Configuring ZoneDirector

This section includes tables of configuration fields and values for setting up the ZoneDirector Controller. For more information, such as how to navigate the ZoneDirector UI, how to find more information about configuration fields, and to view screen shots of the ZoneDirector UI, refer to the RUCKUS ZoneDirector User Guide.

Note: For any configuration fields that are not described in the following sections, you can use their default values.

Setting up Cloudpath as an AAA RADIUS Authentication Server

Fields/Values to Use for ZoneDirector AAA Authentication Service

Configuration Field Corresponding Value
Name Name: Any descriptive name for the AAA authentication service
Type RADIUS
Auth Method PAP
IP Address The IP address of the Cloudpath Enrollment System.
Port 1812 is typically used and is the default.
Shared Secret This must match the shared secret for the Cloudpath ES onboard RADIUS server (Configuration > RADIUS Server).
Confirm Secret Confirm Secret: The shared secret (entered again).

Creating AAA RADIUS Accounting Server (Optional)

Fields/Values to Use for ZoneDirector AAA Accounting Service

Configuration Field Corresponding Value
Name Name: Any descriptive name for the AAA accounting service
Type RADIUS ACCOUNTUING
Auth Method PAP
IP Address The IP address of the Cloudpath Enrollment System.
Port 1813 is typically used and is the default.
Shared Secret This must match the shared secret for the Cloudpath ES onboard RADIUS server (Configuration > RADIUS Server).
Confirm Secret Confirm Secret: The shared secret (entered again).

Testing AAA Servers

To test the connection between the controller and the Cloudpath RADIUS server, RUCKUS strongly recommends testing the AAA server after you set it up. Refer to the instructions in the RUCKUS ZoneDirector User Guide.

Creating a Hotspot (WISPr) Portal

Fields/Values to Use for Creating a Hotspot (WISPr) Portal

Creating a Hotspot (WISPr) Portal section in ZoneDirector UI Configuration Field and Corresponding Value
Top portion of configuration fields area Name: Any descriptive name for the hotspot portal.
Redirection Login URL: Select "External."
Login Page Redirect unauthenticated user: The Cloudpath Enrollment Portal URL, which should be contained in the applicable workflow in the Cloudpath UI (Configuration > Workflows).
Start Page After user is authenticated,: Select "Redirect to the URL that the user intends to visit." This lets you set a different page where users will be redirected (for example, your company website). Enter a domain name or an IP address for the redirection.
Authentication/Accounting Servers (Authentication tab) Authentication Server: Drop-down list to select the Cloudpath RADIUS Authentication Server.
Note: Enabling this option allows users with registered MAC addresses to be transparently authorized without having to log in. A user entry on the RADIUS server needs to be created using the client MAC address as both the user name and password. For the MAC address format, RUCKUS recommends using AA:BB:CC:DD:EE:FF.
Authentication/Accounting Servers (Authentication tab) Accounting Server: Drop-down list to select the Cloudpath RADIUS Accounting Server (if applicable).

Setting Up the Walled Garden

To add a walled garden configuration to your existing Hotspot Services, refer to the instructions in the RUCKUS ZoneDirector User Guide.

Also, when configuring the walled garden, include the following steps:

  1. Include the DNS or IP address of the Cloudpath system, then click OK
  2. Optionally, there are some domains that you can add to the walled garden on all controllers to:
    • Prevent the Apple CNA mini-browser from appearing on Apple devices.
    • Avoid being blocked or slowed when attempting to download the Cloudpath wizard.
      Note: There will still be about a 15-to-20-second delay when the full application is 33 percent complete (about 40 MB) in its download.

      The recommended destinations to add for the walled garden are:

      *.ggpht.com
      *.play.googleapis.com
      *.googleapis.com
      *.play.google.com
      android.clients.google.com
      *.gvt1.com
      connectivitycheck.android.com
      connectivitiycheck.google.com
      *.gstatic.com
      *.clients3.google.com
      *.thawte.com
      

      Note: The *thawte.com destination is the OCSP URL of the SSL certificate of the Cloudpath server. This URL can be found by clicking the lock icon in your web browser and viewing the details of your certificate.
  3. If you are still experiencing issues, you can try adding the following destinations to the walled garden:
    *.clients.google.com
    *.l.google.com
    *.googleusercontent.com
    *.appengine.google.com
    *.cloud.google.com
    *.android.com
    *.cloudfront.net
    *.akamaihd.net
    172.217.0.0/16
    216.58.0.0/16
    

Creating the Onboarding SSID

Fields/Values to Use for ZoneDirector Onboarding SSID

Creating a WLAN Configuration (for Onboarding SSID) section in ZoneDirector UI Configuration Field and Corresponding Value
General Options Name/ESSID: Name of the SSID
Zone: Zone in which the WLAN will reside
WLAN Usages Type: Hotspot (WISPr)
Authentication Options Method: Open
Encryption Options Method: None
Options Hotspot Services Drop-down list to selet the already-created hotspot service.
Note: RUCKUS recommends enabling the "Bypass Apple CNA" feature. For instructions, refer to the RUCKUS ZoneDirector User Guide.