D-Link DWS-3024L User Manual - Page 85

Configuring AAA and RADIUS Settings, Administration > Basic Setup &gt, AAA/RADIUS

Page 85 highlights

5 Configuring Access Point Settings switch or externally on a RADIUS server. When an AP is discovered, the switch verifies the AP's MAC address according to the validation mode (local or RADIUS) as long as the AP is enabled for Managed Mode and has been authentication (if required). Once the AP is verified, it becomes managed by the switch. If an AP is discovered and its MAC address is not found in the Valid AP database or the AP fails to authenticate, the switch adds an entry to the AP failure list. If you use the local Valid AP database, you can add the failed AP to the Valid AP database directly from the AP Authentication Failures page. The Valid AP database stores additional information about the AP along with its MAC address such as the AP mode, local authentication password, and the AP profile that the access point uses. You can also manually set the channel and RF signal transmit power level for an individual AP, which overrides the channel and power settings in the AP profile. Configuring AAA and RADIUS Settings In the D-Link Unified Access System, you can use a RADIUS server for the following functions: • Management of client-to-AP authentication and accounting • Management of AP-to-Switch authentication and accounting • Database for AP settings The information in this section applies to the client-to-AP authentication and accounting management. For information about AP-to-switch management, see "Using the RADIUS Database for AP Validation" on page 78. For information about how to set AP database settings in the RADIUS server, see Appendix B, "Configuring the External RADIUS Server" on page 205. The RADIUS server that you configure from the Administration > Basic Setup > AAA/RADIUS tab is the RADIUS server for the default AP profile. For each network, you can configure a unique RADIUS server or use the default RADIUS server. When you use a RADIUS server for wireless client-to-AP communications, such as when clients use WPA Enterprise or WEP IEEE 802.1X security to connect to the AP, the AP is the RADIUS client and communicates with the RADIUS server. The Unified Switch does not tunnel packets between the AP and RADIUS server. This means that you must configure the AP as a client in the RAIDUS server. For information about how configure RADIUS clients, see Appendix B. Table 7 describes the fields you can configure for the default AP profile RADIUS server. Table 7. Global RADIUS Server Field Description IP Address This is the IP address of the RADIUS server the AP uses for authentication. Configuring AAA and RADIUS Settings 85

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268

Configuring AAA and RADIUS Settings
85
5
Configuring Access Point Settings
switch or externally on a RADIUS server. When an AP is discovered, the switch verifies the
AP’s MAC address according to the validation mode (local or RADIUS) as long as the AP is
enabled for Managed Mode and has been authentication (if required). Once the AP is verified,
it becomes managed by the switch.
If an AP is discovered and its MAC address is not found in the Valid AP database or the AP
fails to authenticate, the switch adds an entry to the AP failure list. If you use the local Valid
AP database, you can add the failed AP to the Valid AP database directly from the AP
Authentication Failures page.
The Valid AP database stores additional information about the AP along with its MAC address
such as the AP mode, local authentication password, and the AP profile that the access point
uses. You can also manually set the channel and RF signal transmit power level for an
individual AP, which overrides the channel and power settings in the AP profile.
Configuring AAA and RADIUS Settings
In the D-Link Unified Access System, you can use a RADIUS server for the following
functions:
Management of client-to-AP authentication and accounting
Management of AP-to-Switch authentication and accounting
Database for AP settings
The information in this section applies to the client-to-AP authentication and accounting
management. For information about AP-to-switch management, see
“Using the RADIUS
Database for AP Validation”
on page 78. For information about how to set AP database
settings in the RADIUS server, see Appendix B,
“Configuring the External RADIUS Server”
on page 205
.
The RADIUS server that you configure from the
Administration > Basic Setup >
AAA/RADIUS
tab is the RADIUS server for the default AP profile. For each network, you
can configure a unique RADIUS server or use the default RADIUS server.
When you use a RADIUS server for wireless client-to-AP communications, such as when
clients use WPA Enterprise or WEP IEEE 802.1X security to connect to the AP, the AP is the
RADIUS client and communicates with the RADIUS server. The Unified Switch does
not
tunnel packets between the AP and RADIUS server. This means that you must configure the
AP as a client in the RAIDUS server. For information about how configure RADIUS clients,
see
Appendix B
.
Table 7
describes the fields you can configure for the default AP profile RADIUS server.
Table 7.
Global RADIUS Server
Field
Description
IP Address
This is the IP address of the
RADIUS
server the AP uses for authentication.