Information for the Customer to Consider Before Cloudpath is Deployed

Before Cloudpath is implemented into the customer network, the following network configurations should be considered:

  • The initial firewall configuration should be set up to allow access to your assigned Cloudpath server which is specified in the server activation email. This is usually specified as:

    onboard(x).cloudpath.net

    Note: Internally, the guest/onboarding VLAN needs to be able to access the wireless controller (this can be locked down to specific ports after the initial setup).
  • If using Active Directory for user authentication, you need the AD domain information (plus any subdomains) and the IP address of the AD server. AD groups should be set up before the implementation call.
    • The Cloudpath server should have Layer 3 access to Active Directory (port 636).
    • The AD server should be configured to allow LDAP queries.
  • Your wireless controller must be WPA2-Enterprise capable.
  • You should have knowledge about how to configure a captive portal on your wireless controller(s).
    • The open SSID typically has pre-authentication ACLs defined, which permit access to the VM.
    • The WLAN controller is configured to point to the Cloudpath VM as an external captive portal.
  • The WPA2-Enterprise SSID should be set up to delegate authentication to the onboard AAA server or your existing AAA.
    Note: If using an existing AAA server, it requires layer 3 access to the Cloudpath VM to verify certificate status (optional).
  • If using NPS, set up the NPS server role and a RADIUS server.
    Note: The new RADIUS server certificates and root CA can be uploaded after Cloudpath is configured.
  • If using a pre-existing RADIUS server, you need the IP address and access to the RADIUS server-signed certificates.
  • If using an existing CA, and you would like to use Cloudpath as an intermediate CA to issue client certificates, you need the public and private key of the existing CA to upload into Cloudpath.
  • If using Cloudpath as a proxy for an existing CA (Microsoft CA or Custom External CA) you need the CA URL and CA chain for the remote CA.
  • DNS should be configured for Cloudpath and other components appropriate for your network.
  • You should have a general idea about your deployment scheme for employees, partners, contractors and guests.