Configuring Virtual SmartZone

This section includes tables of configuration fields and values for setting up the Vitrual SmartZone (vSmartZone) Controller. For more information, such as how to navigate the vSmartZone UI, how to find more information about configuration fields, and to view screen shots of the vSmartZone UI, refer to the RUCKUS SmartZone 300 and Virtual SmartZone-High Scale Administrator Guide.

Note: For any configuration fields that are not described in the following sections, you can use their default values.

Setting up Cloudpath as an AAA RADIUS Authentication Server

Fields/Values to Use for vSmartZone AAA Authentication Service

AAA Authentication Service Section in vSmartZone UI Configuration Field and Corresponding Value
General Options Name: Any descriptive name for the AAA authentication service
Type: RADIUS
Primary Server IP Address: The IP address of the Cloudpath Enrollment System.
Port: 1812 is typically used and is the default.
Shared Secret: This must match the shared secret for the Cloudpath ES onboard RADIUS server (Configuration > RADIUS Server).
Confirm Secret: The shared secret (entered again).

Creating AAA RADIUS Accounting Server (Optional)

Fields/Values to Use for SmartZone AAA Accounting Service

AAA Accounting Service Section in vSmartZone UI Configuration Field and Corresponding Value
General Options Name: Any descriptive name for the AAA accounting service
Type: RADIUS ACCOUNTING
Primary Server IP Address: The IP address of the Cloudpath Enrollment System.
Port: 1813 is typically used and is the default.
Shared Secret: This must match the shared secret for the Cloudpath ES onboard RADIUS server (Configuration > RADIUS Server).
Confirm Secret: The shared secret (entered again).

Testing AAA Servers

To test the connection between the controller and the Cloudpath RADIUS server, RUCKUS strongly recommends testing the AAA server after you set it up. Refer to the instructions in the RUCKUS SmartZone 300 and Virtual SmartZone-High Scale Administrator Guide.

Creating a Hotspot (WISPr) Portal

Fields/Values to Use for Creating a Hotspot (WISPr) Portal

Creating a Hotspot (WISPr) Portal section in vSmartZone UI Configuration Field and Corresponding Value
General Options Portal Name: Any descriptive name for the hotspot portal.
Redirection Login URL: Select "External."
Redirect unauthenticated user: The Cloudpath Enrollment Portal URL, which should be contained in the applicable workflow in the Cloudpath UI (Configuration > Workflows).
Start Page: After user is authenticated,: Select "Redirect to the URL that the user intends to visit." This lets you set a different page where users will be redirected (for example, your company website). Enter a domain name or an IP address for the redirection.

Setting Up the Walled Garden

To add a walled garden configuration to your existing Hotspot Services, refer to the instructions in the RUCKUS SmartZone 300 and Virtual SmartZone-High Scale Administrator Guide.

Also, when configuring the walled garden, include the following steps:

  1. Include the DNS or IP address of the Cloudpath system, then click OK
  2. Optionally, there are some domains that you can add to the walled garden on all controllers to:
    • Prevent the Apple CNA mini-browser from appearing on Apple devices.
    • Avoid being blocked or slowed when attempting to download the Cloudpath wizard.
      Note: There will still be about a 15-to-20-second delay when the full application is 33 percent complete (about 40 MB) in its download.

      The recommended destinations to add for the walled garden are:

      *.ggpht.com
      *.play.googleapis.com
      *.googleapis.com
      *.play.google.com
      android.clients.google.com
      *.gvt1.com
      connectivitycheck.android.com
      connectivitiycheck.google.com
      *.gstatic.com
      *.clients3.google.com
      *.thawte.com
      

      Note: The *thawte.com destination is the OCSP URL of the SSL certificate of the Cloudpath server. This URL can be found by clicking the lock icon in your web browser and viewing the details of your certificate.
  3. If you are still experiencing issues, you can try adding the following destinations to the walled garden:
    *.clients.google.com
    *.l.google.com
    *.googleusercontent.com
    *.appengine.google.com
    *.cloud.google.com
    *.android.com
    *.cloudfront.net
    *.akamaihd.net
    172.217.0.0/16
    216.58.0.0/16
    

Creating the Onboarding SSID

Fields/Values to Use for SmartZone Onboarding SSID

Creating a WLAN Configuration (for Onboarding SSID) section in vSmartZone UI Configuration Field and Corresponding Value
General Options Name: Name of the SSID
SSID: Name of the WLAN
Zone: Zone in which the WLAN will reside
WLAN Group: Group in which the WLAN will reside
Authentication Options Authentication Type: Hotspot (WISPr)
Method: MAC Address
MAC Authentication: Unchecked
MAC Address Format: Recommended format is AA:BB:CC:DD:EE:FF
Encryption options Method: None
Hotspot Portal Hotspot (WISPr) Portal: Drop-down list to selet the already-created hotspot service.
Bypass CNA: Enable
Authentication Server: Drop-down list to select the Cloudpath RADIUS Authentication Server
Accounting Server: Drop-down list to select the Cloudpath RADIUS Accounting Server