Hi Ashish, Than you very much for the document which throws light on the Captive Portal configuration on the enforcer, however I would like to understand the following 1) Users to connect on the Juniper EX3200 switch for access. 2) User gets assigned to a red VLAN and is prompted for authentication, .Post succesful authentication user gets assigned to the respective VLAN if OAC is installed in the PC (Authorized Users) .Guest users to be redirected to a Captive portal and credentials to be verified against local user database configured on the IC. Once authenticated user gets assigned to Guest VLAN. 3) Guest users access would be limited to HTTP / HTTPS traffic on the firewall. 4) Juniper SRX 650 acting as Firewall can be used as Infranet Enforcer. Questions / Queries --------------------------- 1) Users to get IP address from Red VLAN ( not possible without DOT1X) 2) Do I need to have DOT1X configured on all the ports of the switch for the above mentioned scenario. Regards, Lalit
... View more