- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Table of Contents - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Scenario 2c: Supporting 802.1x/WPA customers ......................................80
How it works........................................................................................80
Configuration roadmap ........................................................................80
Scenario 3: Centralized authentication .......................................................81
How it works........................................................................................81
Configuration roadmap ........................................................................82
Scenario 4: Wholesaling with GRE.............................................................84
How it works........................................................................................84
Configuration roadmap ........................................................................85
Scenario 5: Wholesaling with VPNs ...........................................................87
How it works.......................................................................................87
Configuration roadmap ........................................................................87
Scenario 6: Public/private access with VLANs ...........................................90
How it works.......................................................................................90
Configuration roadmap ........................................................................91
Chapter 5
Activating the public access interface
95
Overview ....................................................................................................96
Important .............................................................................................96
Local mode ..........................................................................................96
Supporting PDAs .................................................................................96
Step 1: Setting up the CN3000 RADIUS client ...........................................97
Configuration procedure ......................................................................97
Profile name.........................................................................................98
RADIUS profile settings .......................................................................98
Primary RADIUS server .......................................................................99
Secondary RADIUS server ...................................................................99
Step 2: Setting up CN3000 authentication ...............................................100
Configuration procedure ....................................................................100
CN3000 RADIUS authentication.........................................................101
Step 3: Setting up customer authentication .............................................102
Configuration procedure ....................................................................102
HTML-based user logins....................................................................103
Step 4: Setting up the RADIUS server......................................................104
Minimum setup..................................................................................104
More information ...............................................................................104
Step 5: Testing the public access interface ..............................................105
Chapter 6
Customizing the public access interface
107
Overview ..................................................................................................108
Common configuration tasks .............................................................108
Site map...................................................................................................109
Internal pages ....................................................................................110
External pages ...................................................................................112
How it works......................................................................................113
Customizing the internal pages ................................................................114
Creating new internal pages ...............................................................114
Important restrictions ........................................................................114
Loading new internal pages ...............................................................114
Examples ...........................................................................................116
Customizing the external pages ...............................................................117
Creating new external pages ..............................................................117
Activating new external pages............................................................117
Examples ...........................................................................................119
Using a remote login page .......................................................................121
Activating a remote login page...........................................................121
How it works......................................................................................123
Security issues...................................................................................123
Example .............................................................................................124
Location-aware authentication .................................................................125
How it works......................................................................................125
Example .............................................................................................125
Security..............................................................................................126
Configuration .....................................................................................127
iPass support...........................................................................................128
ASP functions ..........................................................................................129
Errors.................................................................................................129
RADIUS..............................................................................................129
Page URLs .........................................................................................130
Session status and properties............................................................130
Session quotas ..................................................................................133
iPass support.....................................................................................134
Message file.............................................................................................136
Source code for the internal pages ..........................................................138
Login page .........................................................................................138
Transport page...................................................................................140
Session page .....................................................................................140
Fail page.............................................................................................142
Chapter 7
Customizing CN3000 and customer settings
143
Overview ..................................................................................................144
IMPORTANT.......................................................................................144
Standard RADIUS attributes ....................................................................145
Colubris Networks vendor-specific attributes ..........................................146
Attribute value summary....................................................................146
RADIUS limitations ............................................................................147
Terminate-Acct-Cause values.............................................................147
Creating a RADIUS client entry for the CN3000 .......................................149
Configuration settings........................................................................149
Managing shared secrets ...................................................................149
Creating a profile for the CN3000 on the RADIUS server .........................150
Standard RADIUS attributes ..............................................................150
Colubris-AVPair attribute ...................................................................152
Access lists ........................................................................................153
Custom SSL certificate ......................................................................158
Configuration file ...............................................................................159
MAC authentication............................................................................160
Default user idle timeout ....................................................................160
Default user session timeout .............................................................161
Default user SMTP server ..................................................................161
Default user interim accounting update interval.................................161
Default user one-to-one NAT..............................................................162
Default user quotas............................................................................162
IPass login url....................................................................................163
Creating customer profiles on the RADIUS server ...................................164
Supported RADIUS attributes ............................................................164
Colubris-AVPair attribute ...................................................................167
Group name .......................................................................................168
NAT port range...................................................................................168
SSID ..................................................................................................168
Access list..........................................................................................168
Colubris-Intercept ..............................................................................169
One-to-one NAT .................................................................................169
Quotas ...............................................................................................169
SMTP redirection ...............................................................................170
VLAN support ....................................................................................171
Creating administrator profiles on the RADIUS server.............................172
Supported RADIUS attributes ............................................................172
Summary of Contents for CN3000
Page 1: ...CN3000 Administrator s Guide...
Page 8: ...Table of Contents 8...
Page 60: ...Chapter 2 How it works Chapter 2 60...
Page 94: ...Chapter 4 Scenarios Chapter 4 94...
Page 106: ...Chapter 5 Activating the public access interface Chapter 5 106...
Page 211: ...Chapter 10 SSL certificates Chapter 10 211...
Page 292: ...Chapter 13 The configuration file Chapter 13 292...
Page 370: ...Chapter 16 Sample setup Microsoft RADIUS Chapter 16 370...
Page 396: ...Chapter 16 Sample setup Microsoft RADIUS Chapter 16 396...
Page 414: ...Chapter 17 Experimenting with NOC authentication Chapter 17 414...