Summit WM User Guide, Software Version 5.3 167
The first five of these VSAs provide information on the identity of the specific Altitude AP that is
handling the wireless device, enabling the provision of location-based services.
The RADIUS message also includes RADIUS attributes Called-Station-Id and Calling-Station-Id in order
to include the MAC address of the wireless device.
NOTE
Extreme-URL-Redirection is supported by MAC-based authentication.
Defining authentication for a WM-AD for Captive Portal
For Captive Portal authentication, the wireless device connects to the network, but can only access the
specific network destinations defined in the non-authenticated filter. For more information, see
"Defining non-authenticated filters" on page 183. One of these destinations should be a server, either
internal or external, which presents a Web login page - the Captive Portal. The wireless device user
must input an ID and a password. This request for authentication is sent by the Summit WM Controller
to a RADIUS server or other authentication server. Based on the permissions returned from the
authentication server, the Summit WM Controller implements policy and allows the appropriate
network access.
Captive Portal authentication relies on a RADIUS server on the enterprise network. There are three
mechanisms by which Captive Portal authentication can be carried out:
z Internal Captive Portal - The Summit WM Controller displays the Captive Portal Web page, carries
out the authentication, and implements policy.
z External Captive Portal - After an external server displays the Captive Portal Web page and carries
out the authentication, the Summit WM Controller implements policy.
z External Captive Portal with internal authentication - After an external server displays the Captive
Portal Web page, the Summit WM Controller carries out the authentication and implements policy.
Table 14: Vendor Specific Attributes
Attribute Name ID Type Messages Description
Extreme-URL-
Redirection
1 string Returned from
RADIUS server
A URL that can be returned to redirect a
session to a specific Web page.
Extreme-AP-Name 2 string Sent to RADIUS
server
The name of the AP the client is associating to.
It can be used to assign policy based on AP
name or location.
Extreme-AP-Serial 3 string Sent to RADIUS
server
The AP serial number. It can be used instead of
(or in addition to) the AP name.
Extreme-WM-AD-
Name
4 string Sent to RADIUS
server
The name of the WM Access Domain the client
has been assigned to. It is used in assigning
policy and billing options, based on service
selection.
Extreme-SSID 5 string Sent to RADIUS
server
The name of the SSID the client is associating
to. It is used in assigning policy and billing
options, based on service selection.
Extreme-BSS-MAC 6 string Sent to RADIUS
server
The name of the BSS-ID the client is
associating to. It is used in assigning policy and
billing options, based on service selection and
location.