Wired Guest Access with Radius authentication
- add wired guest vlan to network infrastructure(everywhere where needed,e.g.trunks,access switches,etc.)
- Create "Guest" interface
When you select "Guest Lan" checkbox all IP part is removed - it is normal behaviour
- Create dynamic interface. It is interface where wired guest users will obtained IP and reach network resources like Internet.
- Add radius server(s)
- Create WLAN for "Wired Guest Access" - please choose "Guest LAN" type like on picture
As "Ingres" interface select "wired_guest"(VLAN 601) and as a "Egress" interface select dmz
Besides "Web Authentication" you can configure "Open" and "Pass-through"
- Select authentication server
WIRED GUEST CLIENT TEST
- Connect client PC to switch where vlan(601) is assigned.
- Open a browser
- Verify client status on controller before authentication
Before user authentication we should check:
- IP address assigned to client PC
- Interface where client is bridged
- VLAN interface
- Associated WLAN
- Policy Manager State - now WEBAUTH_REQ which is OK because client is not authenticated and WLC is waiting for authentication
- Provide user and password and click submit
After successful authentication wired guest user should be able to browse Internet
- Verify wired guest client on local controller
Note: After wired guest authentication WLC knows guest client username and Policy Manager State change value to "RUN"
- Verify user authentication on radius server