D-Link DWS-3024 Product Manual - Page 211

Configuring RADIUS Settings for Wireless Clients, Configuring RADIUS for Client MAC Authentication

Page 211 highlights

Configuring the External RADIUS Server NOTE: In the FreeRADIUS database, the MAC address is case sensitive, and the octets must be separated by hyphens. 00-11-95-a3-32-80 Auth-Type := Local, User-Password=="NOPASSWORD" D-Link-Wireless-AP-Mode = WS-Managed, D-Link-Wireless-AP-Location = "Lobby AP", D-Link-Wireless-AP-Profile-ID = 1, D-Link-Wireless-AP-Switch-IP = 192.168.30.4, D-Link-Wireless-AP-Radio-1-Chan = Auto, D-Link-Wireless-AP-Radio-2-Chan = Auto, D-Link-Wireless-AP-Radio-1-Power = Auto, D-Link-Wireless-AP-Radio-2-Power = Auto Configuring RADIUS Settings for Wireless Clients You can configure D-Link Access Points to use 802.1X authentication on the RADIUS server to allow or deny specific users on client stations access to the wireless network. If you enable 802.1X authentication, the client entry on a RADIUS server can support user-based VLANs and subnet assignments for IP tunneling. Table 81 shows the attributes to set for wireless clients within the RADIUS server. Table 81. RADIUS Attributes for Wireless Clients RADIUS Server Attribute User-Name (1) User-Password (2) Tunnel-Medium-Type (65) Description Range 1-32 characters 1-128 characters 802 Usage Required Required Optional Configuring RADIUS for Client MAC Authentication You can configure the AP to use RADIUS-based MAC authentication to allow or deny specific client stations access to the wireless network. Although this method is less secure than 802.1X, you can use it for client stations that do not support 802.1X. The addresses you enter are either allowed or denied based on the global default action within the AP profile. Table 82 indicates the attributes that you configure in the RADIUS server entry. Table 82. RADIUS Attributes for Wireless Client MAC Authentication RADIUS Server Attribute User-Name (1) User-Password (2) Description Ethernet Address of the client station. A fixed password used to lookup a client MAC entry. Range Valid Ethernet MAC Address. NOPASSWORD Usage Required Required Configuring RADIUS Settings for Wireless Clients 211

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270

Configuring RADIUS Settings for Wireless Clients
211
Configuring the External RADIUS Server
NOTE:
In the FreeRADIUS database, the MAC address is case sensitive, and the
octets must be separated by hyphens.
00-11-95-a3-32-80
Auth-Type := Local, User-Password=="NOPASSWORD"
D-Link-Wireless-AP-Mode = WS-Managed,
D-Link-Wireless-AP-Location = "Lobby AP",
D-Link-Wireless-AP-Profile-ID = 1,
D-Link-Wireless-AP-Switch-IP = 192.168.30.4,
D-Link-Wireless-AP-Radio-1-Chan = Auto,
D-Link-Wireless-AP-Radio-2-Chan = Auto,
D-Link-Wireless-AP-Radio-1-Power = Auto,
D-Link-Wireless-AP-Radio-2-Power = Auto
Configuring RADIUS Settings for Wireless Clients
You can configure D-Link Access Points to use 802.1X authentication on the RADIUS server
to allow or deny specific users on client stations access to the wireless network. If you enable
802.1X authentication, the client entry on a RADIUS server can support user-based VLANs
and subnet assignments for IP tunneling.
Table 81
shows the attributes to set for wireless
clients within the RADIUS server.
Configuring RADIUS for Client MAC Authentication
You can configure the AP to use RADIUS-based MAC authentication to allow or deny
specific client stations access to the wireless network. Although this method is less secure than
802.1X, you can use it for client stations that do not support 802.1X.
The addresses you enter are either allowed or denied based on the global default action within
the AP profile.
Table 82
indicates the attributes that you configure in the RADIUS server entry.
Table 81.
RADIUS Attributes for Wireless Clients
RADIUS Server
Attribute
Description
Range
Usage
User-Name (1)
1-32 characters
Required
User-Password (2)
1-128 characters
Required
Tunnel-Medium-Type
(65)
802
Optional
Table 82.
RADIUS Attributes for Wireless Client MAC Authentication
RADIUS Server
Attribute
Description
Range
Usage
User-Name (1)
Ethernet Address of the client
station.
Valid Ethernet
MAC Address.
Required
User-Password (2)
A fixed password used to
lookup a client MAC entry.
NOPASSWORD
Required