background image

ArubaOS   +   Amigopod   Integration   Cheet   Sheet   

   

   

   

Aruba   Networks   |   

10

   

   

9.

 

Configure   RADIUS   NAS   for   Aruba   Controller   

An   entry   for   the   Aruba   Controller   needs   to   be   created   under   the   Amigopod   RADIUS   
Services

à

NAS   List.   The   NAS   Type   should   always   be   set   for   

Aruba   (RFC   3576)

   to   allow   the   

Amigopod   to   enable   the   support   for   RADIUS   Dynamic   Authorization.      

As   usual   the   shared   secret   must   match   on   the   Amigopod   and   the   ArubaOS   RADIUS   Server   
definition.   

      

You   can   optionally   check   the   

Web   Login

   option   at   the   bottom   of   the   form   to   automatically   

create   the   Web   Login   form   based   on   the   Aruba   Networks   presets.   

Note:

   Once   you   have   clicked   the   

Create   NAS   Device

   you   will   be   prompted   to   Restart   the   

RADIUS   Server.   This   is   essential,   as   the   RADIUS   Server   within   Amigopod   will   reject   any   request   
from   the   Aruba   Controller   as   unknown   until   the   restart   has   been   performed.   

   

   

Summary of Contents for ArubaOS

Page 1: ...FOR ARUBA NETWORKS EMPLOYEES CUSTOMERS AND PARTNERS ArubaOS Amigopod Integration Cheat Sheet...

Page 2: ...rofile 5 5 Create AAA Profile 6 6 Enable Captive Portal on Initial Role of Captive Portal Profile 7 7 Ensure the Amigopod IP Address allowed in captiveportal policy 8 8 Configure Guest VAP with new AA...

Page 3: ...a RADIUS server so the basis of the integration in ArubaOS is the full AAA config Amigopod uses the default ports of 1812 for Authentication and 1813 for Accounting 2 Add RADIUS Server to a Server Gr...

Page 4: ...tionally Welcome Pages to be hosted by Amigopod For example we could set these pages to the following Login Page https Amigopod IP Address or FQDN Aruba_login php Welcome Page https Amigopod IP Addres...

Page 5: ...t Sheet Aruba Networks 5 4 Configure Authentication for Captive Portal Profile Now the new Captive Portal Profile has been created make sure the Server Group for the Amigopod RADIUS definition is sele...

Page 6: ...5 Create AAA Profile The AAA Profile should be configured to have the Initial Role reference the newly created Captive Portal Profile Also ensure the RADIUS Accounting Server Group of the AAA profile...

Page 7: ...ble Captive Portal on Initial Role of Captive Portal Profile This step is easy to miss and the Captive Portal will not be triggered Select the configured Captive Portal profile from the dropdown box a...

Page 8: ...gh the CLI or GUI It is handy to define the Amigopod appliance in an alias definition as shown below netdestination Amigopod host 10 0 20 15 Add an entry that allows the client based HTTPS traffic to...

Page 9: ...appropriate AP Group To activate the new Amigopod specific Guest configuration edit your VAP and ensure the AAA Profile for the VAP is set to the new AAA Profile configured in the previous step Assum...

Page 10: ...ic Authorization As usual the shared secret must match on the Amigopod and the ArubaOS RADIUS Server definition You can optionally check the Web Login option at the bottom of the form to automatically...

Page 11: ...utomatically created Web Login but you can equally create a new one manually at a later stage The Page Name field is what defines the URL that will be hosted on the Amigopod appliance For example in s...

Page 12: ...u can enable the display of an Accept Terms Conditions option of the login page if required This refers to the default T Cs URL defined under Guest Manager Customization Customize Guest Manager Unfort...

Page 13: ...n see there are options to Insert Content and Self Registration page respectively found in Administrator Content Manager Guest Manager Customization Guest Self Registration You will notice the code at...

Page 14: ...e Login Message HTML will be displayed This is a useful point to grab the contents of a View Source in the client s browser if you need to troubleshoot any Captive Portal issues Finally each Web Login...

Page 15: ...ributes These attributes can be used to signal role based access control context back to the Aruba Controller as shown in the example screenshot This RADIUS Role is presented in the Create User screen...

Page 16: ...ully redirected to the Amigopod Web Login page Use the Amigopod Guest Manager to create a test account and then attempt to login via the redirected Web Login page If you have been able to successfully...

Page 17: ...sions screen shown below Given the Interim Accounting support in ArubaOS 6 1 this screen will display live traffic statistics based on these updates Assuming you have configured RFC 3576 on your Aruba...

Page 18: ...ensure traffic is permitted to configured IP address of the controller in the step above Receiving error message in RADIUS Logs about unknown client Check the RADIUS NAS List and make sure there is a...

Page 19: ...kplace Is Now Open For Business Green Island and The Mobile Edge Company are trademarks of Aruba Networks Inc All rights reserved Aruba Networks reserves the right to change modify transfer or otherwi...

Reviews: