmanage.

  2. In the SSIDs pane, click on the  +  icon in the toolbar to create a new SSID.

  3. In the Wireless Network section, enter the Name (SSID) for the guest SSID, which is the name visible in the ExtremeCloud IQ interface, and the Broadcast Name, which is the name shown to devices when searching for a network.

  4. Scroll down to the SSID Usage section, and on the SSID Authentication tab, select the Open option.

    Note:
    Do not select Enterprise here. Since MAC authentication becomes the sole means of access control on an open SSID, you do not need WPA2 or WPA3 Enterprise authentication on this SSID.
  5. Set the Enable Captive Web Portal switch to ON, and select the Captive Web Portal option.

    1. Activate the User Auth on Captive Web Portal checkbox.
    2. In Choose Authentication Type, select the Redirect to External URL for Authentication option.
  6. Next to the Default Captive Web Portal field, click on the ADD button.

    Result: The New Captive Web Portal window opens.

  7. In the New Captive Web Portal window, in the Name field, enter a name for this captive web portal, for example, Portnox-Guest.

  8. In the Captive Web Portal Settings section, on the CUSTOMIZE AND PREVIEW tab, in the Login URL field, paste the Captive Portal URL that you obtained when you configured the guest network in Portnox Cloud.

  9. In the Password Encryption field, select the No Encryption (Plaintext Password) option, and leave the Authentication Method field set to its default CHAP value.

    Note:
    Since this SSID redirects guests directly to the Portnox Cloud captive portal, ExtremeCloud IQ never uses these values. Avoid the UAM with Shared Secret option only, since it requires a Shared Secret value that you would have to enter to proceed.
  10. Set the Success Page and Failure Page switches to OFF.

  11. Scroll down to the Walled Garden section, click on the  +  icon.

    1. In the text box below Service Type, paste the addresses from the IP (for walled garden) field that you obtained when you configured the guest network in Portnox Cloud, separated by commas.
    2. Click on the ADD button.
      Note:
      ExtremeCloud IQ automatically creates an IP/Host Name object for each address that does not already have one, and adds it to the table below.
    Warning:
    The NAS device must be able to communicate with the walled garden IP addresses at all times. If this communication is blocked in any way, the captive portal will not work, and guest devices will be unable to connect to the network. Before you proceed, verify that all firewalls, ACLs, and any other security measures that could interfere with this communication are configured to explicitly allow the walled garden IP addresses.
  12. Click on the SAVE CWP button.

    Result: The New Captive Web Portal window closes, and the captive web portal that you just created is selected in the Default Captive Web Portal field.

  13. Scroll down to the Authentication Settings section:
    1. Make sure that the Authentication with ExtremeCloud IQ Authentication Service switch is set to OFF.
    2. In the Authenticate via RADIUS Server subsection, click on the  +  icon next to the Default RADIUS Server Group field.

    3. In the Configure RADIUS Servers pane, in the RADIUS Server Group Name field, enter a name for the RADIUS server group, then on the EXTERNAL RADIUS SERVER tab, activate the checkboxes next to the external RADIUS servers that you created earlier, and click on the SAVE RADIUS button.

      Note:
      The EXTERNAL RADIUS SERVER tab lists every external RADIUS server that you created, including any RADSEC-type servers. Select only the Standard-type servers for this SSID.
    4. The SSID page now shows the new RADIUS server group selected in the Default RADIUS Server Group field, with the servers that you selected listed in the table below it.

  14. Clck on the SAVE button to save the SSID configuration.

Result: You created an open SSID that redirects guests to the Portnox Cloud captive portal for authentication.

Important:
After a guest logs in using the Portnox Cloud captive portal page, ExtremeCloud IQ briefly redirects the browser to an internal IP of the access point to capture the form before granting access. This causes the browser to show a Form is not secure warning, stating that the information you’re about to submit is not secure. The guest must click on the Send anyway button to proceed. We tested this thoroughly across every relevant setting available in ExtremeCloud IQ, and the warning appears regardless of configuration. This behavior appears to be an Extreme Networks limitation rather than something fixable through Portnox Cloud or ExtremeCloud IQ settings. If this warning is a concern for your deployment, we recommend working together with Portnox and Extreme Networks support on potential workarounds.

Assign SSIDs to a network policy and update your access points

In this section, you will add any SSIDs that you created to a network policy, and push the updated policy to your access points. Changes to your network policy do not take effect until you complete this section.

  1. In the left-hand side menu of the ExtremeCloud IQ web interface, click on the following menu options: Configure > Network Policies.

  2. On the tile representing the network policy that you want to update, click on the ADD NETWORK button.

    Result: The network policy wizard opens.

  3. Click on the Select icon.

    Result: The SSIDs window opens.

  4. In the SSIDs window, activate the checkbox(es) next to the SSIDs that you created, and click on the SELECT button.

  5. In the wizard, click on the 6 Deploy Policy step.

    Result: The Apply the network policy to selected devices step opens.

  6. Activate the checkbox(es) next to the access points that you want to update and click on the UPLOAD button.

  7. In the Device Update window, select the Complete Configuration Update option, and click on the PERFORM UPDATE button.

    Note:
    We recommend a complete configuration update over a delta update, since it resets the device to match ExtremeCloud IQ's configuration exactly, rather than only applying changes. A delta update can leave stale settings on the device if earlier updates failed or were only partially applied.

Result: Your access points receive the updated network policy, and clients can now access the SSIDs that you created.