School Certification Platform Programme
I. OVERVIEW OF THE PROGRAMME
The programme is based onNATHHELL_BRAND Gateway DeviceandFee-based certification systemThe program supports smooth access to the WIFI equipment, which meets the need for a certification scale of 1,000 teaching staff.
II. Overall architecture design
2.1 Network Tapping Structures

III. NatShell Gateway deployment and configuration
3.1 Hardware deployment
Recommended equipment selection:
∙ NatShell NE-80 series gateway: support 1000 and sender, PPOE/Web Portal multiple authentication methods
l NatShell NSCP-S100 series of harmonized authentication platforms: built-in Radius server, billing engine, user management, group management
Location of deployment:
l Gateway links are deployed between core switch and export routers
l AdoptionTransparency Bridge ModeorRoute ModeDo not change the current network
3.2 Elements of a core configuration
l Enable different address pool names on Authentication Gateway, and configure multiple user groups on a unified authentication platform with each group matching different address pool names
l User authenticates PORTAL page by Authentication Gateway, and when authentication is successful, sends different address pool names to the gateway based on user group privileges
l After receiving address pool names, users are assigned different route policies based on preset address pool strategies and users can achieve different access rights according to route policy
3.3Two-storey access control mechanism
First tier: Port control for gateway layer IP+ (NTSHELL_BRAND gateway implemented)
n Different address pool name based on user role.
n Unauthorized role cannot access professional business systems IP
n Gateway level blocked illegal access and data packs were dropped
Level 2: Business systems self-authorization
n Business systems maintain the original account password system
n Second validation of the business system is required after the gateway
n Forming double security.
Four.、 API Interface
NATHHEL_BRANDAuthenticationSystem Open API InterfaceFor call by the Triangular System
Triangular docking
1. Active pull mode: API access logs are called regularly by the Triangular System
Webbook push mode: authentication event is sent to the specified URL in real time
Syslog mode: Gateway sent Syslog log to a log server in real time
Five.Programme strengths
1. Vendor neutrality: a uniform certification platform, compatible with multi-producer WIFI, fast and fast
2. Fine-tuning of delegation of authority: based on user group access control, to meet the level of business system access
3. Smooth expansion: from 800 people at present to 1,000 or more users without replacement of hardware
4. Standard API: Free of charge API interface to support triangular system docking
5. Developmental stability: NATSHEL_BRAND Gateway + Costing Programme has been deployed to thousands of colleges and universities throughout the country
I. OVERVIEW OF THE PROGRAMME
The programme is based onNATHHELL_BRAND Gateway DeviceandFee-based certification systemThe program supports smooth access to the WIFI equipment, which meets the need for a certification scale of 1,000 teaching staff.
II. Overall architecture design
2.1 Network Tapping Structures

III. NatShell Gateway deployment and configuration
3.1 Hardware deployment
Recommended equipment selection:
∙ NatShell NE-80 series gateway: support 1000 and sender, PPOE/Web Portal multiple authentication methods
l NatShell NSCP-S100 series of harmonized authentication platforms: built-in Radius server, billing engine, user management, group management
Location of deployment:
l Gateway links are deployed between core switch and export routers
l AdoptionTransparency Bridge ModeorRoute ModeDo not change the current network
3.2 Elements of a core configuration
l Enable different address pool names on Authentication Gateway, and configure multiple user groups on a unified authentication platform with each group matching different address pool names
l User authenticates PORTAL page by Authentication Gateway, and when authentication is successful, sends different address pool names to the gateway based on user group privileges
l After receiving address pool names, users are assigned different route policies based on preset address pool strategies and users can achieve different access rights according to route policy
3.3Two-storey access control mechanism
First tier: Port control for gateway layer IP+ (NTSHELL_BRAND gateway implemented)
n Different address pool name based on user role.
n Unauthorized role cannot access professional business systems IP
n Gateway level blocked illegal access and data packs were dropped
Level 2: Business systems self-authorization
n Business systems maintain the original account password system
n Second validation of the business system is required after the gateway
n Forming double security.
Four.、 API Interface
NATHHEL_BRANDAuthenticationSystem Open API InterfaceFor call by the Triangular System
Triangular docking
1. Active pull mode: API access logs are called regularly by the Triangular System
Webbook push mode: authentication event is sent to the specified URL in real time
Syslog mode: Gateway sent Syslog log to a log server in real time
Five.Programme strengths
1. Vendor neutrality: a uniform certification platform, compatible with multi-producer WIFI, fast and fast
2. Fine-tuning of delegation of authority: based on user group access control, to meet the level of business system access
3. Smooth expansion: from 800 people at present to 1,000 or more users without replacement of hardware
4. Standard API: Free of charge API interface to support triangular system docking
5. Developmental stability: NATSHEL_BRAND Gateway + Costing Programme has been deployed to thousands of colleges and universities throughout the country