Alcatel-Lucent (Controller-based)

  • Updated
Important Note: You must add the MAC address of the Controller to your portal under the Hardware tab. Choose "Alcatel-Lucent AP (Controller based)" as the type. The MAC is printed on the sticker on the back of the Controller, or you can retrieve it by going to the "Monitoring > Controller Summary" page on the Controller web interface.

Login and Initial Setup

Login to your Alcatel-Lucent controller web interface and click Configure.

On the left, under Wizards, choose Campus WLAN.

Under the WLANs box, click New. Enter Guest WiFi as the name (or whatever you want the SSID to be).

WLAN Configuration

Click Next and configure with:

Forwarding ModeTunnel (unless you have an existing setup)

Click Next and configure with:

Radio TypeAll
Broadcast SSIDYes
VLAN1 (unless you have a specific VLAN to use)

Click Next and configure with:

Is this WLAN intended for internal or guest?Guest

Click Next and configure with:

Captive portal with authentication via credentialsSelected

Click Next and then Next again on the Captive Portal options page.

Authentication Server Configuration

On the Specify Authentication Server page, click Add and configure with:

Server typeRADIUS
Nameguest1
IP Address*insert radius_server here*
Auth port1812
Acct port1813
Shared key*insert radius_secret here*
Retype keyas above

Click OK and then Add again, this time configuring with:

Server typeRADIUS
Nameguest2
IP Address*insert radius_server2 here*
Auth port1812
Acct port1813
Shared key*insert radius_secret here*
Retype keyas above

Click OK and then Next and configure with:

Pre-authentication roleGuest WiFi-guest-logon
Authenticated roleguest

Click Next and then Finish to confirm.

Advanced Services Configuration

Next, under Advanced Services on the left, click on Stateful Firewall. Select the Destination tab and click on Add. Configure with:

IP VersionIPv4
Destination Nameguestwifi

Click the Add button and configure with:

Typename
Domain Name*insert access_domain here*

Click Add to save and add all the required domains one by one. Please refer to this list.

Click Apply to save.

Security Configuration

Next, under Security on the left, click Authentication.

Select the L3 Authentication tab and then click on Guest WiFi-cp_prof entry. Configure with the following:

Default Roleguest
Default Guest Roleguest
Redirect Pause0
User LoginEnabled
Guest LoginDisabled
Logout popup windowDisabled
Use HTTP for authenticationEnabled
Authentication ProtocolPAP
Login page*insert access_url here*?acmac=<controller-mac>&
Welcome page*insert redirect_url here*&acmac=<controller-mac>&
Show Welcome pageEnabled
Add switch IP in redirection URLEnabled
White ListAdd guestwifi from the list
User idle timeout3600

Click Apply to save.

AAA Profiles Configuration

Next, select the AAA Profiles tab and click on Guest WiFi-aaa_prof. Configure with:

Initial roleGuest WiFi-guest-logon
RADIUS Interim AccountingEnabled

Click Apply to save.

RADIUS Accounting Server Group Configuration

Next, click on the RADIUS Accounting Server Group and configure with:

RADIUS Accounting Server GroupGuest WiFi-srvgrp-xxx (where xxx is a random number)

Click Apply to save.

RADIUS Server Configuration

Next, select the Servers tab and click on RADIUS Server then guest1. Leave all settings as they are except:

ModeEnabled
MAC address delimiterDash

Click Apply to save.

Next, click on RADIUS Server then guest2. Leave all settings as they are except:

ModeEnabled
MAC address delimiterDash

Click Apply to save.

Save Configuration

Finally, click Save configuration at the top and reload/reboot the controller to ensure all settings take effect.

Share online:
Was this article helpful?
0 out of 0 found this helpful