Got it

Guest WIFI with self registration

Created: Aug 22, 2019 16:11:00Latest reply: Aug 23, 2019 02:10:16 1943 3 1 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi All,


Has anyone created a guest wifi network where users can self register? I have seen the Agile controller and the GPRS modem solution but wondering if this is awkward to set up and deliver?


Advice appreciated.


Regards


Adrian

Featured Answers

Recommended answer

wissal
MVE Created Aug 22, 2019 17:24:23

Hi,

For Guest WIFI with self registration

Configuring Guests to Obtain Passwords Through Mobile Phones to Pass Authentication Quickly

Guests can obtain passwords through mobile phones to connect to networks quickly.

Involved Products and Versions

Product Type

Product Name

Version

  • RADIUS Server
  • Portal Server

AC-Campus

V100R002C10

Networking Requirements

An enterprise has deployed an authentication system to implement access control for all the wireless users who attempt to connect to the enterprise network. Only authenticated users can connect to the enterprise network. Enterprise employees connect to the network through personal computers (PCs) and guests connect to the network through mobile phones. The administrator has created local accounts for the employees so that they can use the local accounts to pass authentication. For guest accounts, the system should satisfy the following demands:
  • All guests must associate with the Wi-Fi network whose SSID is guest to connect to the Internet. Other SSIDs are not allowed.
  • All guests can use their mobile phone number to obtain passwords to access the network. After guests send their requests to obtain passwords, passwords are sent to the guests through SMS messages.
  • After the authentication succeeds, the web page requested by the guest before the authentication is displayed automatically.

Data Plan

Table 3-1  Data plan

Item

Data

Description

SM + SC (RADIUS server + Portal server)

IP address: 172.18.1.1

-

SMS server

Message Sending Method

GPRS modem

Enable distributed SC

no

Serial Port ID

COM1

Country Code

86

Baud Rate

115200

Test Number

13412345678

Set corresponding parameters on the GPRS modem in advance. For details, see What Should I Do Before Connecting a GPRS Modem to the AC-Campus?.

Number of the ACL for guests' post-authentication domain

3002

-

SSID of the network to which guests associate with

guest

Configure this parameter on the AC. For details, see step 4 in 2.2.2 Example for Configuring Portal Authentication (Including MAC Address-Prioritized Portal Authentication) for Wireless Users.

Configuration Roadmap

  1. Configure the SMS server so that the system can send SMS messages properly.
  2. Configure guest account policies. This example uses the default policy "self-registration_obtaining passwords through mobile phones_8-hour validity period".
  3. Customize the authentication page. The authentication page is automatically displayed if an unauthenticated guest accesses the network.
  4. Configure a Portal page push rule to push the customized authentication page to guests.
  5. Add guest authorization results and authorization rules to assign access rights to guests after they are successfully authenticated.

Prerequisites

Portal authentication configurations have been completed on the AC/switch and the AC-Campus. For details, see configuration examples about Portal.

Procedure

  1. Enter https://172.18.1.1:8443 in the address box of a web browser to log in to the Service Manager.
  2. Configure the SMS server so that the system can send SMS messages properly.
    1. Choose System > Server Configuration > SMS Server Configuration.
    2. Set parameters of the SMS server.

      24f9a440186a403e9c0273dd6a33ba63

      ced9e994ac1143d29bc19403e2cbb850 NOTE:

      If the SMS modem is used, no more than three guests can register per minute. If the number of guests that need to register in a minute exceeds three, use the SMS gateway.

    3. Click Test. The Test Succeeded message is displayed and the phone with the configured mobile phone number receives a test SMS message.
    4. Click Save.
  3. Configure guest account policies. Choose Policy > Permission Control > Guest Management > Guest Account Policy.

    This example uses the default policy "Self-registration_password through phones_valid for 8 hours". If the default policy cannot satisfy requirements, you can modify it or create a new policy. Set the parameters marked in red rectangles according to the following figure.

    8f8309f0722e4cd881b58ae63d7ca626

  4. Customize the authentication page. The authentication page is automatically displayed if an unauthenticated guest accesses the network.
    1. Choose Policy > Permission Control > Page Customization > Page Customization.
    2. Click 88e09a05dc0948fda3a572c836d423e0.
    3. Configure basic information about the authentication page.

      You must select Self Register and set Guest Account Policy to the policy created in 3.

      026e7cd068924f0a9bde8bd7cd224b6f

    4. Click Next. Set the page template and language template.

      The page template is set to System-Mobile Quick Authentication Template and the language template is set to English.

      7ea4d4ba628a4751b74f953be21dcc65

    5. Click Next to customize the page pushed to a phone.

      The guest uses the phone to obtain a password to complete registration. Therefore, no registration and registration success pages are required. You only need to customize the authentication, authentication success, and user notice pages. You can change logos as required.

      36a2122b5ff94d1cb5824b55ff746204

    6. Click Next to customize the page pushed to a PC.

      b822488b410047129f4d1754ccca9de1

    7. Click Publish.

      If Delivery succeeded is displayed, page customization succeeds.

  5. Configure a Portal page push rule to push the customized authentication page to guests.
    1. Choose Policy > Permission Control > Page Customization > Portal Page Push Rule.
    2. Click Add to add the Portal page push rule.

      c700d73adf0b4482b1d2fe50b9f7d655

      Parameter

      Value

      Description

      Name

      Push rule for phone registration

      -

      User-defined parameters

      ssid=guest

      • ssid=guest indicates that the AC pushes the specified page so long as unauthorized guests select the SSID guest.
      • For details about User-defined parameters, see Defining a Redirection Rule for the Portal Page.
      • The AC needs to send the user-defined URL parameter to the Portal server through the URL parameter template, so that the Portal server can correctly match the pushed condition. In this example, the AC sends the user-defined URL parameter ssid to the Portal server, so that it can correctly match the pushed condition.

      Pushed page

      Select the page customized in 4

      -

      Page displayed after successful authentication

      Continue to visit the original page

      The value of the redirect-url field specified on the AC must be url. For details, see How Do I Continue to Access the Original Page After Successful Portal Authentication?.

    3. Click OK.
  6. Add SSIDs to the AC-Campus for SSID-based user authorization.
    1. Choose Policy > Permission Control > Policy Element > SSID.
    2. Click Add, and add a guest SSID.

      The case-sensitive SSID name must be the same as those configured on the AC.

      1b01e5c1ca594b56989a75737af97711

  7. Add an authorization result and rule to allow guests to connect to the Internet after they are successfully authenticated.
    1. Choose Policy > Permission Control > Authentication and Authorization > Authorization Result and specify resources that guests can access after being authenticated and authorized.

      ee3a9d89469f4ae5bb163ee80a8ffd33

      Parameter

      Value

      Description

      Name

      Authorization Result for guest

      -

      Service Type

      Access Service

      -

      ACL Number/AAA User Group

      3002

      ACL number must be the same as the number of the ACL configured for guests on the AC.

    2. Choose Policy > Permission Control > Authentication and Authorization > Authorization Rule and specify the authorization conditions for guests.

      9bdb0a1854c74fd0a05b86fb3f550a03

      Parameter

      Value

      Description

      Name

      Authorization Rule for guest

      -

      Service Type

      Access User

      -

      User Group

      Guest

      The value must be the same as that of User Group specified when you configure a guest account policy.

      SSID

      guest

      The SSID must be the same as that configured for guests on the AC.

      Authorization Result

      Authorization Result for guest

      -

Verification

  1. A guest uses a mobile phone to connect to a Wi-Fi network. The guest selects the hotspot guest to connect to the Internet. The authentication page is pushed to the guest.
  2. The guest enters his or her mobile phone number and clicks Get Password.

    The authentication password is sent to the guest's mobile phone.

  3. The guest enters the mobile phone number and password and clicks Login. The web page requested by the guest before the authentication is displayed automatically.
  4. On the Service Manager, choose Resource > User > Online User Management. The online information about the account is displayed.
  5. On the Service Manager, choose Resource > User > RADIUS Log. The RADIUS authentication logs of the account are displayed.
Thanks
View more
  • x
  • convention:

All Answers
Hi,

You can use agile controller for self-registration of guests. And it's easily configured with wireless network.
You can also use 3rd party sms gateway to send username/password to guest user. Or any mail client to send details via email.
View more
  • x
  • convention:

Hi,

For Guest WIFI with self registration

Configuring Guests to Obtain Passwords Through Mobile Phones to Pass Authentication Quickly

Guests can obtain passwords through mobile phones to connect to networks quickly.

Involved Products and Versions

Product Type

Product Name

Version

  • RADIUS Server
  • Portal Server

AC-Campus

V100R002C10

Networking Requirements

An enterprise has deployed an authentication system to implement access control for all the wireless users who attempt to connect to the enterprise network. Only authenticated users can connect to the enterprise network. Enterprise employees connect to the network through personal computers (PCs) and guests connect to the network through mobile phones. The administrator has created local accounts for the employees so that they can use the local accounts to pass authentication. For guest accounts, the system should satisfy the following demands:
  • All guests must associate with the Wi-Fi network whose SSID is guest to connect to the Internet. Other SSIDs are not allowed.
  • All guests can use their mobile phone number to obtain passwords to access the network. After guests send their requests to obtain passwords, passwords are sent to the guests through SMS messages.
  • After the authentication succeeds, the web page requested by the guest before the authentication is displayed automatically.

Data Plan

Table 3-1  Data plan

Item

Data

Description

SM + SC (RADIUS server + Portal server)

IP address: 172.18.1.1

-

SMS server

Message Sending Method

GPRS modem

Enable distributed SC

no

Serial Port ID

COM1

Country Code

86

Baud Rate

115200

Test Number

13412345678

Set corresponding parameters on the GPRS modem in advance. For details, see What Should I Do Before Connecting a GPRS Modem to the AC-Campus?.

Number of the ACL for guests' post-authentication domain

3002

-

SSID of the network to which guests associate with

guest

Configure this parameter on the AC. For details, see step 4 in 2.2.2 Example for Configuring Portal Authentication (Including MAC Address-Prioritized Portal Authentication) for Wireless Users.

Configuration Roadmap

  1. Configure the SMS server so that the system can send SMS messages properly.
  2. Configure guest account policies. This example uses the default policy "self-registration_obtaining passwords through mobile phones_8-hour validity period".
  3. Customize the authentication page. The authentication page is automatically displayed if an unauthenticated guest accesses the network.
  4. Configure a Portal page push rule to push the customized authentication page to guests.
  5. Add guest authorization results and authorization rules to assign access rights to guests after they are successfully authenticated.

Prerequisites

Portal authentication configurations have been completed on the AC/switch and the AC-Campus. For details, see configuration examples about Portal.

Procedure

  1. Enter https://172.18.1.1:8443 in the address box of a web browser to log in to the Service Manager.
  2. Configure the SMS server so that the system can send SMS messages properly.
    1. Choose System > Server Configuration > SMS Server Configuration.
    2. Set parameters of the SMS server.

      24f9a440186a403e9c0273dd6a33ba63

      ced9e994ac1143d29bc19403e2cbb850 NOTE:

      If the SMS modem is used, no more than three guests can register per minute. If the number of guests that need to register in a minute exceeds three, use the SMS gateway.

    3. Click Test. The Test Succeeded message is displayed and the phone with the configured mobile phone number receives a test SMS message.
    4. Click Save.
  3. Configure guest account policies. Choose Policy > Permission Control > Guest Management > Guest Account Policy.

    This example uses the default policy "Self-registration_password through phones_valid for 8 hours". If the default policy cannot satisfy requirements, you can modify it or create a new policy. Set the parameters marked in red rectangles according to the following figure.

    8f8309f0722e4cd881b58ae63d7ca626

  4. Customize the authentication page. The authentication page is automatically displayed if an unauthenticated guest accesses the network.
    1. Choose Policy > Permission Control > Page Customization > Page Customization.
    2. Click 88e09a05dc0948fda3a572c836d423e0.
    3. Configure basic information about the authentication page.

      You must select Self Register and set Guest Account Policy to the policy created in 3.

      026e7cd068924f0a9bde8bd7cd224b6f

    4. Click Next. Set the page template and language template.

      The page template is set to System-Mobile Quick Authentication Template and the language template is set to English.

      7ea4d4ba628a4751b74f953be21dcc65

    5. Click Next to customize the page pushed to a phone.

      The guest uses the phone to obtain a password to complete registration. Therefore, no registration and registration success pages are required. You only need to customize the authentication, authentication success, and user notice pages. You can change logos as required.

      36a2122b5ff94d1cb5824b55ff746204

    6. Click Next to customize the page pushed to a PC.

      b822488b410047129f4d1754ccca9de1

    7. Click Publish.

      If Delivery succeeded is displayed, page customization succeeds.

  5. Configure a Portal page push rule to push the customized authentication page to guests.
    1. Choose Policy > Permission Control > Page Customization > Portal Page Push Rule.
    2. Click Add to add the Portal page push rule.

      c700d73adf0b4482b1d2fe50b9f7d655

      Parameter

      Value

      Description

      Name

      Push rule for phone registration

      -

      User-defined parameters

      ssid=guest

      • ssid=guest indicates that the AC pushes the specified page so long as unauthorized guests select the SSID guest.
      • For details about User-defined parameters, see Defining a Redirection Rule for the Portal Page.
      • The AC needs to send the user-defined URL parameter to the Portal server through the URL parameter template, so that the Portal server can correctly match the pushed condition. In this example, the AC sends the user-defined URL parameter ssid to the Portal server, so that it can correctly match the pushed condition.

      Pushed page

      Select the page customized in 4

      -

      Page displayed after successful authentication

      Continue to visit the original page

      The value of the redirect-url field specified on the AC must be url. For details, see How Do I Continue to Access the Original Page After Successful Portal Authentication?.

    3. Click OK.
  6. Add SSIDs to the AC-Campus for SSID-based user authorization.
    1. Choose Policy > Permission Control > Policy Element > SSID.
    2. Click Add, and add a guest SSID.

      The case-sensitive SSID name must be the same as those configured on the AC.

      1b01e5c1ca594b56989a75737af97711

  7. Add an authorization result and rule to allow guests to connect to the Internet after they are successfully authenticated.
    1. Choose Policy > Permission Control > Authentication and Authorization > Authorization Result and specify resources that guests can access after being authenticated and authorized.

      ee3a9d89469f4ae5bb163ee80a8ffd33

      Parameter

      Value

      Description

      Name

      Authorization Result for guest

      -

      Service Type

      Access Service

      -

      ACL Number/AAA User Group

      3002

      ACL number must be the same as the number of the ACL configured for guests on the AC.

    2. Choose Policy > Permission Control > Authentication and Authorization > Authorization Rule and specify the authorization conditions for guests.

      9bdb0a1854c74fd0a05b86fb3f550a03

      Parameter

      Value

      Description

      Name

      Authorization Rule for guest

      -

      Service Type

      Access User

      -

      User Group

      Guest

      The value must be the same as that of User Group specified when you configure a guest account policy.

      SSID

      guest

      The SSID must be the same as that configured for guests on the AC.

      Authorization Result

      Authorization Result for guest

      -

Verification

  1. A guest uses a mobile phone to connect to a Wi-Fi network. The guest selects the hotspot guest to connect to the Internet. The authentication page is pushed to the guest.
  2. The guest enters his or her mobile phone number and clicks Get Password.

    The authentication password is sent to the guest's mobile phone.

  3. The guest enters the mobile phone number and password and clicks Login. The web page requested by the guest before the authentication is displayed automatically.
  4. On the Service Manager, choose Resource > User > Online User Management. The online information about the account is displayed.
  5. On the Service Manager, choose Resource > User > RADIUS Log. The RADIUS authentication logs of the account are displayed.
Thanks
View more
  • x
  • convention:

  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.