Captive Portal Authentication (External Web Authentication)
To equip the ICX switch to handle the HTTP redirection mechanism, configuration details specific to the NAC server such as virtual IP address, HTTP or HTTPS protocol port number, and login page details hosted on the NAC server must be specified on the switch. Upon receiving the redirected web access request, the NAC server honors the login page to the client which in turn submits the user login credentials. The NAC server reverts the credentials and sends the username, password, and default URL of the web page to the network-attached storage (NAS) or switch.
- For the RUCKUS Cloudpath server, refer to the Cloudpath ES 5.2 Deployment Guide (at this URL: https://support.ruckuswireless.com/documents/2006).
- For the Aruba ClearPass server, refer to the Aruba ClearPass Guest User Guide. Refer to the ClearPass Guest 6.4 User Guide, as the version used for validation is 6.4.
- For the Cisco ISE server, refer to Cisco Identity Services Engine documentation.
The ICX switch makes use of the credentials for initiating the authentication process through the RADIUS server, which is integrated with NAC server.
The RADIUS server validates the user credential information and, if the client is authenticated, the client is redirected to the URL provided by the server. For information about re-authentication and login failure behavior, refer to Re-authentication Period and Web Authentication Cycle.