D-Link DWS-3160-24TC DWS-3160 Series Web UI Reference Guide - Page 498

Client 802.1X RADIUS Attributes, Attribute, Description, Range, Usage

Page 498 highlights

DWS-3160 Series Gigabit Ethernet Unified Switch Web UI Reference Guide Radio-1-Power (107) Vendor-Specifc (26), D-Link (171), Radio-2-Power (108) Vendor-Specifc (26), D-Link (171), Expected-Channel (112) Vendor-Specifc (26), D-Link (171), Expected-AP-Security (110) Vendor-Specifc (26), D-Link (171), Expected-SSID (109) Vendor-Specifc (26), D-Link (171), Allowed-On-WiredNetwork (113) power assignment. Indicates a fixed power setting for the radio. 0, 1-100 percent 0 indicates automatic power assignment. The expected channel for a stand-alone AP. The expected security mode for a stand-alone AP. The expected SSID for a standalone AP. Flag indicating whether this stand-alone AP is allowed on the wired network. 0, 1-165. 0 indicates that this AP can operate on any channel. 0 - Any Mode 1 - Open 2 - WEP 3 - WPA or WPA2 Character string, 0 to 32 bytes. If string is empty, then device may use any SSID 0 - AP is allowed on the wired network. 1 - AP is not allowed on the wired network. valid will override auto power configuration. Optional, if 0 defined and valid wil override auto power configuration. Optional 0 Optional 0 Optional "" Optional 0 Client 802.1X RADIUS Attributes An Access Point can use 802.1X authentication via the RADIUS to allow or prohibit access to the wireless network for specific users on client stations. Wireless Client QoS parameters can be obtained if (and only if) 802.1X authentication is used, which is based on user name and password identification credentials. Each of the QoS parameters defined here are optional, meaning they may not be present in the client's RADIUS server entry even though a valid 802.1X authentication occurs for the client. Assuming a wireless client successfully authenticates using 802.1X, each QoS RADIUS attribute that exists for the client will be sent to the AP for processing. In all other cases, either 802.1X authentication is not used, is used but is not successful, or is successful but a particular QoS RADIUS attribute is either not configured or not valid for the client entry. The corresponding AP network client QoS default parameter is used instead for the client. Each such RADIUS attribute is evaluated this way, case-by-case. Attribute Vendor-Specific (26), D-Link (171), Client-ACL-Dn (120) Vendor-Specific (26), D-Link (171), Description Access list identifier to be applied to 802.1X authenticated wireless client traffic in the outbound (down) direction. If this attribute is not present then the Client QoS Default ACL Down Type and Name parameters defined in the Network configuration are used instead. If this attribute is present but refers to an undefined access list name in the system, all packets for this client will be dropped until the ACL is defined. Access list identifier to be applied to 802.1X authenticated wireless client traffic in the Range Type: string 5-36 characters (not nullterminated) The string is of the form "type:name" where: • type = ACL type identifier: IPV4, IPV6, MAC • : = required separator character • name = 1-31 alphanumeric characters, specifying the ACL number (IPV4) or name (IPV6, MAC) Type: string 5-36 characters (not null- Usage Optional Optional 493

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505

DWS-3160 Series Gigabit Ethernet Unified Switch Web UI Reference Guide
493
Radio-1-Power (107)
power assignment.
valid will
override auto
power
configuration.
Vendor-Specifc (26),
D-Link (171),
Radio-2-Power (108)
Indicates a fixed power
setting for the radio.
0, 1-100 percent 0
indicates automatic
power assignment.
Optional, if
defined and
valid wil
override auto
power
configuration.
0
Vendor-Specifc (26),
D-Link (171),
Expected-Channel (112)
The expected channel for a
stand-alone AP.
0, 1-165. 0 indicates that
this AP can operate on
any channel.
Optional
0
Vendor-Specifc (26),
D-Link (171),
Expected-AP-Security
(110)
The expected security mode
for a stand-alone AP.
0 - Any Mode
1 - Open
2 - WEP
3 - WPA or WPA2
Optional
0
Vendor-Specifc (26),
D-Link (171),
Expected-SSID (109)
The expected SSID for a
standalone AP.
Character string, 0 to 32
bytes. If string is empty,
then device may use any
SSID
Optional
“”
Vendor-Specifc (26),
D-Link (171),
Allowed-On-Wired-
Network (113)
Flag indicating whether this
stand-alone AP is allowed
on the wired network.
0 - AP is allowed on the
wired network.
1 - AP is not allowed on
the wired network.
Optional
0
An Access Point can use 802.1X authentication via the RADIUS to allow or prohibit access to the wireless network
for specific users on client stations. Wireless Client QoS parameters can be obtained if (and only if) 802.1X
authentication is used, which is based on user name and password identification credentials. Each of the QoS
parameters defined here are optional, meaning they may not be present in the client's RADIUS server entry even
though a valid 802.1X authentication occurs for the client. Assuming a wireless client successfully authenticates
using 802.1X, each QoS RADIUS attribute that exists for the client will be sent to the AP for processing.
Client 802.1X RADIUS Attributes
In all other cases, either 802.1X authentication is not used, is used but is not successful, or is successful but a
particular QoS RADIUS attribute is either not configured or not valid for the client entry. The corresponding AP
network client QoS default parameter is used instead for the client. Each such RADIUS attribute is evaluated this
way, case-by-case.
Attribute
Description
Range
Usage
Vendor-Specific (26),
D-Link (171),
Client-ACL-Dn (120)
Access list identifier to be applied to 802.1X
authenticated wireless client traffic in the
outbound (down) direction. If this attribute is
not present then the Client QoS Default ACL
Down Type and Name parameters defined in
the Network configuration are used instead. If
this attribute is present but refers to an
undefined access list name in the system, all
packets for this client will be dropped until the
ACL is defined.
Type: string 5-36
characters (not null-
terminated) The
string is of the form
"type:name" where:
• type = ACL type
identifier: IPV4,
IPV6, MAC
• : = required
separator character
• name = 1-31
alphanumeric
characters,
specifying the ACL
number (IPV4) or
name (IPV6, MAC)
Optional
Vendor-Specific (26),
D-Link (171),
Access list identifier to be applied to 802.1X
authenticated wireless client traffic in the
Type: string 5-36
characters (not null-
Optional