Support Support Downloads Knowledge Base Case Manager My Juniper Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

[WLC] Configuring wired-authentication with fall-thru authentication of web-portal and local authentication



Article ID: KB28253 KB Last Updated: 21 Feb 2020Version: 3.0

This document discusses the configuration for wired-authentication using fall-thru authentication of the web-portal (web-portal page from SmartPass) and local authentication on the WLC.


Clearing the port type in preparation for wired authentication

  1. Select the port for wired authentication, remove it from any VLANs and make sure it’s not configured as an AP port. You can reset the port to the port’s default configuration using the following command:

  2. WLC# clear port type <port_nr>

  4. Remove the port from one or more VLANs using the following command:

  5. WLC# clear vlan <vlan_name> port <port_nr>


Configure the WLC for web-portal wired-authentication


WLC Configuration

  1. Configure the SmartPass server as a radius server on WLC. Default port for radius authentication is 1812:

  2. WLC# set radius server <SP_name> address <SP_IP_address> auth-port <auth_port> deadtime 0 key <secret_key>

  4. Configure a server group and add the configured SmartPass server as a member:

  5. WLC# set server group <server_group_name> members <SP_name>

  7. Configure the SmartPass as a RADIUS dynamic authorization client (DAC):

  8. WCL# set radius dac <dac_name> address <SP_IP_address> replay-protect disable

  10. Configure the wired dynamic authorization to the configured RADIUS dynamic authorization client:

  11. WLC# set authorization dynamic wired <dac_name>

  13. Configure the web wired authentication local on the WLC:

  14. WLC# set authentication web wired ** local

  16. Configure the VLAN attribute for web-portal-wired users

  17. WLC# set user web-portal-wired attr vlan-name <VLAN_name>

  19. Name the port with a descriptive name using the following command:

  20. WLC# set port <port_nr> name <port_name>

  22. Set the port type, VLAN tag and the fall-thru authentication for web-portal:

  23. WLC# set port type wired-auth <port_nr> tag <VLAN_tag_nr> auth-fall-thru webportal

  25. The default maximum number of wired clients per port is 1. This can be changed using the command:

  26. WLC# set port type wired-auth <port_nr> max-sessions

  28. Configure the web-portal form(web-portal page from SmartPass server):

  29. WLC# set port type wired-auth <port_nr> web-portal-form https://<SP_IP_address>:<SP_https_port>/gp2/webportal/ext/webPortalAuthLogin

  31. Configure the ACL and permit all IP addresses or a specific subnet --> SmartPass IP address. The default ACL for web-portal is named portalacl.

  32. WLC# set security acl name portalacl permit udp eq 68 eq 67
    WLC# set security acl name portalacl permit ip <SP_IP_address>
    WLC# set security acl name portalacl deny capture
    WLC# commit security acl portalacl



WLC-TAC# set radius server 2k8-sp address auth-port 11812 deadtime 0 encrypted-key ABC123
WLC-TAC# set server group 2k8sp members 2k8-sp
WLC-TAC# set radius dac sp-radius-dac address replay-protect disable encrypted-key ABC123
WLC-TAC# set vlan 424 name MD424
WLC-TAC# set vlan 424 port 1 tag 424
WLC-TAC# set authentication web wired ** local
WLC-TAC# set authorization dynamic wired sp-radius-dac
WLC-TAC# set user web-portal-wired attr filter-id
WLC-TAC# set user web-portal-wired attr vlan-name MD424
WLC-TAC# set port type wired-auth 2 tag 424 max-sessions 1 auth-fall-thru web-portal web-portal-form
WLC-TAC# set security acl name portalacl permit udp eq 68 eq 67
WLC-TAC# set security acl name portalacl permit ip
WLC-TAC# set security acl name portalacl deny capture
WLC-TAC# commit security acl portalacl

SmartPass configuration

Configure the WLC as a RADIUS client on SmartPass.

  1. Go to SmartPass --> Setup --> RADIUS Client Settings --> Authorized Radius Clients -->

  2. Click Add button --> configure the IP Address, Shared Secret key (must be the same key as the one configured on WLC for the SmartPass server) and the Vendor type (which should be “Trapeze” ).
Modification History:

2020-02-21: Changed password to “ABC123".

Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search