All Products
Search
Document Center

Secure Access Service Edge:Network access best practices

Last Updated:Aug 28, 2026

Secure Access Service Edge (SASE) integrates a RADIUS (Remote Authentication Dial-In User Service) component and supports both the 802.1X protocol and portal-based access. Use these capabilities to control which users and devices reach your enterprise office network and to keep that access compliant. This topic describes how to configure network access for employees, guests, and dumb terminals over wireless and wired networks.

Considerations

Review the following information before you configure network access:

  • Example devices — This topic uses H3C devices as an example for the wireless controller and the switch.

  • Employee and guest networks — You can configure employee access and guest access at the same time. Use a separate SSID for each network and configure the corresponding backend policies.

  • Console navigation — In Use case 1, Use case 2, and Use case 3, the Authentication Server, Network Device, Wi-Fi Management, and Certificate Management tabs are all on the Network Access Control > Basic Configurations page of the SASE console. Steps that start with "On the ... tab" continue on that page.

Use case 1: Configure wireless network access for employees

SASE secures network access with an 802.1X authentication solution and gives employees a one-click connection process. Employees use the SASE client to connect to the corporate network quickly and securely anywhere the office network reaches. Complete the required configurations both in the SASE management console and on your on-premises wireless controller.

Step 1: Configure the authentication server (RADIUS)

RADIUS is a network protocol that provides centralized authentication, authorization, and accounting (AAA) services. SASE provides a Cloud Authentication Server, and you can also configure your own authentication server.

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Network Access Control > Basic Configurations.

  3. On the Authentication Server tab, view the Cloud Authentication Server information, or click Add Authentication Server. Complete one of the following options:

    • View the cloud authentication server

      1. In the upper-right corner of the page, click Cloud Authentication Server.

      2. In the Cloud Authentication Server pane, view the details of the cloud authentication server that SASE provides.

    • Add an authentication server

      1. Click Add Authentication Server.

      2. In the Add Authentication Server pane, configure the Authentication Server Name and the IP Address of the server, and then click Save.

        Note

        The default authentication port, shown as User Wi-Fi Authentication Interface, is 1812. The default accounting port, shown as User Wi-Fi Billing Interface, is 1813.

      3. On the Deployment and Installation tab, view the Recommended Server Specifications and the Server Deployment Commands required to deploy RADIUS.

      4. Copy the Server Deployment Commands and deploy RADIUS on your own server.

      5. After the deployment finishes, check the deployment status in the list.

        An authentication server that is deployed successfully shows the status Online.

Step 2: Configure network device information

A wireless controller centrally manages and controls wireless access points (APs), and lets you configure, monitor, and optimize the wireless network from one place. Register your on-premises wireless controller in the SASE console.

  1. On the Network Device tab, click Add Network Device.

  2. In the Add Network Device dialog box, configure the following parameters and click OK.

Parameter

Description

Device Name

Enter a name for the device.

Device Brand

Select the brand of your wireless controller.

Device Type

Select the device type for a wireless controller.

IP Address

Enter the IP address or IP address range of the wireless controller.

MAC Address

Enter the MAC address of the wireless controller.

CoA Port

Enter the CoA port of the wireless controller.

Step 3: Configure Wi-Fi management

Create a network instance for the wireless network that employees connect to.

  1. On the Wi-Fi Management tab, click Create Network Instance.

  2. In the Enterprise Wireless Network Configuration dialog box, configure the Network SSID and the Authentication Mode that employees use to access the network. Only EAP-TLS is supported. Then click OK.

Step 4: Configure certificate management

After a device connects to the enterprise office network through SASE, the system automatically issues the SASE CA certificate and a network access certificate to the SASE client. Only devices with these certificates installed can access internal enterprise applications over the enterprise wireless network. If the certificates that are issued automatically do not fit your business scenario, you can change the installation scope or the validity period, or customize the certificate organization name.

  1. Click the Certificate Management tab.

  2. On the Certificate Management tab, complete the Network Access Certificate Configuration, the CA Certificate Configuration, and the Global Settings.

Step 5: Configure the on-premises wireless controller (H3C example)

Configure the RADIUS scheme, the ISP domain, and wireless 802.1X authentication in the console of your on-premises wireless controller.

Configure RADIUS

  1. Log on to the console of the H3C wireless controller.

  2. At the bottom of the page, select Network. In the left-side navigation pane, choose Network Security > Authentication.

  3. On the RADIUS tab, click image to add a RADIUS scheme.

  4. On the Add RADIUS Scheme page, configure the RADIUS settings and click OK.

Parameter

Description

Example value

Scheme Name

Enter a custom name for the RADIUS scheme.

sase-r1

Authentication Server

Configure the authentication server. If you have multiple authentication servers, you can add them as backup servers. You can find the required values on the Network Access Control > Basic Configurations > Authentication Server tab of the SASE console. This tab lists the Cloud Authentication Server that SASE provides and every authentication server that you added by using Add Authentication Server. For each server, the tab shows its Name, Server Status, IP address, and key.

VRF: Default public network; Type: Default IP address; IP address: 121.40..; Port: 1812; Shared key: enter the key; Status: Active

Accounting Server

Configure the accounting server. If you have multiple accounting servers, you can add them as backup servers. The accounting server uses the same IP address and shared key as the authentication server, and uses port 1813.

VRF: Default public network; Type: Default IP address; IP address: 121.40.. (same as the authentication server); Port: 1813; Shared key: enter the key (same as the authentication server); Status: Active

Advanced Settings

Click Show Advanced Settings and set Real-time Accounting Update Interval to 60 seconds.

60

Configure the ISP domain

  1. In the left-side navigation pane, choose Network Security > Authentication. On the ISP Domain tab, click image to add an ISP domain.

  2. On the Add ISP Domain page, configure the ISP domain with the following parameters and click OK.

    Configure the following parameters: set Domain Name to a custom name, such as sase-dm1, set Status to Active, and select LAN Access for Access Mode. In the LAN access AAA scheme, set Authentication to RADIUS and select the RADIUS scheme that you created. Set Authorization and Accounting to RADIUS and select the same scheme.

Configure the wireless network (802.1X authentication)

  1. In the left-side navigation pane, choose Wireless Configuration > Wireless Network.

  2. On the Wireless Network tab, click image to add a wireless network.

  3. On the page for adding a wireless service, configure Wireless Service Name, SSID, and Default VLAN, and turn on Wireless Service. Then click OK and Go to Advanced Settings.

    In the Security Authentication section, set Authentication Mode to 802.1X Authentication (Unencrypted) and Authentication Location to Central AC.

    Note

    You can get the SSID of the network instance that you created on the Network Access Control > Basic Configurations > Wi-Fi Management tab of the SASE console.

  4. On the Link Layer Authentication tab, set Authentication Mode to 802.1X Authentication and set Domain Name to the ISP domain that you created. Keep the default values for the other settings. Then click OK.

  5. On the Binding tab, click the AP that you want to bind and click OK.

  6. In the left-side navigation pane, choose Network Security > Access Control.

  7. In the upper-right corner of the page, click image. On the 802.1X page, click the configuration option next to Authentication Method, select EAP from the drop-down list, and click OK.

Step 6: Enable dynamic authorization (CoA)

CoA is usually implemented on the RADIUS protocol, and sends a RADIUS CoA-Request message to trigger an authorization change. After the wireless controller receives such a request, it updates the session parameters of the user based on the request content, and returns a CoA-ACK (acknowledgment) or CoA-NAK (rejection) message to the RADIUS server.

  1. Connect to the wireless controller (AC) with a console cable.

  2. Run the following commands to enable CoA.

[AC] radius dynamic-author server
[ac-radius-da-server] client ip <Radius server IP> key simple <Sharesecret>

Replace <Radius server IP> with the IP address of the RADIUS server, and replace <Sharesecret> with the shared key of that server.

Note

You can view the Radius Server IP address and the SharedSecret (shared key) on the Network Access Control > Basic Configurations > Authentication Server tab of the SASE console.

Step 7: Configure a network access policy

When employees access the enterprise office network through SASE, a network access policy gives you fine-grained isolation and control over the access permissions of employees and devices, which improves network security and management efficiency.

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Network Access Control > Office Network.

  3. On the Network Access Permissions tab, click Create Policy.

  4. In the Create Policy pane, configure the following parameters and click OK.

Parameter

Description

Policy Name

Enter a name for the policy.

Effective Scope

Set Effective Scope to Applicable User. Based on your business requirements, click Select and refine the scope by All Users, Specific User Group, Specific Device, or Specific Device Tag.

VLAN ID

Set the VLAN ID that is configured on your wireless controller. Valid values: 1 to 4094.

ACL ID

Set the ACL ID that is configured on your wireless controller. The valid value range depends on the brand and model of the network device that you use.

Terminal Type

Select the terminal types that the policy applies to.

Network Permissions

Select the wireless network.

Wi-Fi Network Scope

Select All Wi-Fi Networks, or select Specific Wi-Fi Networks based on your requirements.

Priority

Set the priority of the policy. A smaller value indicates a higher priority.

Policy Status

Turn on the policy status.

Advanced Settings

Set the Authentication Server and the Network Device for Access Control that the policy applies to.

Step 8: Install and log on to the SASE client

Install and log on to the SASE client on an endpoint that is connected to the Internet. What you do after you log on to the client is described in Install and log on to SASE client.

Step 9: View authentication and network access records

After you complete the preceding steps, you can view network access records or employee authentication logs in the SASE console.

  • View employee authentication logs

    1. In the navigation pane on the left of the SASE console, choose Log Analysis > Log Audit.

    2. On the Access Logs > User Authentication Logs tab, view the network access authentication status of employees.

  • View network access records

    1. Log on to the Secure Access Service Edge console.

    2. In the navigation pane on the left, choose Network Access Control > Office Network.

    3. On the Network Access History tab, view the network access status of employees. You can also perform the Disable and Enable operations.

Use case 2: Configure wired network access for employees

This use case configures 802.1X authentication on a wired network to grant network access. Configure the settings in the SASE management console and on your on-premises switch. Step 1 is the same as in Use case 1: you configure the authentication server (RADIUS) before you register the switch.

Step 1: Configure the authentication server (RADIUS)

RADIUS is a network protocol that provides centralized authentication, authorization, and accounting (AAA) services. SASE provides a Cloud Authentication Server, and you can also configure your own authentication server.

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Network Access Control > Basic Configurations.

  3. On the Authentication Server tab, view the Cloud Authentication Server information, or click Add Authentication Server. Complete one of the following options:

    • View the cloud authentication server

      1. In the upper-right corner of the page, click Cloud Authentication Server.

      2. In the Cloud Authentication Server pane, view the details of the cloud authentication server that SASE provides.

    • Add an authentication server

      1. Click Add Authentication Server.

      2. In the Add Authentication Server pane, configure the Authentication Server Name and the IP Address of the server, and then click Save.

        Note

        The default authentication port, shown as User Wi-Fi Authentication Interface, is 1812. The default accounting port, shown as User Wi-Fi Billing Interface, is 1813.

      3. On the Deployment and Installation tab, view the Recommended Server Specifications and the Server Deployment Commands required to deploy RADIUS.

      4. Copy the Server Deployment Commands and deploy RADIUS on your own server.

      5. After the deployment finishes, check the deployment status in the list.

        An authentication server that is deployed successfully shows the status Online.

Step 2: Configure network device information

A switch connects network devices of different types, such as computers, servers, printers, and routers, so that these devices can communicate and exchange data. Register your on-premises switch in the SASE console.

  1. On the Network Device tab, click Add Network Device.

  2. In the Add Network Device dialog box, configure the following parameters and click OK.

Parameter

Description

Device Name

Enter a name for the device.

Device Brand

Select the brand of your switch.

Device Type

Select the device type for a wired switch.

IP Address

Enter the IP address or IP address range of the switch.

MAC Address

Enter the MAC address of the switch.

CoA Port

Enter the CoA port of the switch.

Step 3: Configure certificate management

After a device connects to the enterprise office network through SASE, the system automatically issues the SASE CA certificate and a network access certificate to the SASE client. Only devices with these certificates installed can access internal enterprise applications over the enterprise wired network. If the certificates that are issued automatically do not fit your business scenario, you can change the installation scope or the validity period, or customize the certificate organization name.

  1. Click the Certificate Management tab.

  2. On the Certificate Management tab, complete the Network Access Certificate Configuration, the CA Certificate Configuration, and the Global Settings.

Step 4: Configure the on-premises switch (H3C example)

Configure the RADIUS scheme, the ISP domain, and wired 802.1X authentication in the console of your on-premises switch.

Configure RADIUS

  1. Log on to the console of the H3C switch.

  2. At the bottom of the page, select Network. In the left-side navigation pane, choose Network Security > Authentication.

  3. On the RADIUS tab, click image to add a RADIUS scheme.

  4. On the Add RADIUS Scheme page, configure the RADIUS settings and click OK.

Parameter

Description

Example value

Scheme Name

Enter a custom name for the RADIUS scheme.

sase-r1

Authentication Server

Configure the authentication server. If you have multiple authentication servers, you can add them as backup servers. You can find the required values on the Network Access Control > Basic Configurations > Authentication Server tab of the SASE console. This tab lists the Cloud Authentication Server that SASE provides and every authentication server that you added by using Add Authentication Server. For each server, the tab shows its Name, Server Status, IP address, and key.

VRF: Default public network; Type: Default IP address; IP address: 121.40..; Port: 1812; Shared key: enter the key; Status: Active

Accounting Server

Configure the accounting server. If you have multiple accounting servers, you can add them as backup servers. The accounting server uses the same IP address and shared key as the authentication server, and uses port 1813.

VRF: Default public network; Type: Default IP address; IP address: 121.40.. (same as the authentication server); Port: 1813; Shared key: enter the key (same as the authentication server); Status: Active

Advanced Settings

Click Show Advanced Settings and set Real-time Accounting Update Interval to 60 seconds.

60

Configure the ISP domain

  1. In the left-side navigation pane, choose Network Security > Authentication. On the ISP Domain tab, click image to add an ISP domain.

  2. On the Add ISP Domain page, configure the ISP domain and click OK.

    Configure the following parameters: set Domain Name to a custom name, such as sase-dm1, set Status to Active, and select LAN Access for Access Mode. In the LAN access AAA scheme, set Authentication to RADIUS and select the RADIUS scheme that you created. Set Authorization and Accounting to RADIUS and select the same scheme.

Configure the switch port (802.1X authentication)

  1. In the left-side navigation pane, choose Network Security > Access Control.

  2. On the 802.1X Authentication page, select GE1/0/3 for port-based authentication and click OK.

  3. Click Advanced Settings. On the Advanced Settings page, configure Mandatory Authentication ISP Domain of the Port and click OK.

    Set Mandatory Authentication ISP Domain of the Port to the name of the ISP domain that you created, such as sase-dm1. Keep the default values for the other parameters.

  4. In the upper-right corner of the page, click image. On the 802.1X page, click the configuration option next to Authentication Method, select EAP from the drop-down list, and click OK.

Step 5: Enable dynamic authorization (CoA)

CoA is usually implemented on the RADIUS protocol, and sends a RADIUS CoA-Request message to trigger an authorization change. After the network device receives such a request, it updates the session parameters of the user based on the request content, and returns a CoA-ACK (acknowledgment) or CoA-NAK (rejection) message to the RADIUS server.

  1. Connect to the access controller (AC) with a console cable.

  2. Run the following commands to enable CoA.

[AC] radius dynamic-author server
[ac-radius-da-server] client ip <Radius server IP> key simple <Sharesecret>

Replace <Radius server IP> with the IP address of the RADIUS server, and replace <Sharesecret> with the shared key of that server.

Note

You can view the Radius Server IP address and the SharedSecret (shared key) on the Network Access Control > Basic Configurations > Authentication Server tab of the SASE console.

Step 6: Configure a network access policy

When employees access the enterprise office network through SASE, a network access policy gives you fine-grained isolation and control over the access permissions of employees and devices, which improves network security and management efficiency.

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Network Access Control > Office Network.

  3. On the Network Access Permissions tab, click Create Policy.

  4. In the Create Policy pane, configure the following parameters and click OK.

Parameter

Description

Policy Name

Enter a name for the policy.

Effective Scope

Set Effective Scope to Applicable User. Based on your business requirements, click Select and refine the scope by All Users, Specific User Group, Specific Device, or Specific Device Tag.

VLAN ID

Set the VLAN ID that is configured on your switch. Valid values: 1 to 4094.

ACL ID

Set the ACL ID that is configured on your switch. The valid value range depends on the brand and model of the network device that you use.

Terminal Type

Select the terminal types that the policy applies to.

Network Permissions

Select the wired network.

Priority

Set the priority of the policy. A smaller value indicates a higher priority.

Policy Status

Turn on the policy status.

Advanced Settings

Set the Authentication Server and the Network Device for Access Control that the policy applies to.

Step 7: Install and log on to the SASE client

Install and log on to the SASE client on an endpoint that is connected to the Internet. What you do after you log on to the client is described in Install and log on to SASE client.

Step 8: View authentication and network access records

After you complete the preceding steps, you can view network access records or employee authentication logs in the SASE console.

  • View employee authentication logs

    1. In the navigation pane on the left of the SASE console, choose Log Analysis > Log Audit.

    2. On the Access Logs > User Authentication Logs tab, view the network access authentication status of employees.

  • View network access records

    1. Log on to the Secure Access Service Edge console.

    2. In the navigation pane on the left, choose Network Access Control > Office Network.

    3. On the Network Access History tab, view the network access status of employees. You can also perform the Disable and Enable operations.

Use case 3: Configure wireless network access for guests

SASE provides enterprises with a secure and convenient guest access solution. Separate SSIDs for employees and guests keep the network secure and improve the guest experience. When guests connect to the SASE guest Wi-Fi, only SMS verification code authentication on a portal page is supported.

Step 1: Configure portal authentication

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Network Access Control > Guest Network.

  3. In the upper-right corner of the page, click Authentication Configuration.

  4. On the Authentication Configuration page, complete the Authentication Portal Settings and the Custom Settings on Authentication Page. The detailed procedure is described in .

Step 2: Configure the authentication server (RADIUS)

RADIUS is a network protocol that provides centralized authentication, authorization, and accounting (AAA) services. For the guest network, SASE lets you configure your own authentication server.

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Network Access Control > Basic Configurations.

  3. On the Authentication Server tab, click Add Authentication Server.

  4. In the Add Authentication Server pane, configure the Authentication Server Name and the IP Address of the server, and then click Save.

    Note

    The default authentication port, shown as User Wi-Fi Authentication Interface, is 1812. The default accounting port, shown as User Wi-Fi Billing Interface, is 1813.

  5. On the Deployment and Installation tab, view the Recommended Server Specifications and the Server Deployment Commands required to deploy RADIUS.

  6. Copy the Server Deployment Commands and deploy RADIUS on your own server.

  7. After the deployment finishes, check the deployment status in the list.

    An authentication server that is deployed successfully shows the status Online.

Step 3: Configure Wi-Fi management

Create a network instance for the wireless network that guests connect to.

  1. On the Wi-Fi Management tab, click Create Network Instance.

  2. In the Enterprise Wireless Network Configuration dialog box, configure the Network SSID and the Authentication Mode that guests use to access the network. Only EAP-TLS is supported. Then click OK.

Step 4: Configure the on-premises wireless controller (H3C example)

Configure portal authentication for the guest network in the console of your on-premises wireless controller.

Configure RADIUS

  1. Log on to the console of the H3C wireless controller.

  2. At the bottom of the page, select Network. In the left-side navigation pane, choose Network Security > Authentication.

  3. On the RADIUS tab, click image to add a RADIUS scheme.

  4. On the Add RADIUS Scheme page, configure the RADIUS settings and click OK.

Parameter

Description

Example value

Scheme Name

Enter a custom name for the RADIUS scheme.

sase-r1

Authentication Server

Configure the authentication server. If you have multiple authentication servers, you can add them as backup servers. You can find the required values on the Network Access Control > Basic Configurations > Authentication Server tab of the SASE console. This tab lists every authentication server that you added by using Add Authentication Server. For each server, the tab shows its Name, Server Status, IP address, and key.

VRF: Default public network; Type: Default IP address; IP address: 121.40.. (same as the authentication server); Port: 2000; Shared key: enter the key (same as the authentication server); Status: Active

Advanced Settings

Click Show Advanced Settings and use the following settings. Keep the default values for the other parameters. Source IPv4 Address for Sending RADIUS Packets: the IPv4 address of the access device that is specified on the RADIUS server. This is usually the management interface IP address of the AC. Username Format Sent to the RADIUS Server: without domain name.

Source IPv4 Address for Sending RADIUS Packets: 121.40..; Username Format Sent to the RADIUS Server: without domain name

Configure the ISP domain

  1. In the left-side navigation pane, choose Network Security > Authentication. On the ISP Domain tab, click image to add an ISP domain.

  2. On the Add ISP Domain page, configure the ISP domain and click OK.

    Configure the following parameters: set Domain Name to a custom name, such as sase-dm1, set Status to Active, and select LAN Access for Access Mode. In the LAN access AAA scheme, set Authentication to RADIUS and select the RADIUS scheme that you created. Set Authorization and Accounting to RADIUS and select the same scheme.

Configure the portal authentication server

  1. In the left-side navigation pane, choose Network Security > Provisioning.

  2. On the Portal tab, click Portal Authentication Server.

  3. On the Portal page, click image to add a portal authentication server.

  4. On the Create Portal Authentication Server page, use the following settings, keep the default values for the other parameters, and click OK.

Parameter

Description

Example value

Server Name

Set a name for the portal authentication server.

sase-newptv4

IP address

Set the IP address of the RADIUS server.

121.40..

Server Reachability Detection

Turn on detection, and set Detection Duration and Action.

Detection Duration: 60 seconds; Action: select Log

Configure the portal web server

  1. In the left-side navigation pane, choose Network Security > Provisioning.

  2. On the Portal tab, click Local Portal Web Server.

  3. On the Portal page, click image to add a portal web server.

  4. On the Create Local Portal Web Server page, use the following settings and click OK.

Parameter

Description

Example value

Server Name

Enter a name for the server.

sase-newptv4

URL

Enter the server address.

121.40..

URL Parameters

Select User IP Address, enter a parameter name in URL Parameter Name, and click Add. Then select User MAC Address, enter a parameter name in URL Parameter Name, and click Add.

User IP address: userip; User MAC address: usermac

Configure the wireless service

  1. In the left-side navigation pane, choose Wireless Configuration > Wireless Network.

  2. On the Wireless Network tab, click image to add a wireless network.

  3. On the page for adding a wireless service, configure Wireless Service Name, SSID, and Default VLAN, and turn on Wireless Service. Then click OK and Go to Advanced Settings.

    In the Security Authentication section, set Authentication Mode to 802.1X Authentication (Unencrypted) and Authentication Location to Central AC.

    Note

    You can get the SSID of the network instance that you created on the Network Access Control > Basic Configurations > Wi-Fi Management tab of the SASE console.

  4. On the Link Layer Authentication tab, set Authentication Mode to IPv4 Portal Authentication, set Domain Name to the name of the ISP domain that you created, select the Web Server Name, and configure BAS-IP. Keep the default values for the other settings. Then click OK.

  5. On the Binding tab, click the AP that you want to bind and click OK.

Additional configurations

Connect to the AC with a console cable and run the following commands.

# Enable wireless portal roaming.
[AC] portal roaming enable
# Disable ARP entry pinning for wireless portal clients.
[AC] undo portal refresh arp enable
# Enable the validity check for wireless portal clients.
[AC] portal host-check enable
# Set the portal authentication server type to CMCC
[AC] portal server sase-newptv4
[AC-portal-server-newpt] server-type cmcc
[AC-portal-server-newpt] quit
# Configure the portal web server
[AC] portal web-server sase-newptv4
[AC-portal-websvr-newpt] url http://192.168.XX.XX:8080/portal
# Include the ssid and wlan parameters in the portal web server URL that the device redirects users to. The values are the SSID and VLAN of the AP.
[AC-portal-websvr-newpt] url-parameter ssid ssid
[AC-portal-websvr-newpt] url-parameter vlan vlan
[AC-portal-websvr-newpt]  url-parameter acip value  <Actual IP address of the AC> 
# Set the portal web server type to CMCC.
[AC-portal-websvr-newpt] server-type cmcc
# Configure iOS captive-bypass adaptation
[AC-portal-websvr-newpt] captive-bypass ios optimize enable
[AC-portal-websvr-newpt] quit
# Enable the RADIUS session control feature.
[AC] radius session-control enable
# Configure the RADIUS CoA feature
[AC] radius dynamic-author server
[AC-radius-da-server] client ip <Radius server IP> key simple <SharedSecret>

Replace <Radius server IP> with the IP address of the RADIUS server, and replace <SharedSecret> with the shared key of that server.

Replace <Radius server IP> with the IP address of the RADIUS server, and replace <Sharesecret> with the shared key of that server.

Step 5: Log on as a guest

After a device connects to the guest Wi-Fi, the portal authentication page opens automatically. Enter your mobile number, get the SMS verification code and enter it, and then click Log On. You can access internal enterprise applications only after the authentication succeeds.

Step 6: View guest logs

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Log Analysis > Log Audit.

  3. On the Access Logs > Guest Authentication Logs tab, view the network access authentication status of guests.

Use case 4: Configure network access for dumb terminals

Dumb terminals can access the enterprise office environment over a wired or a wireless network. Add the dumb terminals in the SASE console first, and then configure network access on your on-premises switch.

Step 1: Add dumb terminals

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Endpoint Management > Terminals.

  3. In the list on the left, select Dumb Terminal. Based on your business requirements, click Add Terminal or Import Devices. Complete one of the following options:

    • Add Terminal — In the Add Terminal pane, enter the MAC Address, MAC Address Mask, Device Vendor, Device Name, and Device Type of the terminal, and then click OK.

    • Import Devices — In the Import Devices dialog box, click Download Import Template. After you fill in the device information, click Upload Local File. After the upload finishes, click OK.

Step 2: Configure network access

The network access configuration of a dumb terminal depends on the device type: wireless terminals and wired terminals use different methods.

Note

Dumb terminals do not need certificate management or the SASE client. Skip Step 4 and Step 8 of Use case 1, or Step 3 and Step 7 of Use case 2.

Step 3: View dumb terminal authentication logs

  1. In the navigation pane on the left of the SASE console, choose Log Analysis > Log Audit.

  2. On the Access Logs > Dumb Terminal Authentication Logs tab, view the network access authentication status of the dumb terminals.