Describes how to configure guest access using various security methods and provides detailed information about different configuration options and implementation approaches.
These sections provide information about:
Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.x
Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.x
Describes how to configure guest access using various security methods and provides detailed information about different configuration options and implementation approaches.
These sections provide information about:
To configure the guest access with open authentication, follow the steps:
Configure the WLAN Profile
Configure access policy profile
No tag is required unless AVC is enabled.
Create a WLAN profile that allows guest users to connect to the wireless network without requiring authentication credentials, providing open access for temporary or visitor use.
Guest access with open authentication is commonly used in public areas, visitor networks, or temporary access scenarios where security requirements are minimal and ease of access is prioritized.
Choose .
Click Add.
In the General tab, enter the Profile Name, the SSID and the WLAN ID. Choose the radio policy from the Radio Policy drop-down list. Enable or disable the Status and Broadcast SSID toggle buttons.
Choose Security > Layer2 tab. Uncheck the WPA Policy, WPA2 Policy, AES and 802.1x check boxes.
Click Apply to Device.
The WLAN profile is created and configured for guest access with open authentication. Guest users can now connect to the wireless network without providing authentication credentials.
To configure LWA, follow these steps:
Configure a parameter map to define web authentication settings including connection limits and timeout values.
Parameter maps are used to configure web authentication parameters that control how users authenticate through the web interface. This configuration is performed through the device's graphical user interface.
Choose .
Click Add.
Enter the Parameter-map name, Maximum HTTP connections,Init-State Timeout(secs) and choose webauth in the Type drop-down list.
Click Apply to Device.
The parameter map is configured and applied to the device with the specified web authentication settings.
Configure a WLAN profile to enable guest access with local web authentication, allowing temporary network access for visitors while maintaining security controls.
Use this procedure when you need to provide internet access to guests through a web-based authentication portal. This configuration enables controlled access for users who do not have permanent network credentials.
Follow these steps to configure a WLAN profile for guest access with local web authentication:
Choose .
Click on the WLAN name.
Choose .
Check the Web Policy check box.
Choose a parameter map from the Web Auth Parameter Map drop-down list.
Choose an authentication list from the Authentication List drop-down list.
Click Update & Apply to Device.
The WLAN profile is configured with local web authentication for guest access. Guest users connecting to this WLAN will be redirected to a web authentication portal where they can obtain network access.
This task configures a WLAN profile with local web AUTHENTICATION to provide secure guest access to the wireless network.
Local web AUTHENTICATION allows guest users to access the network through a web-based AUTHENTICATION portal. This configuration is typically used in guest access scenarios where users need to authenticate via a web interface before gaining network access.
The WLAN profile is configured with local web AUTHENTICATION for guest access. Guest users will now be prompted to authenticate through a web interface when connecting to the wireless network.
This task allows you to set up AAA server configuration for local web authentication using the graphical user interface.
Use this procedure when you need to configure authentication and authorization settings for local web authentication through the device's web interface.
Choose .
Choose the options from the Local Authentication, Authentication Method List, Local Authorization and Authorization Method List drop-down lists.
Enable or Disable the Radius Server Load Balance using toggle button.
Check the Interim Update check box.
Click Apply.
The AAA server configuration for local web authentication is now configured with your selected settings.
Configure Authentication, Authorization, and Accounting (AAA) server settings to enable local web authentication on the device.
Use this procedure when you need to set up local authentication and authorization for web-based user access on your device.
The AAA server is configured for local web authentication. Users can now authenticate locally when accessing the device through web interface.
Configure a WLAN profile that enables guest access using central web authentication to provide secure network access for guest users.
Guest access with central web authentication allows visitors to access the network through a web-based authentication portal while maintaining security controls through MAC filtering and authorization lists.
Follow these steps to configure a WLAN profile for guest access with central web authentication:
Choose .
Click Add.
In the General tab, enter the Profile Name, the SSID, and the WLAN ID.
To enable the WLAN, set Status as Enabled.
From the Radio Policy drop-down list, select the radio policy.
To enable the Broadcast SSID, set the status as Enabled.
Choose Security > Layer2 tab. Uncheck the WPA Policy, WPA2 Policy, AES and 802.1x check boxes.
Check the MAC Filtering check box to enable the feature. With MAC Filtering enabled, choose the Authorization list from the Authorization List drop-down list.
Click Apply to Device.
The WLAN profile is configured for guest access with central web authentication. The profile is now available for guest users to connect through the web authentication portal.
Configure RADIUS server groups and individual RADIUS servers to enable AAA authentication for network access control and user authentication.
AAA (Authentication, Authorization, and Accounting) servers provide centralized authentication services for network devices. RADIUS servers must be properly configured with server groups to ensure reliable authentication services.
Choose .
Click the RADIUS server group.
From the MAC-Delimiter drop-down list, choose an option.
From the MAC-Filtering drop-down list, choose an option.
Enter the Dead-Time (mins).
From the Available Servers on the left, move the servers you need to Assigned Servers on the right.
Click Update & Apply to Device.
Choose .
Click the RADIUS server.
Enter the IPv4/IPv6 Server Address, Auth Port, Acct Port, Server Timeout (seconds) and Retry Count.
Check or uncheck the PAC Key checkbox and choose the Key Type from the Key Type drop-down list. Enter the Key and Confirm Key.
Enable or disable the Support for CoA toggle button.
Click Update & Apply to Device.
The RADIUS server groups and servers are configured and applied to the device. AAA authentication is now available using the configured RADIUS servers.
To configure the CWA with PSK security protocol, follow the steps:
To configure the CWA with iPSK security protocol, follow the steps:
This task configures a WLAN profile that enables central web authentication with iPSK (Identity Pre-Shared Key) protocol, providing secure guest access while maintaining centralized authentication control.
Use this configuration when you need to provide guest wireless access with pre-shared key authentication combined with central web authentication. This approach allows for individualized keys per device while maintaining centralized authentication oversight.
The WLAN profile is configured for central web authentication with iPSK protocol. Guest devices can now connect using pre-shared keys while being subject to centralized web authentication control and MAC filtering.
This task configures Web Authentication to handle situations where MAC address filtering fails, providing an alternative authentication method for network access.
When MAC filtering is enabled but a device's MAC address is not in the authorization list, you can configure the system to fall back to Web Authentication instead of denying access completely.
Click .
Click Add to add a new WLAN Profile or click the one you want to edit.
In the Edit WLAN window, complete the following steps:
Web Authentication is now configured to activate when MAC address filtering fails, allowing devices not on the authorization list to authenticate through the web interface.
Enable web authentication for clients who fail MAC authentication bypass on a WLAN, using a pre-shared key, through the CLI.
Use this configuration to ensure clients who do not pass MAC authentication bypass are redirected to a web authentication portal with a secure pre-shared key.
The WLAN is configured to perform web authentication for clients failing MAC authentication bypass, securing access with a pre-shared key.
Enable web authentication for clients who fail MAC authentication bypass (MAB) on a WLAN, using a pre-shared key through the CLI.
Use this configuration to ensure that clients who do not pass MAC authentication bypass are redirected to a web authentication portal protected by a secure pre-shared key.
The WLAN now performs web authentication for clients who fail MAC authentication bypass and secures access with a pre-shared key.
Configure a WLAN using the CLI. If MAC Authentication Bypass (MAB) fails, users are directed to web authentication with Simultaneous Authentication of Equals (SAE) enabled.
Use this task when you require a WLAN that supports MAC authentication. If MAC authentication fails, the controller falls back to web authentication with SAE.
This setup strengthens security by ensuring that only authorized users can access the network. It also supports modern authentication protocols.
Prepare the names of the authentication and authorization lists and the parameter map, if needed.
The WLAN is configured to use MAC authentication. If MAC authentication fails, users are redirected to web authentication, with WPA3 and SAE enabled.