Secure Access Solution
10.4.2602
Search this version
Secure Access Solution
Secure Access Solution
3rd Party Integration
Title
Message
Create new category
What is the title of your new category?
Edit page index title
What is the title of the page index?
Edit category
What is the new title of your category?
Edit link
What is the new title and URL of your link?
Captive Portal Configuration
Summarize Page
Copy Markdown
Open in ChatGPT
Open in Claude
Configure Captive Portal Profile
For DNAT supported Vendor
To configure Access Rules for Network Vendors that support DNAT (ex: Aruba), perform the below steps:
- On Access Profiles tab, create a Access Profile for Captive Portal
- On Aruba drop-down, declare a values (ex: ORG_B_2084RDR) for Aruba-User-Role attributes

- On Rules tab, add a new Rule and select to assign to the above Captive Portal profile

- On the Network Vendor (ex: Aruba) console, create an ACL (Network Access Control List) to forward traffic to your NAC Edge.

For VLAN supported Vendor
To configure Access Rules for Network Vendors that support VLAN redirect (ex: Cisco), perform the below steps:
- On Access Profiles tab, create a Access Profile for Captive Portal
- On Cisco dropdown, declare a value (ex: 1776) for Tunnel-Private-Group-Id attribute

- Config redirect for VLAN
Pre-condition: a Layer 3 router or switch with ACL (Access Control List) and Policy Routing capabilities is required. The configuration will involve the following sections:
- ACL and Policy Map on Router
Bash
x
ip access-list extended Non_Redirect #create ip access extendedpermit udp any any eq domainpermit udp any any eq bootpsroute-map CloudNac_Quarantine deny 10 #create route mapmatch ip address Non_Redirectroute-map CloudNac_Quarantine permit 20set ip next-hop 10.40.177.85 #IP Address of NAC Edge#Apply route map into Routerinterface GigabitEthernet0_0.1796description Wireless Quarantine Subnetencapsulation dot1Q 1796ip address 10.40.179.65 255.255.255.240ip helper-address 10.40.177.94 #DHCP Server in outside of this vlanno ip route-cacheip policy route-map CloudNac_Quarantine #Apply route map CloudNac_QuarantineHow to verify
- Using a test device & Connect to the Network
- If the agent is not installed on that machine, the browser will be redirect to a remediation page, prompting the user to install Agent.

Note: For Apple devices, IT admin can make use of DHCP option 114 on Windows DHCP server to get NAC integrated with Apple CNA (Captive Network Assistant),
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
Last updated on
Was this page helpful?
Next to read:
Configure EAP-TLS for Cloud RADIUS AuthenticationDiscard Changes
Do you want to discard your current changes and overwrite with the template?
Archive Synced Block
Message
Create new Template
What is this template's title?
Delete Template
Message
