Cloud User Group Settings

When you configure a user group for an Enterprise 802.1X SSID, the password database always resides in the cloud. For a user group for a Private Pre-Shared Key (PPSK) SSID, the password database can reside in the cloud or on all SSID APs. The following settings are available when you configure a cloud-based user group.

Table 1. Settings for Cloud User Groups
Setting Description
User Group Name Type a name for the user group.
Password DB Location Select Cloud for a cloud-resident password database.
Password Type Select PPSK or RADIUS.
Description Type an optional Description for the user group.
Enable CWP Register Select Enable CWP Register to require users in this user group to log in using a captive web portal.

Available only if a captive web portal is enabled for this SSID.

PCG Use (Optional) Available only for the PPSK password type.

Select Enable use for Private Client Group.

Password Settings
Generate Password Using (Required)

Select any combination of characters that you want to include in the password: Letters, Numbers, and Special Characters.

Enforce the use of Select one of the password enforcement options from the menu:
  • All selected character types
  • Any selected character types
  • Only one character type
PSK Generation Method Available only for the PPSK password type.

Select Password Only or User String Password from the menu. With the User String Password option, you can include the user name and a string of characters in front of the generated Private PSKs.

If the password generation method is Password Only, then the PPSK password can be between eight and 63 characters. If the generation method is User + String + Password, the maximum passphrase for the Private PSK can be between eight and 31 characters.

Generated Password Length Select the length for automatically-generated passwords for this user group. Range: 8–63
Concatenating String Available only for the User String Password PSK Generation Method. Range: 0–8

Use this string to generate PPSKs as User name + Character String + Password. For example, if you enter Extreme, as the string, then the generated PPSKs are <User name>Extreme<Password>.

Expiration Settings
Account Expiration Select one of the options from the menu:
  • Never Expire
  • Valid During Dates

    Use the calendar and time controls to specify the Start and End dates and times.

  • Valid For Time Period

    Specify the time period for which the password is valid after ID Creation or First Login. Type the number of hours, days, or weeks. Select the unit of time and the after-condition from the menus.

    Optionally, select Renew user credentials. To delete credentials after a specific time period, select Delete credentials after, type a value, and then select the unit of time from the menu.

  • Daily

    Use the Start and End controls to specify the daily time period.

Action at Expiration Not available for accounts set to never expire.

Select Access Rejected to have ExtremeCloud IQ block users from renewing their credentials.

Select Show Expiration Message to have ExtremeCloud IQ present to users an on-screen prompt that they can use to renew their credentials.

Delivery Settings
Deliver Access Key by Select the methods for delivery of the access key. Select one or both:
  • Text Messages (SMS)
  • Email

Use the menus to select an email template for each method.