> For the complete documentation index, see [llms.txt](https://legacydocs.nexudus.com/platform/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://legacydocs.nexudus.com/platform/settings/integrations-and-apps-1/wifi-based-check-in/setting-up-wifi-based-check-in-using-radius-servers/network-based-check-in-cisco-wlc.md).

# WiFi-based check-in: Cisco WLC

### Setup

Before you configure the controller make sure you have set up your [RADIUS server and have purchased a license](/platform/settings/integrations-and-apps-1/wifi-based-check-in/setting-up-wifi-based-check-in-using-radius-servers.md).

### Configuring the Cisco WLC controller

#### To configure Access Control rules for the WLC controller

1. Log in the Cisco WLC web browser interface and go to Advanced Settings by clicking the configuration icon on top of the screen.
2. Go to **Security>Access Control Lists** and add two new ACL rules to allow connections to the captive portal:
   * **Source IP**: any; **Destination IP**: 107.178.250.42, **Mask**: 255.255.255.255; **Protocol**: TCP; **Dest Port**: 443, **Action**: Permit.
   * **Source IP**: 107.178.250.42, **Mask**: 255.255.255.255; **Destination IP**: any; **Protocol**: TCP; **Source Port**: 443; **Action**: Permit.
3. You may also want to add the following IPs to your rules:
   * XYZ.spaces.nexudus.com, where **XYZ** is the default domain name you can find in **Settings>Webiste>General** on your Nexudus account.
   * 107.178.250.42/32
   * 216.239.32.0/19
   * 64.233.160.0/19
   * 72.14.192.0/18
   * 209.85.128.0/17
   * 66.102.0.0/20
   * 74.125.0.0/16
   * 64.18.0.0/20
   * 207.126.144.0/20
   * 173.194.0.0/16

![Configuring Access Control rules](https://3743897482-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lbh_u87wC7EAH8sHaxc%2F-LhLgJlCJQ6vW2zfs4uP%2F-LhLgd7avWLA9p8vQtlk%2Fassets_-LZFtxNPXnGfu3w0vzug_-LaPIz_72mGQIAZeA9Ss_-LaPk7GcX67xvasLdWQw_wlc_access_control_config.png?alt=media\&token=3140d7c1-4381-4578-b994-f1e90db68b87)

#### Configuring RADIUS Authentication

Go to **Security** > **Web Auth** > **Web Login Page** and change **Web Authentication Type** to **External (redirect to external server)***.* Add the **External Webauth URL**. The URL here should be **<http://XYZ.spaces.nexudus.com/en/splash>**. **XYZ** is the default domain name you can find in **Settings** > **Webiste** > **General** on your Nexudus account.

Go to **Security** > **AAA** > **RADIUS>Authentication**, add a new RADIUS Authentication server and enter the following:

* IP address in the **Server Address(Ipv4/Ipv6)** text box.
* In the **Shared** **Secret** text box, the Shared Secret from the details of the RADIUS server that you received when you created the server.
* Your RADIUS ports in the **Port Number** text box.

![Configuring RADIUS Authentication Servers](https://3743897482-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lbh_u87wC7EAH8sHaxc%2F-LhLgJlCJQ6vW2zfs4uP%2F-LhLgszNlral50f9uoBD%2Fassets_-LZFtxNPXnGfu3w0vzug_-LaPIz_72mGQIAZeA9Ss_-LaPkhgjMkMmE8WCRDIP_wlc_radius_auth_config.png?alt=media\&token=8eb0cd4b-07f5-4ef5-820d-6ca9b20939b4)

### Configuring RADIUS Accounting

Go to **Security** > **AAA** > **RADIUS** > **Accounting**, add a new RADIUS Accounting server and enter the following:&#x20;

* IP address in the **Server Address(Ipv4/Ipv6)** text box.
* In the **Shared** **Secret** text box, the Shared Secret from the details of the RADIUS server that you received when you created the server.
* Your RADIUS ports in the **Port Number** text box.

![Configuring RADIUS Accounting Servers](https://3743897482-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lbh_u87wC7EAH8sHaxc%2F-LhLgJlCJQ6vW2zfs4uP%2F-LhLgxvxcXmoRNMeaUPa%2Fassets_-LZFtxNPXnGfu3w0vzug_-LaPIz_72mGQIAZeA9Ss_-LaPlF-gnjVqqmoHD-Ht_wlc_radius_accounting_config.png?alt=media\&token=a115b958-a7e5-44a4-9a22-049368441d67)

### Configuring WLAN

Go to **WLANs**, select existing or create a new **WLAN** and then open the **WLAN** settings.

![](https://3743897482-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lbh_u87wC7EAH8sHaxc%2F-LhLgJlCJQ6vW2zfs4uP%2F-LhLh0mS4xnSNUpIGoTn%2Fassets_-LZFtxNPXnGfu3w0vzug_-LaPIz_72mGQIAZeA9Ss_-LaPmCsdNotsSdTCquXC_wlc_wlan_config.png?alt=media\&token=98f31ee6-2d21-4740-aa1a-312fba0ac63d)

Click **Security>Layer 2** and set **Layer 2 Security** to **None**.

![](https://3743897482-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lbh_u87wC7EAH8sHaxc%2F-LhLgJlCJQ6vW2zfs4uP%2F-LhLh40Qv1w_DR-hc5KB%2Fassets_-LZFtxNPXnGfu3w0vzug_-LaPIz_72mGQIAZeA9Ss_-LaPnUqOcIt0j6xlCUYH_wlc_wlan_layer2.png?alt=media\&token=33884d19-7503-4fec-a61c-11c55c73c2c4)

Click **Layer 3**, select **Web Policy** from the **Layer 3 Security** drop-down list and then select **Authentication**. Select your new ACL from the **Preauthentication ACL** drop-down list.

![](https://3743897482-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lbh_u87wC7EAH8sHaxc%2F-LhLgJlCJQ6vW2zfs4uP%2F-LhLh8NhKDzejYTRDJiu%2Fassets_-LZFtxNPXnGfu3w0vzug_-LaPIz_72mGQIAZeA9Ss_-LaPnwRwIXwGNz84WTcA_wlc_wlan_layer3.png?alt=media\&token=cea55cee-28a3-4221-86c8-03d043e54bb5)

Click **AAA Servers** and select RADIUS authentication and accounting servers. You can also set **Interim Interval** to 180 seconds or higher. To save and apply new settings, click **Save Configuration**.

![](https://3743897482-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lbh_u87wC7EAH8sHaxc%2F-LhLgJlCJQ6vW2zfs4uP%2F-LhLhaY9WNPgvt1koXvR%2Fassets_-LZFtxNPXnGfu3w0vzug_-LaPIz_72mGQIAZeA9Ss_-LaPpgnpcyHK2zGF8XYw_wlc_aaa_config_and_save.png?alt=media\&token=a323dffb-3b68-4f44-bc3e-8f4629410293)

| Number | Description                           |
| ------ | ------------------------------------- |
| 1      | Authentication and Accounting Servers |
| 2      | Interim Interval                      |
| 3      | Save Configuration                    |
