Captive Portal Help

Hello All,
working with the RV180W and a Ubuntu server I have established a FreeRADIUS server and have it setup for PEAP authentication based on a users file with NTLM encrypted passwords.  This is working pretty well, however I have one problem.  My certificates are self-signed and windows freaks out over it (all mobile OS's, OSX, and Linux work fine).  I'm trying to investigate other options and right now I'm curious, is there any way for the RV180W to use a captive portal setup that isn't the one built in? or is there any way to have the users be authenticated against the radius server I already have rather than setting them up on the router?  I'm open to other suggestions, but I'm trying to avoid paying for certs (I know they aren't incredibly expensive but this is mostly for home use/development/learning) so paying for certs aren't worth it and wanted to see if this was an option.  I will also accept the option of hosting a wireless network that is open but only goes to a page to download an XML & batch file which can be run to add the wireless network to the system (I have this working from USB atm, but trying to develop self-serve options)
Thanks in advance... P.S. very happy with this router so far! its great!

Hi Lucas,
I was looking for a solution with my colleagues from the Support Center, but I am afraid the answer of what you ask is no - you can only use the internal database of the router, when using the Captive portal.
Can you use a Captive portal that isnt' the build in? Theoretically yes, if the users in the LAN has as gateway a machine with a captive portal, which will make the radius authentication and only after that will forward the trafic to RV180 and inet.. Unfortunately I cant offer you a practical configuration on this.
If meanwhile you find another solution, please chare it with us
Regards,
Kremena

Similar Messages

  • ISE captive portal timeouts and radio policy

    Hello!
    I have two questions.
    First, have some of you guys worked with the captive portal in ISE (guestportal)?
    I have set up a new wireless network for a customer and they want to use the guest portal for som users.
    The problem that I am expering is that on a particular site with many small buildings user complains that they have to reauthenticate using the webportal when moving between the buildnings.
    I have tired extending the idle user timeout on that particular wlan in the cisco 5508, but I still having this problem.
    I would actually like if the user login via the guestportal at the beginning of the work day and after say 4-5 hours they have to reautencitcate.
    And if they loose network connectivity (moving between buildings, iphone/andriod shutting down wifi adapter, etc) they shuld be fine connecting again because they have aldready authecnticated once during the last 4-5 hours.
    Is this possible via the ISE?
    My second question deals with 2.4 and 5 Ghz band.
    I use AP groups on each of my distribution areas. All groups have the same SSID but diffrenet egress interfaces (interfaces groups).
    And in some of these I want to save the 5 GHz band for voice over wlan and in others i would like to use both bands.
    Do I have to create diffrent wlan profiles with diffrent radio policys and same SSID or could I do this in the AP group settings using RF-profiles?
    Hope for some help!
    //Simon

    Your first answer  is there is no such option in ISE till now there you can specify the login time fix for a client. If the client disconnect from the network and reconnect again, it require re-authentication Every time.
    2nd : You can use the AP group settings using RF-profiles to achieve this task.1st: There is no such option in ISE till now there you can specify the login time fix for a client. If the client disconnect from the network and reconnect again, it require re-authentication Every time.
    your seconde answer : You can use the AP group settings using RF-profiles to achieve this task.

  • Laptop no longer loads Captive Portal following Windows 8.1 upgrade

    Since upgrading to Win 8.1 from Win 8, I no longer see a captive portal displayed whenever I try to connect to a wireless network that requires additional login information.  Some WiFi networks require you to click their Terms and Conditions box
    or add some additional logon information and they splash up a Captive Portal screen to allow you to enter the information.  Without entering this information I receive an IP address for my wireless adapter ok, but end up with a "Limited Internet"
    connection.  Which means I cannot connect to the Internet at all.  This exact same problem has happened to two colleagues of mine that recently upgraded to Windows 8.1 on their laptops.  Any help will be much appreciated.

    Hello Grantlsmith,
    Do you receive any error message when you connect to a wireless network that requires additional login information?
    Or you just connect to the Wi-Fi with limited Internet, and nothing pop up?
    Please take the following steps for troubleshooting:
    1. Please provide the result of the command ipconfig –all
    2. Ping the IP address of URL and check if we can contact.
    3. Type in the URL that can use in Windows 8 and check if we can open the Captive Portal
    Best regards,
    Fangzhou CHEN
    Fangzhou CHEN
    TechNet Community Support

  • How can I change the re-direct URL on the WebKit for Captive Portals?

    Hi,
    I have a guest network at the office that is configured with a captive portal for authentication. My MBP detects that it is behind a Captive Portal when the HTTP WISPr request fails and launches the WebKit (ie. the CNA) as designed and displays the login page. When the login is successful, the Captive Portal displays a success and the WebKit then proceeds to re-direct the browser to http://www.apple.com
    Of late, Apple's homepage has become graphic rich and more often than not, loading the page without caching (since the webkit does not cache the webpage loaded) loading Apple's homepage on the guest network takes over 30-90 seconds depending on the traffic on the network. The OS does not allow me to use the network till the page on the webkit has successfully loaded and the "Done" button appears on the webkit and this often becomes irritating.
    Is there a method to change the redirect URL to something less resource hungry like http://www.google.com or a less graphic rich Apple page (like http://www.apple.com/library/test/success.html)?
    I understand that there is a method to disable Captive Portal Handling, ie.
    sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.captive.control Active -boolean false
    However, I don't want to disable Captive Portal Handling in the OS as I don't believe Apps that require internet access will handle the lack of the internet well.
    Any hints would be appreciated.
    Cheers!

    Hey again,
    I did have a look at it and the Settings.plist file isn't very helpful for the issue I have.
    The file defines the probes and exceptions. So you have the default probe WISPr URL in there (http://www.apple.com/library/test/success.html) and the exceptions for specific SSIDs, as an example, attwifi is in the exception list and uses an alternate probe WISPr URL (http://attwifi.apple.com/library/test/success.html). The configuration does not have parameters that would be used by the CNA for the redirect to http://www.apple.com after a succesful Captive Portal login.
    Give it a shot on your laptop, get to a random public wifi like ATT Wifi/Starbucks/Guest Wifi's at office spaces/Boingo etc. and after the successful login, your CNA Webkit will re-direct to http://www.apple.com and the "Done" button won't appear till the page has completely loaded and stays as "Cancel" till the page is loaded.

  • WAP321 - Captive portal in 2 different VLAN

    Hi,
    I have a Wap321 installed in my network.  IP: 192.168.0.36 - VLAN 1
    If I'm in the local area network, I do not have any problem to use the wireless.
    I just added a guest VLAN for people who need Internet connection without LAN access. So I setup a second SSID and tag it with vlan 50. I can access to Internet.  But If I want active the captive portal, I'm unable to access to it because the adress is in the VLAN 1 (or 192.168.0.36).
    How I can setup my Wap321 to have the captive portal in the VLAN 50, not in the VLAN 1?
    Thank you               
    Alex

    Hello Alexandre,
    If you have a router upstream, please make sure that you have enabled inter-vlan routing in there. Also, on the WAP321, please configure the router's VLAN 1 IP address as the default gateway. With these settings, you should be able to use Captive Portal for both VLAN 1 and VLAN 50.
    Hope this helps.
    Regards,
    Nagaraja

  • Allowing Airwatch MDM access to the Captive-Portal guest users in pre-auth role for android and BB?

    Requirement:
    How to allow Airwatch MDM access to the Captive-Portal guest users in pre-authentication role for Android and Blackberry devices?
    What is Airwatch MDM?
    Airwatch MDM is Mobile Device Management. The Airwatch is an enterprise which helps to manage and secure data traveling through the mobile devices like Laptops, Tablets, Android, iPhones, iPads etc.
    Solution:
    Why we need to allow access to Airwatch MDM?
    The network administrator can force the guest users to register to Airwatch MDM before they get authenticated and access the internet. So that the network administrator could manage the guest devices through Airwatch Management tool. This can be achieved by CPPM server. To download the Airwatch MDM app and register with the Airwatch MDM server certain domains should be permitted in the captive portal pre-authentication role. This KB provides the configuration steps to allow the guest users to download the Airwatch MDM app and register with the Airwatch MDM server.
    Configuration:
    Below is the configuration
    Configuration steps:
    1. Create the following netdestinations
    netdestination Airwatch
      name *.awagent.com
      name *.awmdm.com
      name air-watch.com
    netdestination Google-Play
      name android.clients.google.com
      name .ggpht.com
      name gstatic.com
      name accounts.google.com
      name clients1.google.com
      name clients2.google.com
      name clients3.google.com
      name clients4.google.com
      name i.ytimg.com
      name google-analytics.com
      name .1e100.net
      name android.l.google.com
      name mtalk.google.com
      name clients.l.google.com
      name googleapis.com
      name gvt1.com
    netdestination BlackBerry
      name *.blackberry.com
    2. Now define the rules in the session acl and map it to the pre-authentication Role of the captive portal.
    ip access-list session Airwatch_Access
      any   alias Airwatch svc-http  permit
      any   alias Airwatch svc-https  permit
    ip access-list session Google-Play-Store
                   any   alias Google-Play any permit
    ip access-list session BlackBerry-Access
                   any   alias BlackBerry any permit
    3. Now map the session ACLs to captive-portal pre-authentication Role as follows
    user-role Guest-Pre-Auth-Role
     access-list session Airwatch_Access
     access-list session Google-Play-Store
     access-list session BlackBerry-Access
     access-list session logon-control
     access-list session captiveportal
    4. Now whitelist the list of domain names in the Captive Portal profle
    aaa authentication captive-portal Airwatch-Captive-Portal-Profile
    white-list Airwatch
    white-list Google-Play                                                                                ------------>Netdestinations where you defined the Domains.
    white-list BlackBerry
    Verification
    Now the user will be placed under the "Guest-Pre-Auth-Role" before the authentication. The user can now go the Google Play-Store or BlackBerry Appworld to download the Airwatch MDM and register to Airwatch Management Server.

    Thanks so much getting these names listed out. I have been working on this very issue for a few weeks and was basing my firewall rules on IP's. It was not going well. Now access is working and testing can commence!  Thanks,Chris

  • Wifi captive portal not working 10.10.2

    Just updated to 10.10.2 and cannot use FON or any other captive portal wifi. It does connect to the wifi router and dhcp completes, but I neither get the popup from apple, nor can i navigate to a login page from a browser.
    This is the first time in 6 years that OSX has been unusable for me but it is a disaster!

    After experimenting with the network assistant on my own FON portal I got to the point where it told me to restart my router. After that, I was able to connect. Obviously I cannot restart any other captive portal I come across, but pass this on in the hope that it helps.
    What does network assistant do just ahead of asking user to restart router - does it delete / reset anything specific?

  • IOS 6 Wi-Fi Issue (Campus Captive Portal)

    Hey there,
    I know some of people facing Wi-Fi connection problems after iOS 6 update.
    There are a lot of threads and solutions about this problem. But mine is bit different.
    I have an iPad and after i update to iOS 6 there wasn't any issue about Wi-Fi connection.
    I surfed all day long , upload and download many thing using my home Wi-Fi network.
    Today I couldn't connect to my campus' Wi-Fi network. I turned on my phone's hotspot
    and iPad connected to my phone's cellular based network just fine. I tried to connect directly with my phone to campus' network and my phone also connected just fine. When i searched the web i saw a lot of Wi-Fi issue thread about iOS 6. I have read all of them but my problem is bit different.
    My campus' network is using a Captive Portal thing to get internet access. So you have to enter your user id and password after you connect wirelessly.
    When i was using iOS 5.1.1 iPad was connecting to network automatically and waiting for me to open safari or chrome and enter my id and password.
    But now after i joined to network a window pops up and and wants me to enter id and password (not an apple page, my own university page) and at the same time connection drops and wi-fi icon get lost so my log-in info can't send. I open and wi-fi panel and connect again and same thing occurs. Pop-up window and connection lost. This is a vicious cycle i think and everybody using iOS 6 in my campus facing same problem. iPhone iPad iPod Touch users can not connect because of this problem.
    I have done everything that written about common Wi-Fi issue.
    I am sorry about my broken English BTW.
    Waiting for your help.

    If you experiencing the above subject heading, please read below
    Go to Settings, General, About
    Scroll down till you see Modem Firmware
    Reply Back with your Modem Firmware
    Modem Firmware: 04.12.02
    Wireless Access Point Device: NetGear WG102 which is superceded by NetGear WG103.
    I have Firmware 5.0 for this device
    Also check your IOS Version and (BUILD)
    If your Modem Firmware is LESS than the above, then you have the same problem as myself and many others with Wireless Connectivity issues to WAP's
    It is my understanding, unless im proven wrong by anyone with my above findings, this can only be fixed by APPLE. I have reported this as a BUG
    Please REPLY only to this thread if you're criteria is less than the MODEM FIRMWARE listed
    Im checking to see if i can be proven wrong in my findings.
    I have performed the below
    Backup Phone
    Factory Reset
    Network Reset
    Hard Reset
    Soft Reset
    Apply Store in Australia, Sydney CBD George St have tried the above with meand cant help either.
    Apple support via the phone cant help. This problem has now been logged as a BUG for the time being.

  • Auto pop-up for wispr in any captive portal won't work anymore

    Hi all,
    I really like the captive portal function. I am often at Starbucks, and I like the easy way to accept the user agreement.
    But, since some weeks, the auto pop-up to see the captive portal won't show ... neither Starbucks nor somewhere else!
    At Starbucks ....
    1. I tried to delete the btopenzone WiFi (the provider for Starbucks free WiFi) but nothing changed.
    2. I tried to set up another networking zone, won't help either.
    3. I searched the web, but all I could see is, that there is not really a way to disable it (but changing the website in plist somewhere).... 
    4. I  tried to find a way to just disable or enable it... but was not lucky
    Hope anyone can help me, cause I really like the feature.
    Thanks...
    Michael.

    Hi DelBaero,
    So, it sounds like push notifications are working intermittently. Take a look at the article linked below, not only does it give insight into how notifications work, it also provides some troubleshooting tips that should help.
    iOS: Understanding notifications
    http://support.apple.com/kb/ht3576
    Troubleshooting notifications
    Push notifications require an active Wi-Fi or cellular connection.
    Note: Notifications use Wi-Fi only when a cellular connection is unavailable. Firewalls and proxy servers may affect your ability to receive notifications. For more information, see Unable to use Apple Push Notification service (APNs).
    If you're not receiving notifications for a specific app, try these steps:
    Verify that the app supports notifications.
    After installing an app or restoring a backup to a different iOS device, open the app to begin receiving notifications. If the app requires entering or logging in to an account, you will need to do this before receiving notifications.
    Check Settings > Notification Center to ensure that the app is configured for notifications. If notifications do not appear in the Notification Center, verify that the Notification Center setting for the app is enabled.
    -Jason

  • Trouble accessing a "Captive Portal"

    Recently I was unable to access a WiFi network at a commercial location. Their tech services were baffled because other users were having no trouble at all. They told me that several other Mac users had been unable to log on as well. After I got home I read up on this and found that they were using a Captive Portal to redirect my log on. Googling these terms I find others with Macs asking for help but getting no response. One poster suggested it was a problem that began with an upgrade to Snow Leopard.
    I'm using 10.6.6 and frustrated with my inability to log in. Can anyone suggest a solution.
    MacTrekker

    I can't say for certain what is going wrong in your case but I can confirm it is possible to do an ARD connection i.e. Screen Sharing to a remote user connected via a VPN. The way we do this is to get the user to connect to the VPN server (a Mac OS X Server), then on the Mac OS X Server in Server Admin see what IP address they have been allocated by the VPN server, then tell ARD Admin to connect to that IP address.
    This works fine for me.
    The IP address will be a 'local'  to the ARD and VPN machines IP address it would not be the remote public or private IP addresses.

  • Captive Portal

    my customer is educational istitution,they have Cisco 1252 AP (autonomous).i want to setup a captive portal, i can build a linux based server..
    they cannot spend much... is there a way out..
    Thanks in advance
    Mak

    Hi,
    Setting a specific web page for the clients everytime when they connect to the AP is not possible
    by using the AP only. AP only has the option to redirect all the client traffic to any other IP
    on the network and thenfurther the device associated to that IP can provide the Web page for the
    clients that will be displayed on their client screens. That device can be a
    BBSM(Building Broadband Service Manager) or a Cisco NAC Appliance.
    As per the below link, BBSM is out of sale:
    http://www.cisco.com/en/US/prod/collateral/netmgtsw/ps5689/ps533/ps5463/prod_end-of-life_notice0900aecd805aeb23.html
    In order to configure a SSID/VLAN to open a particular website when any user
    connects to it, you need to connect a BBSM(Building Broadband Service
    Manager) or a Cisco NAC Appliance to any one of the Access ports on the
    switch which is a part of that VLAN. We can configure the BBSM device or the
    NAC device to open a specific webpage and after that we can configure the AP
    to forward all the packets coming from client connected to that specific
    SSID/VLAN to the IP address of the BBSM server with the help of "IP
    redirect" command we can configure on the AP. Here is a document for the
    same:
    http://www.cisco.com/en/US/docs/wireless/access_point/12.3_4_JA/configuratio
    n/guide/s34ssid.html#wp1049571
    Here is an application note about the list of APs which support IP redirection
    http://www.cisco.com/en/US/docs/wireless/technology/ip-redirect/technical/re
    ference/ipredir.html
    Most of the cases that we have seen on "IP redirection" go way back to when
    BBSM was available.  Nowadays, this is deployed using WLCs for the guest
    access.
    I hope the above answered your question.
    Regards
    Surendra

  • Captive Portal behavior could be better

    I noticed last night that one of my favorite watering holes had added a captive portal to the free WiFi.
    It took me a while to figure out what was going on, though, because I tried to use Maps first. So, I had good WiFi signal strength, but nothing was happening.
    It was only when I opened Safari and got redirected to a login that I figured it out.
    I'm not sure what Apple could do about this to detect this. (connect to a site at apple, and pop a warning if they don't get the expected content? Would a DNS lookup be enough?)
    But, if you have good signal and maps (or any of the other widgets) don't work, open Safari and take a look.

    Helpful find... A real time saver for some, it seems...

  • Configuration of AP 561 for captive portal.

    Can i use a single 561 accesspoint as a captive portal for whole network?
    I would like to install linksys APs in my network & single 561 AP along with linksys accesspoints. So, can I use 561 as a captive portal for my entire network?

    Ok. Here are the answers:
    1. Basic steps for Portal Configuration
       > Download ESS/MSS Business Package, it has two parts Business Package for ERP 2005 (Contains iviews, Roles etc) and XSS 5.0 or 6.0 depending upon the version of the ECC.
      > Make sure that you have SAP_HR and EA_HR component installed on your ECC box.
      > Also make sure that there is no compatibility mismatch between version of SAP_HR, EA_HR and XSS.
      > Configure the JCo Destinations, create required system definition and establish SSO between ECC and Portal.
      > Assign the role to the users
    > After doing these steps you can see the SAP provided iviews etc working PROVIDED configuration on HR side are already done.  (This is just to get initial configuration work)
    2. I need some docs for configuring ESS and MSS...
    > Provided by Bala above
    3. a) After configuring ESS and MSS, wat needs to be done.. suppose my client is asking for Leave Request in ESS, whether i need to create that application in webdynpro java or webdynpro abap in backend and i've to call that application in portal throgh iview...
    > Look for that application in WebDynpro (identify the component from iView properties) and show it to the client.
    If they are Ok with the basic things then fine else they need to specify the kind of customisation they want in this component
    Options available if we need to modify the components
    >>Copy the component in your namespace and do the modification using NWDINWDS
    >>If some field need to be disabled, you can do the same using Self service administration.
    b) or by doing the configuration of ESS, by default i will get all the aplications(e,g, Leave Request, Travel Managemetn ....) from that package and it will display in iview...
    Hope this helps. ...

  • WLC Captive Portal not loading images or via HTTP correctly

    Hi All,
    I have a strange issue I'm hoping someone can shed some light on.
    I have a CT2504 at a customer site which does not load the captive portal page correctly nor will it load via HTTP as opposed to HTTPS.
    So for starters I did what I do with all my CT2504's (which work fine), I configured my Guest network to authenticate via the default captive portal. I then disabled HTTPS and SSH and enabled HTTP managment followed by rebooting the controller.
    On boot, logging into the WLC management GUI is automatically presented via HTTP as expected.
    However when clients access the Guest network they are redirected to the Web Authorisation via HTTPS instead of HTTP, any ideas?
    In addtion to the above the captive portal page does not display correctly.
    The preview via the controller works fine, but the client is presented with a page with broken links to the images i.e. the blue strip at the top and the Cisco logo on the right, any clue what's happening here?
    Any help would be greatly appreciated.
    Thanks,
    Gary

    Thanks Gray. I am glad it worked.
    Rating useful replies is more useful than saying "Thank you"

  • LAPAC1750PRO - Web Portal / Captive Portal need to be responsive

    LAPAC1750PRO, The "Web Portal/ Captive Portal" need to be redesigned so it will be displayed in responsive design for the user. Right now, it’s almost “NOT” possible to use it from a phone or tablet.
    Captive Portal --> Web Portal Customization
    Solved!
    Go to Solution.

    I will notify Linksys engineering of this issue.
    Please remember to Kudo those that help you.
    Linksys
    Communities Technical Support

Maybe you are looking for