Users Guide

Table Of Contents
Dell PowerConnect ArubaOS 5.0 | User Guide] Captive Portal | 299
Chapter 12
Captive Portal
Captive portal is one of the methods of authentication supported by ArubaOS. A captive portal presents a web
page which requires action on the part of the user before network access is granted. The required action can be
simply viewing and agreeing to an acceptable use policy, or entering a user ID and password which must be
validated against a database of authorized users.
You can also configure captive portal to allow clients to download the Dell VPN dialer for Microsoft VPN clients
if the VPN is to be terminated on the Dell controller. For more information about the VPN dialer, see Chapter
15, “Virtual Private Networks.
This chapter describes the following topics:
z “Captive Portal Overview” on page299
z “Captive Portal in the Base ArubaOS” on page300
z “Captive Portal with the PEFNG License” on page302
z “Example Authentication with Captive Portal” on page305
z “Guest VLANs” on page311
z “Captive Portal Authentication” on page312
z “Optional Captive Portal Configurations” on page316
z “Personalizing the Captive Portal Page” on page320
Captive Portal Overview
You can configure captive portal for guest users, where no authentication is required, or for registered users who
must be authenticated against an external server or the controller’s internal database.
You can use captive portal for guest and registered users at the same time. The default captive portal web page
provided with ArubaOS displays login prompts for both registered users and guests. (You can customize the
default captive portal page, as described in “Personalizing the Captive Portal Page” on page320)
You can also load up to 16 different customized login pages into the controller. The login page displayed is based
on the SSID to which the client associates.
Policy Enforcement Firewall Next Generation (PEFNG) License
You can use captive portal with or without the PEFNG license installed in the controller. The PEFNG license
provides identity-based security to wired and wireless clients through user roles and firewall rules. You must
purchase and install the PEFNG license on the controller to use identity-based security features.
Note: While you can use captive portal to authenticate users, it does not provide for encryption of user data and should not be
used in networks where data security is required. Captive portal is most often used for guest access, access to open systems
(such as public hot spots), or as a way to connect to a VPN.