PURPOSE
This guide explains how to configure Huawei iMaster NCE (Cloud Campus) in order to use each Access Point for IPERA Starling Platform.
ARCHITECTURE
HUAWEI iMASTER CONFIGURATION STEPS
Log in to your Huawei iMaster NCE (CloudCampus) web interface. At the top, click on Design > Template Management.
On the left, click ACL and then Create. Configure with:
Set the Name: IPERA
Select ACL Type: User
Set ACL Number: 6000
Under Rule List click Add and add the required domains as per below. Please refer to this list.
Select Rule Type: domain
Set IP/Domain: *insert domain here*
It is mandatory to add the following domains to ACL
- engage.iperawifi.com
- static.iperawifi.com
If you wish to support social network logins, you need to add rules for domains below for each network you plan to support
|
|
login.microsoftonline.com | accounts.google.com | |
| aadcdn.msauth.net | www.google.com | ||
| login.live.com | fonts.gstatic.com | ||
| akamaihd.net | play.google.com | ||
| aadcdn.msftauth.net | ssl.gstatic.com | ||
| www.facebook.com | accounts.youtube.com | ||
| www.facebook.net | accounts.google.com | ||
| static.xx.fbcdn.net | TikTok (**) | *.tiktok.com | |
| api.twitter.com | firebaseinstallations.googleapis.com | ||
| abs-0.twimg.com | storage.googleapis.com | ||
| pbs.twimg.com | *.ibytedtos.com | ||
|
|
www.linkedin.com | *.tiktokv.com | |
| static.licdn.com | open-api.tiktok.com | ||
| media.licdn.com | www.tiktok.com | ||
| ponf.linkedin.com | *.ttwstatic.com | ||
| platform.linkedin.com | *.tiktokcdn.com | ||
| Apple | www.apple.com | ||
| appleid.apple.com | |||
| appleid.cdn-apple.com | |||
| is4-ssl.mzstatic.com | |||
(*) Please refer to the below URL if you wish to use Microsoft login method
https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/review-admin-consent-requests
(**) Google, Facebook, Twitter, and Apple should be also added for TikTok
Click OK to save.
Next, on the left, click URL Template and then Create. Configure with:
Set Name: IPERA
Select Template type: Cloud platform-based relay authentication
Under Parameters in template, click Create and Configure with:
Set Parameter: loginurl
Set Value Assignment Mode: Replace the existing value
Set Parameter Name: switch_url
Click the Tick icon to add the item. You'll need to add the below ones too:
Set Parameter: redirect-url
Set Value Assignment Mode: Replace the existing value
Set Parameter Name: originalUrl
Set Parameter: ssid
Set Value Assignment Mode: Replace the existing value
Set Parameter Name: ssid
Set Parameter: user-mac
Set Value Assignment Mode: Replace the existing value
Set Parameter Value: user-mac
Set Parameter: user-ip
Set Value Assignment Mode: Replace the existing value
Set Parameter Name : uaddress
Set Parameter: device-mac
Set Value Assignment Mode: Replace the existing value
Set Parameter Name : AP-MAC
Click OK to save.
Next, on the left, click RADIUS Relay Server and then Create. Configure with:
Set Name: IPERA
Select Authentication service: Portal authentication
Select Authentication protocol: PAP
Under Authentication server address click Add and configure with:
Set Priority: 1
Set Host: *insert radius_server_ip here*
Set Port: 1812
Set Key: *insert radius_secret here*
Add again and configure with:
Set Priority: 2
Set Host: *insert radius_server2_ip here*
Set Port: 1812
Set Key: *insert radius_secret here*
Under Accounting server address click Add and configure with:
Set Priority: 1
Set Host: *insert radius_server_ip here*
Set Port: 1813
Set Key: *insert radius_secret here*
Add again and configure with:
Set Priority: 2
Set Host: *insert radius_server2_ip here*
Set Port: 1813
Set Key: *insert radius_secret here*
Click Submit to save. Set the following:
Set Timeout period: 5
Select Load balancing mode: Strict accordance with priority
Click OK to save.
Next, at the top, click on Provision> Site Configuration and on the left menu click AP > SSID. Click Create and configure with:
Set SSID Name: Guest WiFi (or whatever SSID name you wish)
Select Working status: On
Select Effective radio: 2.4 and 5G
Click Next and configure with:
Select WLAN security policy: Open network
Select Push pages: On
Select Portal pushing mode: Relay authentication by cloud platform
Select Interconnection mode: RADIUS relay
Select Page push protocol: HTTPS
Set Username: username
Set Password parameter name: password
Select Redirect URL matching rule: Redirect URL parameter
Set Parameter name for the authentication success redirect URL: successUrl
select RADIUS relay server: select IPERA
Set Portal authentication free: Disabled
Set Real-time acocunting: Enabled
Set Billing reporting cycle: 5
Select Default permit rule: select IPERA
Select Bypass policy: Authenticated users can continue accessing the network, and new users are not allowed to access the network.
Click Next and then OK to save.
Next, at the top, click on Admission > Page Management. Click the Portal Page Push Policy at the top. Click Create and Configure with:
Set Name: IPERA
Select Access Mode: Wireless
Select Match SSIDs: Yes, and click Add. Choose the SSID you created earlier
Select Page Push authentication mode: Cloud platform-based relay authentication
Select Interconnection mode: RADIUS Relay
Select URL template: select IPERA
Set Third-party authentication URL: *insert access_url here*
Click OK to Save.
PARAMETERS FOR THE CONFIGURATION
AWS
IPERA Radius IP Address (Primary): 35.156.39.198
IPERA Radius IP Address (Secondary): 35.156.23.166
Shared Key: (It will be shared within a separate email)
Authentication Port Number: 1812
Accounting Port Number: 1813
Third-party authentication URL: https://engage.iperawifi.com/onboarding/
Azure
IPERA Radius IP Address (Primary): 20.174.25.122
IPERA Radius IP Address (Secondary): 20.174.42.3
Shared Key: (It will be shared within a separate email)
Authentication Port Number: 1812
Accounting Port Number: 1813
Third-party authentication URL: https://me.iperawifi.com/onboarding/
Any changes on the above parameters and values will be communicated with IPERA customers in advance.
Note: IPERA servers to send the post request to the iMaster; the iMaster should have been configured with a public IP.
Comments
0 comments
Please sign in to leave a comment.