Explains external web authentication mechanisms for WLAN clients, providing instructions to configure single or multiple WebAuth servers and wired guest EWA using CLI procedures.
Configure EWA with single WebAuth server address and default ports (80/443) (CLI)
Configure External Web Authentication (EWA) on your device to use a single WebAuth server address with default ports (80 or 443).
Use this procedure to redirect guest WLAN clients to a specific WebAuth portal using default HTTP or HTTPS ports.
Procedure
Once enabled for the configured WLAN, web authentication redirects clients to the specified WebAuth portal using default ports.
Configure EWA with multiple web servers and/or ports different than default (80/443)
Configure an External Web Authentication (EWA) workflow to support multiple web servers and custom port numbers using CLI.
Enable guest access using EWA if there are multiple external web servers or if web authentication must use ports other than the default ports of 80 or 443.
Procedure
This configuration allows EWA with multiple external web servers and ports. It supports DNS or DHCP traffic and blocks unauthorized traffic.
Configure wired guest EWA with multiple web servers, ports different than default (80/443)
Configure Wired Guest External Web Authentication (EWA) when using multiple web servers or ports other than the default ports of 80 or 443 using CLI.
Wired Guest LAN profiles do not allow manual ACL assignment directly. To support multiple web servers or custom ports, use the bypass ACL in the global parameter map.
Procedure
The wired guest profile uses the bypass ACL, enabling external web authentication with multiple web servers or custom ports.