cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1215
Views
5
Helpful
2
Replies

Open Roaming - Capturing Identity

cbishop
Level 1
Level 1

I am researching using open roaming and I found cisco documentation on how to enable open roaming on meraki devices.  It all seems straight forward but where I am lost is how do I capture the info of the authorized user? If a user authenticates with a google ID on my network how do I find out what the google ID is?  If I cannot find out what that user ID is how do I bring up a captive portal?

1 Accepted Solution

Accepted Solutions

Rich R
VIP
VIP

1. The whole idea of Openroaming is to log the user in (authentication) so there would be no captive portal.

2. You don't need a user ID for a captive portal.  Captive portals are driven by IP and MAC address for identity.  In fact 99% of the time you don't know the user ID when presenting a captive portal. 

For more info on Openroaming in general see https://wballiance.com/openroaming/

 

View solution in original post

2 Replies 2

Rich R
VIP
VIP

1. The whole idea of Openroaming is to log the user in (authentication) so there would be no captive portal.

2. You don't need a user ID for a captive portal.  Captive portals are driven by IP and MAC address for identity.  In fact 99% of the time you don't know the user ID when presenting a captive portal. 

For more info on Openroaming in general see https://wballiance.com/openroaming/

 

whoops. didn't mean to accept as solution.

 

So we want to prompt the connect user to allow us to have their email address for future contact.  We currently do that through Open Wifi.  We also give users the option of installing a Passpoint profile to connect securely next time.  We have the ability to wall garden the user on secure wifi to prompt them with a captive portal to capture additional details.  We achieve this by passing back Radius Attributes that trigger the AP to move the user into a wall garden.  With Open Roaming we don't handle the authentication, in fact I don't know if there is any option for hooking into this process so we can tell the AP not to allow the authenticated user online but instead move them to a walled garden.

Review Cisco Networking products for a $25 gift card