Setting Up SSIDs
Cloudpath requires an open SSID for onboarding, and one or more secure SSIDs, depending on your deployment scheme. The open SSID terminates to a captive portal that points to Cloudpath, and the secure SSID is the network to which your users migrate. We recommend creating an SSID specifically for Cloudpath.
Configure the secure SSID to use TLS, and point the RADIUS authentication requests to the RADIUS sever, whether that is the Cloudpath onboard RADIUS server, a Microsoft NPS, or other external RADIUS server.
Guest SSID
If your security policy provides a guest SSID for Internet-only or limited network access, you can set up an open SSID specifically for guests. The guest SSID redirects guest users to the Cloudpath captive portal, where they can onboard to a limited access network. The limited access is managed using VLAN assignment, which is configured in the wireless LAN controller, where you can also filter, shape or throttle the guest VLAN.
Conflicting SSIDs
Cloudpath provides a method for managing conflicting SSIDs to prevent a device from roaming away from the secure network. When setting up the device configuration, in the conflicting SSID section, you can set it up to either delete the open SSID or set it to connect manually. See Device Configuration and Client Certificate.