
9-28
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 9 Managing User Accounts
Configuring Wired Guest Access
Step 21 From the Layer 3 Security drop-down box, choose one of the following:
• None—Layer 3 security is disabled.
• Web Authentication—Causes users to be prompted for a username and password when connecting
to the wireless network. This is the default value.
• Web Passthrough—Allows users to access the network without entering a username and password.
Step 22 If you choose the Web Passthrough option, an Email Input check box appears. Check this check box if
you want users to be prompted for their email address when attempting to connect to the network.
Step 23 To override the global authentication configuration set on the Web Login page, check the Override
Global Config check box.
Step 24 When the Web Auth Type drop-down box appears, choose one of the following options to define the web
login page for wired guest users:
• Internal—Displays the default web login page for the controller. This is the default value.
• Customized—Displays a custom web login page that was downloaded to the controller. If you
choose this option, you must also choose the desired login page from the Login Page drop-down box.
These optional login pages are downloaded to the controller as webauth.tar files.
Note You can use customized web pages only for the login pages. Login and logout error pages
cannot be customized.
• External—Redirects users to an external server for authentication. If you choose this option, you
must also enter the URL of the external server in the URL field.
Note If details for the external server are not already defined, you can configure them on the
RADIUS Authentication Servers page or the TACACS+ Authentication Servers page.
Step 25 Click Apply to commit your changes.
Step 26 Click Save Configuration to save your changes.
Step 27 Repeat this process if a second (anchor) controller is being used in the network.
Using the CLI to Configure Wired Guest Access
Using the controller CLI, follow these steps to configure wired guest user access on your network.
Step 1 To create a dynamic interface (VLAN) for wired guest user access, enter this command:
config interface create interface_name vlan_id
Step 2 If a link aggregation trunk is not configured, enter this command to map a physical port to the interface:
config interface port interface_name primary_port {secondary_port}
Step 3 To enable or disable the guest LAN VLAN, enter this command:
config interface guest-lan interface_name {enable | disable}
This VLAN is later associated with the ingress interface created in Step 5.
Commentaires sur ces manuels