Skip to content

Cisco WLC

Compatibility

The below instruction pertains to Cisco WLCs of 2504 and 5520 series with IOS 8.2.166.0

Social WiFi has been tested and is proven to work on the following configurations:

Cisco 2500 Series Wireless Controller

  • versions up to 8.5.131.0

Cisco AIR-CAP3702I-E-K9

  • versions compatibile with the Controller

Accessing the device’s administrative panel

Log in to the administrative panel with root permissions and press Advanced.

Device configuration

RADIUS configuration

Security → AAA → Radius → Authentication

2023-02-02_14-10.png

Security → AAA → Radius → Authentication → New

Server Index (Priority)Leave default (1)
Server IP Address35.205.62.147
Shared Secret FormatASCII
Shared SecretRadius Secret available in Access Points tab of the Social WiFi Panel
Confirm Shared SecretRadius Secret available in Access Points tab of the Social WiFi Panel
Key WrapLeave unchecked
Port Number31812
Server StatusEnabled
Support for CoADisabled
Server Timeout5 seconds
Network UserUnchecked
ManagementUnchecked
Management Retransmit TimeoutLeave default (2)
IPSecLeave unchecked

image_263752.png

Press Apply.

Now, configure as follows:

Auth Called Station ID TypeAP MAC Address
Use AES Key WrapLeave unchecked
MAC DelimiterHyphen
Framed MTU1300

2023-02-07_12-14.png

Press Apply.

Now, in the menu on the left go to the AAA → Radius → Accounting tab and add new accounting server.

Server Index (Priority)Leave default (1)
Server IP Address35.205.62.147
Shared Secret FormatASCII
Shared SecretRadius Secret available in Access Points tab of the Social WiFi Panel
Confirm Shared SecretRadius Secret available in Access Points tab of the Social WiFi Panel
Port Number31813
Server StatusEnabled
Server Timeout5 seconds
Network UserLeave unchecked
IPSecLeave unchecked

2023-02-02_14-51.png

Press Apply.

2023-02-07_12-16.png

DNS Walled Garden Configuration

Now, go to the Access Control Lists → Access Control Lists in the same tab and press New… to add a new list.

2023-02-02_14-58.png

Access Control List Namesw_walledgarden
ACL TypeIPv4

2023-02-02_14-59.png

Press Apply.

Hover the coursor over the blue icon on the right side of sw_walledgarden text and press “Add/Remove URL”.

2023-02-02_15-02.png

Add these entries one by one:

socialwifi.com

sw-login.com

facebook.com

fbcdn.net

twitter.com

x.com

twimg.com

linkedin.com

licdn.com

connect.facebook.net

www.googletagmanager.com

www.googleadservices.com

googleads.g.doubleclick.net

2023-02-07_15-24.png

Captive Portal/Hotspot configuration

Now, go to the Security -> Web Auth → Web Login Page and configure as follows:

Web Authentication TypeExternal (Redirect to external server)
Redirect URL after login[leave empty]
External Webauth URLhttps://login.socialwifi.com/

2023-02-02_15-14.png

Press Apply.

Go to Management → HTTP-HTTPS and disable WebAuth SecureWeb and HTTPS Redirection:

WebAuth SecureWebDisabled
HTTPS RedirectionDisabled

2023-02-07_11-15_1.png

Press Apply.

In the Controller → Interfaces section, make sure that the “virtual” interface’s address is not set to 1.1.1.1 (it used to be the default value). If it is, change it to 192.0.2.1.

2023-02-07_11-22.png

Network settings configuration

Now, go to the WLANs → WLANs and create the WLAN network or edit if you already have one.

On the upper right press the Go button next to “Create New”.

2023-02-02_15-35.png

2023-02-02_15-41.png

Press Apply.

Edit your WLAN and go to security Layer 2 tab. Set “Layer 2 Security” as None.

image_193853.png

Next, go to the Layer 3 tab and configure as follows:

Layer 3 SecurityWeb Policy
Check the boxAuthentication
Preauthentication ACLIPv4 sw_walledgarden
IPv6None
WebAuth FlexAclNone
Sleeping ClientLeave unchecked
Over-ride Global ConfigLeave unchecked

2023-02-02_15-44.png

Go to AAA Servers tab and configure as follows:

Authentication Servers EnabledYes
Server 1IP:35.205.62.147, Port:31812
Accounting Servers EnabledYes
Server 1IP:35.205.62.147, Port:31813
Radius Server Accounting Interim UpdateYes
Radius Server Accounting Interim Interval600

Press Apply.

2023-02-02_15-47.png

Adding the device to Social WiFi platform

Monitor → Access Points → Radios → 802.11a/n/ac or 802.11b/g/n

  • Copy the MAC addresses of the Access Points you would like to add to Social WiFi platform.
  • Go to the Social WiFi Panel.
  • Choose the place to which you would like to add the device.
  • In the “Access Points” tab, press “Add” (upper right corner), paste the MAC address you copied into the form (adding a name is optional) and click “Create”.