Security

 View Only
  • 1.  External Captive Portals on AOS10

    Posted Nov 09, 2023 04:22 PM

    Hi

    I have been considering updating to AOS10 on Aruba Central for our Wifi and i've created a group just to test to see the differences.
    One thing I have noticed is that the Internal Captive has now been removed and only Cloud Guest or External Captive Portal are now the only 2 options.

    We currently use the Internal Captive Portal with Radius and Active Directory (I do find it quite slow to authorise and also it will never remember anyone if they have disconnected for a few minutes)

    I was wondering what other people use to create their external captive portals?
    I'm looking at creating an AD authentication page (Also so it will report to our content filtering for reporting as I work in education) 
    I did look to create a WPA2 Enterprise SSID where it can forward to the Splash page using a Role when they connect.

    Thanks for any help.



  • 2.  RE: External Captive Portals on AOS10

    Posted Nov 09, 2023 05:09 PM
    Edited by sukumar Nov 09, 2023 05:10 PM

    Hi

    Internal Captive Portal is no longer available as an option in AOS 10. Moving forward, we have two alternatives:

    If you have ClearPass or any Policy Manager, including NPS, you can host an external captive portal.

    We have many customers using Cloud Guest for hosting their captive portal. There are multiple customization and authentication options made easy with authentication on Central. Check for sponsor approval workflow which might match your current guest authorization process. 

    While forwarding the user to Splash Page post dot1x is achievable through user role, just curious to understand the use case. 



    ------------------------------
    Sukumar Krishnamoorthy
    ------------------------------



  • 3.  RE: External Captive Portals on AOS10

    Posted Nov 10, 2023 04:18 AM

    Hi Sukumar

    Thanks for your reply.

    We need to have a guest SSID for the staff and students which we need to allow them to login to.  
    Current we use the internal splash page with AD Authentication - (We also send the Accounting Token back for monitoring of Internet usage for safeguarding)

    We do have NPS setup on our Domain Controllers already, so I would be able to use this for an External Captive Portal.
    I did look at using NPS with WPA 2 or 3 Enterprise, but I wasn't sure what to use for the external captive portal, that's why I would see what other people use for this.


    I have looked at the Cloud Guest, I currently use it for Visitors who don't have an AD Account, but I couldn't see any options for AD auth in there.

    Thanks




  • 4.  RE: External Captive Portals on AOS10

    Posted Nov 13, 2023 10:35 PM

    Hi Tim,

     

    Thank you for providing the details.

     

    Currently, AD authentication with Cloud Guest Portal is not supported. Only anonymous, username and password on central & social logins are currently supported.

     

    If you have NPS, we recommend using WPA2/3 for 802.1x authentication. Setting this up should be straightforward if you already have the certificate service installed on the NPS server.

     

    Alternatively, if you prefer using the Captive Portal, you can host the Captive Portal page on an external web server or on your Windows server. There are several community posts that explain the HTML code to support captive portal authentication. Please check the following links for more information:

    https://community.arubanetworks.com/discussion/iap-external-captive-portal-html-code

    https://community.arubanetworks.com/discussion/configure-captive-portal-with-html-page-to-authenticate-with-radius-server

     

    Currently, the default certificate on the access points is securelogin.hpe.com. If a custom certificate is used, please use the certificate name.

     

    Sukumar Krishnamoorthy