Using the Timed Access Workflow Template

You can the Timed Access workflow template to create a workflow that allows limited-time access for a user based on MAC address authentication.

The main concept of the Timed Access workflow template is to give users free access to a network connection for a limited time period, and, when that time period expires, they can re-enroll their device to one of the a pre-configured "premium" lists. You can use other workflow plug-ins to add steps to this workflow, and in fact that is how the Timed Access template is intended to be used. An example of a useful plug-in that works well with this template is described later in this section.

The procedure below demonstrates how to create a Timed Access workflow.
  1. Go to Configuration > Workflows.
  2. On the right hand side of the Workflow page, click Add Workflow, then, with the "Create a new Workflow" button selected, click Next.
    The Create Workflow screen is displayed:

    Create Workflow Screen - Selecting "Timed Access" For Workflow Template Type

  3. On the Create Workflow screen, enter a Display Name and Description.
  4. From the Workflow Template Type drop-down list, select "Timed Access."
  5. Fill out the URL Name field.
  6. Click Save, and you are returned to the workflow page that is shown in the following figure.

    Timed Access Workflow After Initial Creation

  7. Expand the workflow to show its complete logic by clicking Non Premium User, then clicking Free/Premium User, then clicking Premium Registration. The workflow appears as shown in the following figure:

    Timed Access Workflow Fully Expanded

    The following MAC registration lists are automatically created by this workflow template, and can be viewed in the Configuration > MAC Registrations portion of the UI:

    • Premium List - 1day
    • Premium List - 1hr
    • Premium List - 30min
    • Free List

Free User Registration

The Free User Registration branch is exposed to users only when they enroll for the first time within a 24-hour period. The Free List is pre-configured to have a 30-minute expiration; this list is automatically cleaned up every 24 hours so that users can again use the Free User Registration branch again in the next 24-hour period.

Workflow Logic:

To understand workflow logic and how the user gets presented with various steps, it is essential to know how "First match in" and "All matches in" work during user enrollment:

  • "First match in:" The first branch (going from left to right in the workflow) where the criteria being evaluated matches that of the user is used automatically.
  • "All matches in:" All branches are evaluated to determine if the criteria being evaluated matches that of the user. After this determination has been calculated, all options that are a match are offered to the user, and the user can select an option from the choices presented. If only one match occurs, the matching branch is used automatically.
The basic steps shown in this workflow are described in the following table.
Note: In the UI, be sure to use your cursor to hover over the text of each workflow step, and the logic of each possible option is described.

Description of Steps in Timed Access Workflow Template

Step 1 Acceptable Use Policy.
Step 2 First match in:
  • Premium User: An enrollment whose MAC address is already registered in one of the three premium lists is taken down this branch. This branch is never available to a first-time enrollment in a 24-hour period. If this option is a match, the enrollment then goes directly to the device configuration (Result step).
  • Non Premium User: Any enrollment that does not match the "Premium User" criteria is taken down this branch. A first-time enrollment in a new 24-hour period is taken down this branch.
Step 3 First match in:
  • Free User: An enrollment whose MAC address is already registered in the Free List (and has not yet expired) is taken down this branch. If this option is a match, the enrollment then goes directly to the device configuration (Result step).
  • Free/Premium User: Any enrollment that does not match the "Free User" criteria is taken down this branch.
Step 4 All matches in:
  • Free User Registration: Presented if the MAC address is not currently in the Free List, nor is the MAC address marked as "expired" or "revoked" in the Free List. If this branch is chosen, the MAC address is registered to the Free List and the enrollment is assigned a device configuration (Result step).
  • Premium Registration: Available to all enrollments

A first-time enrollment (for a new 24-hour period) will either be presented with both options or will be taken down the Premium Registration branch.

Step 5 All matches in:
  • 30 min: Available to all enrollments
  • 1 hour: Available to all enrollments
  • 1 day: Available to all enrollments

These options are presented to all enrollments who have gone down the Premium Registration branch. The user makes a selection, and the enrollment proceeds with the MAC address getting registered.

Step 6 Register the MAC address: The MAC address is registered in the selected premium MAC Registration list.

You can determine what other steps you want to include in your workflow. For example, a "Charge user for service" step would fit well within a workflow where timed access is involved. You could insert such a step before the MAC Registration step. (Refer to the "Charge User for Service" topic in the Cloudpath Enrollment System Deployment Administration Guide.)