Working with Internal Captive Portal Engine Rules

When configuring captive portal, the ExtremeCloud IQ Controller Rules Engine creates default rules for network policy. Use the default rules and modify the Accept Policy when necessary.

  1. Go to Onboard > Rules.
    Two new engine rules are displayed:
    • Unregistered LOC: Network: Test1- ICP (SSID of network)

      Prior to CP authentication, the client matches this rule and applies the Accept Policy of a non-authenticated role.

    • Web Authenticated LOC: Network: Test1- ICP (SSID of network)

      Once the client password is authenticated on the RADIUS server, the client matches this rule and applies the Accept Policy of the Enterprise User role.

      The Enterprise User is the default Accept Policy.

    Alternatively, you can create unique Accept Policy roles to be assigned upon authentication.
    1. Select the rule Web Authenticated LOC: Network: Test1- ICP and click to edit.
    2. From the Accept Policy field select a different value.
  2. Click Save.

Next, modify the device group profile to enable the network and role options we are using.