Cisco NAC Guest Server Installation and Configuration Guide, Release 2.1
Total Page:16
File Type:pdf, Size:1020Kb
Cisco NAC Guest Server Installation and Configuration Guide Release 2.1 November 2012 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 Text Part Number: OL-28256-01 THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS. THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY. The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB’s public domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California. NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS” WITH ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE. IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R) Any Internet Protocol (IP) addresses used in this document are not intended to be actual addresses. Any examples, command display output, and figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses in illustrative content is unintentional and coincidental. Cisco NAC Guest Server Installation and Configuration Guide © 2013 Cisco Systems, Inc. All rights reserved. CONTENTS About This Guide xi Audience xi Purpose xi New Features in this Release xi Product Documentation xii Documentation Updates xiii Obtaining Documentation and Submitting a Service Request xiii Document Conventions xiii CHAPTER 1 Welcome to Cisco NAC Guest Server 1-1 Introduction 1-1 Guest Access Concepts 1-1 Before You Start 1-2 Package Contents 1-2 Rack Mounting 1-3 Cisco NAC Guest Server Licensing 1-3 Upgrading Firmware 1-3 Additional Information 1-3 CHAPTER 2 Installing Cisco NAC Guest Server 2-1 Connecting the Cisco NAC Guest Server 2-1 Command Line Configuration 2-4 Initial Log In 2-4 Configure IP Address and Default Gateway 2-5 Change Root Password 2-8 Next Steps 2-8 Re-Imaging the Appliance 2-9 Configuring Boot Settings on NAC-3415 / NAC-3315 Based Appliances 2-12 CHAPTER 3 System Setup 3-1 Installing the Product License and Accessing the Administration Interface 3-1 Obtain and Install Cisco NAC Guest Server License 3-2 Access Cisco NAC Guest Server Administration Interface 3-3 Cisco NAC Guest Server Installation and Configuration Guide OL-28256-01 iii Contents Configuring Network Settings 3-4 Date and Time Settings 3-6 Access Restrictions 3-7 Administration Access 3-7 Sponsor Access 3-8 Configuring SSL Certificates 3-9 Accessing the Guest Server Using HTTP or HTTPS 3-9 Generating Temporary Certificates/ CSRs/ Private Key 3-11 Generating Self-Signed SSL Certificates Through CLI 3-12 Downloading Certificate Files 3-13 Downloading the Certificate 3-13 Downloading the Private Key 3-13 Uploading Certificate Files 3-14 Uploading a Private Key 3-14 Configuring Administrator Authentication 3-15 Add New Admin Account 3-15 Edit Existing Admin Account 3-17 Delete Existing Admin Account 3-18 Admin Session Timeout 3-19 Configuring RADIUS for Administrator Authentication 3-19 CHAPTER 4 Configuring Sponsor Authentication 4-1 Configuring Local Sponsor Authentication 4-1 Add New Local User Account 4-1 Edit Existing User Account 4-3 Delete Existing User Account 4-4 Configuring Active Directory (AD) Authentication 4-6 Add Active Directory Domain Controller 4-7 Edit Existing Domain Controller 4-8 Delete Existing Domain Controller Entry 4-10 Configuring LDAP Authentication 4-10 Add an LDAP Server 4-11 Edit an Existing LDAP Server 4-13 Delete an Existing LDAP Server Entry 4-15 Configuring RADIUS Authentication 4-16 Add a RADIUS Server 4-16 Edit an Existing RADIUS Server 4-17 Delete an Existing RADIUS Server Entry 4-18 Configuring Sponsor Authentication Settings 4-19 Cisco NAC Guest Server Installation and Configuration Guide iv OL-28256-01 Contents Changing the Order of Authentication Servers 4-19 Session Timeouts 4-20 Configuring Active Directory Single Sign-On 4-20 Requirements for Active Directory Single Sign-On 4-21 Mapping User Group with AD SSO 4-22 Configuring AD SSO on Multiple Domains 4-23 Verifying the Configuration for Multiple Domain 4-24 Configuring AD SSO on Multiple Forests 4-24 Verifying the Configuration for Multiple Forest 4-26 Troubleshooting the AD SSO Configuration 4-26 CHAPTER 5 Configuring Sponsor User Groups 5-1 Adding Sponsor User Groups 5-2 Editing Sponsor User Groups 5-5 Deleting User Groups 5-8 Specifying the Order of Sponsor User Groups 5-9 Mapping to Active Directory Groups 5-10 Mapping to LDAP Groups 5-11 Mapping to RADIUS Groups 5-12 Assigning Guest Roles 5-13 Assigning Time Profiles 5-14 CHAPTER 6 Configuring Guest Policies 6-1 Setting Username Policy 6-1 Setting Password Policy 6-3 Setting Guest Details Policy 6-4 Configuring Guest Roles 6-5 Adding Guest Roles 6-5 Editing Guest Roles 6-6 Edit NAC Roles 6-6 Edit RADIUS Attributes 6-7 Edit Locations 6-8 Edit Authentication Settings 6-9 Configuring Time Profiles 6-10 Adding Time Profiles 6-10 Editing Time Profiles 6-12 Deleting Time Profiles 6-14 Cisco NAC Guest Server Installation and Configuration Guide OL-28256-01 v Contents External Guest Authentication 6-14 CHAPTER 7 Integrating with Cisco NAC Appliance 7-1 Adding Clean Access Manager Entries 7-2 Editing Clean Access Manager Entries 7-3 Deleting Clean Access Manager Entries 7-4 Configuring the CAM for Reporting 7-5 Adding RADIUS Accounting Server 7-5 Configure CAM to Format RADIUS Accounting Data 7-6 CHAPTER 8 Configuring RADIUS Clients 8-1 Overview 8-1 Adding RADIUS Clients 8-2 Editing RADIUS Clients 8-3 Deleting RADIUS Clients 8-5 CHAPTER 9 Guest Activity Logging 9-1 Configuring Syslog Monitoring Settings 9-1 Guest Activity Logging with Replication Enabled 9-2 CHAPTER 10 Guest Account Notification 10-1 Configuring Email Notification 10-2 Configuring SMS Notification 10-3 Print Notification 10-4 CHAPTER 11 Customizing the Application 11-1 User Interface Templates 11-1 Adding a User Interface Template 11-2 Editing a User Interface Template 11-3 Editing the Print Template 11-5 Editing the Email Template 11-7 Editing the SMS Template 11-8 Using Time Profiles 11-10 Deleting a Template 11-11 Setting the Default Interface Mapping 11-11 Setting User Default Redirection 11-11 Cisco NAC Guest Server Installation and Configuration Guide vi OL-28256-01 Contents CHAPTER 12 Configuring Hotspots 12-1 Configuring Hotspot Sites 12-1 Adding Hotspot Sites 12-1 Edit Existing Hotspot Site 12-5 Delete Existing Hotspot Site 12-6 Configuring Payment Providers 12-6 Adding a Payment Provider 12-7 Editing Payment Provider 12-8 Creating Hotspot Web Pages 12-9 Integrating with Wireless LAN Controller 12-9 Integrating with Switch 12-9 Creating a Login Page (WLC) 12-10 Creating a Login Page (Switch) 12-11 Adding Realms Support (Switch) 12-12 Customizing the Login Page 12-13 Acceptable Usage Policy (WLC) 12-14 Acceptable Usage Policy (Switch) 12-14 Creating a Self Service Page (WLC) 12-15 Creating a Self Service Page (Switch) 12-17 Customizing the Self Service Page 12-18 Auto Login 12-19 Modifying Additional Fields 12-20 Creating a Billing Page (WLC) 12-21 Create a Billing Page (Switch) 12-24 Customizing the Billing Page 12-25 Creating a Password Change Page (WLC and Switch) 12-26 Authentication Options 12-27 The ngsOptions Configuration Object 12-29 Overriding Error/Status Messages 12-29 Overriding Form Labels 12-29 Default Error/Status Messages 12-30 Default Form Labels 12-32 CHAPTER 13 Backup and Restore 13-1 Configuring Backup 13-1 Saving Backup Settings 13-2 Taking Snapshots 13-3 Scheduling Backups 13-3 Restoring Backups 13-4 Cisco NAC Guest Server Installation and Configuration Guide OL-28256-01 vii Contents CHAPTER 14 Replication and High Availability 14-1 Configuring Replication 14-1 Configuring Provisioning 14-3 Replication Status 14-4 Recovering from Failures 14-4 Network Connectivity 14-4 Device Failure 14-4 Deployment Considerations 14-5 Connectivity 14-5 Load Balancing 14-5 Web Interface 14-5 RADIUS Interface 14-5 Data Replication 14-6 CHAPTER 15 Management, Logging and Troubleshooting 15-1 SNMP Configuration