The following instructions outline how to setup a Cisco Wireless LAN Controller for the Marketing4WIFi Platform. Please make sure any firewall rules, web content filters, and other security measures have been configured to interface with the Smart WiFi Platform.
- Login to the WLC
- Using the top navigation menu, click on Security
- Using the menu to the left, open AAA > RADIUS > Authentication
- Auth Call Station ID Type: AP MAC Address
- Press New and configure a Authentication server using the settings below
- Server IP Address: Select one
- Shared Secret Format: ASCII
- Shared Secret: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Confirm Secret: same as above
- Port: 1812
- Server Status: Enabled
- Network User: unchecked
- Management: unchecked
- IPSec: unchecked
- Click Apply
- Server IP Address: Select one
- Press New and configure another Authentication server using the settings below
- Server IP Address: Select one
- Shared Secret Format: ASCII
- Shared Secret: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Confirm Secret: same as above
- Port: 1812
- Server Status: Enabled
- Network User: unchecked
- Management: unchecked
- IPSec: unchecked
- Click Apply
- Server IP Address: Select one
- Click Apply
- Using the menu to the left, open AAA > RADIUS > Accounting
- Acct Call Station ID Type: AP MAC Address
- Press New and configure a Accounting server using the settings below
- Server IP Address: Select one
- Shared Secret Format: ASCII
- Shared Secret: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Confirm Secret: same as above
- Port: 1813
- Server Status: Enabled
- Network User: unchecked
- IPSec: unchecked
- Click Apply
- Server IP Address: Select one
- Press New and configure another Authentication server using the settings below
- Server IP Address: Select one
- Shared Secret Format: ASCII
- Shared Secret: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Confirm Secret: same as above
- Port: 1813
- Server Status: Enabled
- Network User: unchecked
- IPSec: unchecked
- Click Apply
- Server IP Address: Select one
- Using the menu to the left, open Access Control Lists > Access Control Lists (or FlexConnect ACLs if you’re using FlexConnect)
- Press New and configure with
- Access Control List Name: SmartWiFi
- ACL Type: IPv4
- Click Apply
- Hover over the blue arrow of the ACL you created and click Add-Remove URL.
- Use the URL String Name field to add the whitelist entries one at a time.
- Press New and configure with
- Using the menu to the left, Web Auth > Web Login Page
- Redirect URL after login: leave this blank
- Click Apply
- Using the top navigation menu, click on Management
- Using the menu to the left, open HTTP-HTTPS
- WebAuth SecureWeb: Disabled
- Click Apply
- Using the top navigation menu, click on Controller
- Using the menu to the left, open Interfaces
- Click on the virtual interface
- Change the interface IP Address from 1.1.1.1 to 192.0.2.1
- Click Apply
- Using the top navigation menu, click on WLANs
- Create a new WLAN using the Create New > Go option at the top right or edit your existing WLAN
- WLAN General settings-
- Status: Enabled
- Broadcast SSID: Enabled
- NAS-ID: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called SWS/Hotspot/NAS-ID.
- Security > Layer 2-
- Layer 2 Security: None
- Security > Layer 3-
- Layer 3 Security: Web Policy
- Authentication: Enabled
- Pre-Authentication ACL: Select the IPv4 or FlexConnect ACL called SmartWiFi
- Sleeping Client: Enabled
- Sleeping Client Timeout: 12
- Override Global Config: Enable
- Web Auth type: External
- Redirect URL: Select one
- Security > AAA Servers-
- Authentication Server: Enabled
- Server 1: Select the Authentication server created in step 3.2
- Server 2: Select the Authentication server created in step 3.3
- Accounting Servers: Enabled
- Server 1: Select the Accounting server created in step 4.2
- Server 2: Select the Accounting server created in step 4.3
- Authentication priority order for web-auth user
- Not Used: LOCAL & LDAP
- Order Used for Authentication: RADIUS
- Advanced-
- Allow AAA Override: Enabled
- Enable Session Timeout: Enabled
- Session Timeout(secs): 43200
- Click Apply
- WLAN General settings-
- Using the top navigation menu, click on Save Configuration and press OK
- Reboot the WLC for all the changes to take affect
- The configuration is complete