Users Guide

Table Of Contents
306 | Captive Portal Dell PowerConnect ArubaOS 5.0 | [User Guide
Creating an Auth-guest User Role
The auth-guest user role consists of the following ordered policies:
z cplogout is a predefined policy that allows captive portal logout.
z guest-logon-access is a policy that you create with the following rules:
Allows DHCP exchanges between the user and the DHCP server during business hours while blocking
other users from responding to DHCP requests.
Allows DNS exchanges between the user and the public DNS server during business hours. Traffic is
source-NATed using the IP interface of the controller for the VLAN.
z block-internal-access is a policy that you create that denies user access to the internal networks.
z auth-guest-access is a policy that you create with the following rules:
Allows DHCP exchanges between the user and the DHCP server during business hours while blocking
other users from responding to DHCP requests.
Allows DNS exchanges between the user and the public DNS server during business hours. Traffic is
source-NATed using the IP interface of the controller for the VLAN.
Allows HTTP/S traffic from the user during business hours. Traffic is source-NATed using the I interface
of the controller for the VLAN.
z drop-and-log is a policy that you create that denies all traffic and logs the attempted network access.
Configure Policies and Roles via the WebUI
Time Range
To create a time range via the WebUI:
1. Navigate to the Configuration > Security > Access Control > Time Ranges page to define the time range
“working-hours”.
2. Click Add.
a. For Name, enter working-hours.
b. For Type, select Periodic.
c. Click Add.
d. For Start Day, click Weekday.
e. For Start Time, enter 07:30.
f. For End Time, enter 17:00.
g. Click Done.
3. Click Apply.
To create the guest-logon-access policy via the WebUI:
1. Navigate to the Configuration > Security > Access Control > Policies page.
2. Select Add to add the guest-logon-access policy.
3. For Policy Name, enter guest-logon-access.
4. For Policy Type, select IPv4 Session.
5. Under Rules, select Add to add rules for the policy.
a. Under Source, select user.
b. Under Destination, select any.
c. Under Service, select udp. Enter 68.
d. Under Action, select drop.