Monday, February 19, 2018

Encrypted guest wifi with captive portal help

I am trying to set up a guest wifi network where internal employees with their BYOD need to type a password to get into wifi, then redirected to a captive portal page which displays terms and policy. But also, I don't want them to re-authenticate portal every day or every time they go out for lunch/breaks. I'm aiming for guests to re-authenticate(accepting terms and policy) every week or so.

I tried to set this up with Cisco WLC 2504 with L2 WPA2+PSK, L3 Web-authentication and sleeping client feature. I tested by going out for lunch ~ 1 hour and when I came back, wireless controller disassociated the wifi client, and asked me to re-authenticate to a captive portal every now and then. Looked like sleeping client feature only worked 3 out of 5 times.

Then, I found out Cisco limitations below

The authentication of sleeping clients feature is not supported with Layer 2 security and web authentication enabled. The authentication of sleeping clients feature is supported only on WLANs that have Layer 3 security enabled.

Can someone help me what I need to accomplish this? As a side question, does anyone know if packetfence can do this?

End goal is, 1. guest wifi data encryption 2. Captive portal with terms and policy 3. guests not having to re-auth after lunch/longer break - (important) If they accepted terms and policy once, I don't want them to re-auth for another week

Thanks for any input.



No comments:

Post a Comment