SSID with Radius auth

TROB82
Comes here often

SSID with Radius auth

Morning,

I am setting up a new Meraki wireless network for a customer with a hand full of SSIDs. 2 of these are radius authenticated and seem to be working but I need a way of failing users who are unauthenticated to the guest SSID splash screen, can this be done and if so are there any tips.

 

Kind Regards

 

Tom

6 Replies 6
marce1000
Getting noticed

 

  - What do you mean by : ... I need a way of failing users...

 

 M.

TROB82
Comes here often

Hi, 

 

Sorry I mean a way of forcing the Radius unauthenticated users to connect to the guest ssid for self registration.

PhilipDAth
Kind of a big deal
Kind of a big deal

There is no way of doing this if you are using WPA2-Enterprise mode authentication.

 

You typically create a seperate guest SSID.

So I have a seperate Guest SSID set which has a self registration splash screen working as requested. But this request is for when they connect to the corporate ssid and do not authenticate they would like the users to be pushed over to the guest SSID. do you know any way this could be achieved. Thank you

RaphaelL
Kind of a big deal
Kind of a big deal

You can use filter-Id / Reply-Message / Airespace-ACL-Name / Aruba-User-Role to push a group policy to the desired client. In that group policy specify a VLAN ( Guest vlan ).

 

https://documentation.meraki.com/MR/Encryption_and_Authentication/Configuring_RADIUS_Authentication_...

TROB82
Comes here often

Thank you for the response, So this is what I was looking at too but I was thinking i could create a group policy but if i forced it to a guest vlan it would just pass the user over to the guest vlan with no self registration from the splash screen currently set in the Guest SSID. The Customer would like them to still go through the self registration when placed on the Guest VLAN.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels