Setup Own Hosted Captive Portal SSID
11 min
configure a service area overview service areas are locations where you need nile connectivity as a service configuring a new service area log in to the nile portal in the left navigation, select network setup > service areas click the ' + ' sign to start adding a site name define the site location where you need the nile service find my address enter the exact shipping address where nile will deliver its network elements click the newly created service area and start adding all buildings within that service area enter the information for each building where you need the nile service and save note if some buildings do not have unique addresses, you can drop a pin on the map for reference click the newly defined building and add all floors in that building attach the floor plan to each floor optional after adding floor plans, you can define wi‑fi zones on the floors if applicable wi‑fi zones are custom ssid zones used to serve a specific set of clients configure dhcp overview a dhcp server automatically assigns ip addresses, default gateways, and other network parameters to client devices nile offers cloud dhcp as a service you can use immediately, or you can use your own dhcp server (e g , windows server, infoblox) if you are using your own dhcp server, configure the dhcp relay agent in the nile portal option 1 nile cloud dhcp server log in to the nile portal in the left navigation, select network setup > dhcp click on nile dhcp click on the ' + ' icon and enter the following details pool name enter a name for the dhcp user subnet network enter the subnet default gateway this is auto populated once you enter the network subnet please keep it as is lease time select the lease time default is 1 day dns server please input the ip addresses of your dns server for example 8 8 8 8,8 8 4 4 ip range click on the ' + ' icon to add an ip range specify the start and end ip addresses the fields are pre populated; modify them as required the basic setup is now complete; this covers the most common configuration advanced dhcp reservation enter the device hostname, mac address, and the ip address to reserve for each device options this section is used to configure advanced settings such as ntp server, tftp server, dns server, etc option 2 bring your own dhcp server prerequisites ensure you have the ip addresses of all the dhcp servers you plan to use in your enterprise the nile service block (nsb) acts as a dhcp relay and sends dhcp requests from the first ip address of each subnet (for example, for the employee subnet 192 168 1 0/24, it sends from 192 168 1 1) ensure your dhcp server supports layer‑3 dhcp standalone servers such as windows server and infoblox support this; many routers and firewalls do not verify support before configuring the nile portal ensure bidirectional routing between the dhcp server and your core router/firewall that connects to the nile service gateway configuring dhcp log in to the nile portal in the left navigation, select network setup > dhcp click on the ' + ' icon and enter the following details name specify the name you would like to use for the dhcp server host you can specify all the dhcp server ip addresses here if you have multiple dhcp servers, please specify the other ip/fqdn in the subsequent hosts geo scope select the sites where this dhcp server will be used to assign ip addresses subnet click on the ' + ' sign to add a subnet add all applicable subnets (for example, employee, corporate, and iot) router enter the default gateway ip address for the subnet this address is used by the nile relay agent when obtaining an ip lease from the dhcp server ensure this ip is configured on your dhcp server as the router/default gateway dhcp option (commonly option 3) this is typically the first usable ip in the subnet click save to complete configuration configure segments overview segments function as user defined profiles grouping specific sets of users within an enterprise (e g , corporate, guest) each segment operates similarly to a vlan in traditional networking and encompasses both wired and wireless devices a single segment can extend across multiple locations or be applied enterprise wide configuring segments log in to the nile portal in the left navigation, select network setup > segments click on the ' + ' sign to create a new segment configure the following general info enter a name for the segment service areas select one or multiple sites, buildings, or zones for example, a corporate segment can span all corporate sites, with each site using its own authentication method and subnet authentication for each site, select a custom radius server or the default nile radius from the dropdown note custom radius servers appear only after you configure them under authentication dhcp select the dhcp server to use for each site subnets for each site, select the subnets configured on the selected dhcp server from the dropdown typically, one subnet per segment advanced wired self register allows wired users to self‑register their devices without administrator intervention walled garden define the list of urls accessible before authentication (e g , help pages, login portals) click save to complete configuration setup wireless own‑hosted captive portal ssid this solution is ideal for customers who already use a network access control (nac) or captive portal platform with their existing wlan in this model, the nile access service acts as a pass through, relying on the external captive portal server to authenticate guest devices there are two modes or operation server initiated flow static url server initiated flow in the server initiated flow, the captive portal server is configured with the redirect url and hosts the captive portal page when a guest device connects to the captive portal ssid the nile access service assigns the device to a guest segment and provides an ip address from the dhcp server the nile access service initiates a mac authentication request to the captive portal server if the mac address is not in the captive portal server’s database, the server responds with an access accept message that embeds the redirect url the nile access service then redirects the user to the url provided by the captive portal server the user interacts with the captive portal page and provides the required authentication (e g , accept and connect, social login, password) after successful authentication, the captive portal server triggers a change of authorization (coa) , and the nile access service re initiates mac authentication this time, the server responds with an access accept without a redirect url the nile access service then admits the device onto the network static url in the static url mode, the administrator configures the redirect url in the nile cloud services portal when adding the radius server the captive portal server does not provide the url via the mac authentication process configuration steps 1\) prepare your portal set up your portal’s splash page and decide your redirect mode server‑initiated (portal embeds redirect url in mab response) or static url (nile holds the redirect url) 2\) add your radius server in nile in nile portal network setup → authentication → add radius server; in static url mode, set the redirect url while adding the server 3\) create or map a segment for guests create a guest segment and map it to use the above radius server for authentication; ensure dhcp/subnets are assigned for the sites where this segment is used 4\) create the guest ssid in nile portal network setup → wireless → + → set ssid name type select captive portal segment select the segment configured for the captive portal click save to complete configuration
