Dell PowerConnect W-IAP3WN Dell Instant 5.0.3.0-1.1.0.0 User Guide - Page 70

External RADIUS Server, Configuring an External RADIUS Server

Page 70 highlights

controller (the client certificate must be signed by a known CA) before the user name is checked on the authentication server.  EAP-TTLS (MSCHAPv2) - The Extensible Authentication Protocol-Tunneled Transport Layer Security (EAP-TTLS) method uses server-side certificates to set up authentication between clients and servers. However, the actual authentication is performed using passwords.  EAP-PEAP (MSCHAPv2) - Protected Extensible Authentication Protocol (PEAP) is an 802.1X authentication method that uses server-side public key certificates to authenticate clients with server. The PEAP authentication creates an encrypted SSL / TLS tunnel between the client and the authentication server. Exchange of information is encrypted and stored in the tunnel ensuring the user credentials are kept secure.  LEAP - Lightweight Extensible Authentication Protocol (LEAP) uses dynamic WEP keys for authentication between the client and authentication server. NOTE: Dell Instant does not ship with any 802.1x server certificate. EAP-TTLS and EAP-PEAP support is not available until the administrator uploads a valid 802.1x server certificate to the Dell Instant network. By default, the 802.1x authentication is limited to LEAP only. NOTE: Dell does not recommend the use of LEAP authentication method because it does not provide any resistance to network attacks. External RADIUS Server In the external RADIUS server, IP address of the virtual controller is configured as the NAS IP address. Instant RADIUS is implemented on the virtual controller. This feature eliminates the need to configure multiple NAS clients for every IAP on the RADIUS server for client authentication. Instant RADIUS dynamically forwards authentication requests from a NAS to a remote RADIUS server. The RADIUS server responds to the authentication request with an Access-Accept or Access-Reject message. Users are allowed or denied access to the network depending on the response from the RADIUS server. Configuring an External RADIUS Server To configure the external RADIUS server for the wireless network, perform the following steps: 1. In the Network tab, click the network for which you want to configure the external RADIUS Server. The edit link for the network appears. 2. Click the edit link. The Edit box for the network appears. 3. Click Next and perform the following tasks in the Security tab: 1. For a network with Personal or Open security level, select External Radius Server from the MAC Authentication drop-down list. 2. Click the Primary link and perform the following steps: a. Enter the IP address of the external RADIUS server in the IP address text box. b. Enter the authorization port number of the external RADIUS server in the Auth Port text box. The port number is set to 1812 by default. c. Enter a shared key for communicating with the external RADIUS server in the Shared key text box. d. Enter the virtual controller IP address in the NAS IP address text box. The NAS IP address is the virtual controller IP address that is sent in the data packets. 3. Click the Backup link and set appropriate values for the backup RADIUS server. 70 | Authentication Dell PowerConnect W-Instant Access Point 5.0.3.0-1.1.0.0 | User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

70
|
Authentication
Dell PowerConnect W-Instant Access Point 5.0.3.0-1.1.0.0
| User Guide
controller (the client certificate must be signed by a known CA) before the user name is checked on the
authentication server.
EAP-TTLS (MSCHAPv2) - The Extensible Authentication Protocol-Tunneled Transport Layer Security
(EAP-TTLS) method uses server-side certificates to set up authentication between clients and servers.
However, the actual authentication is performed using passwords.
EAP-PEAP (MSCHAPv2) - Protected Extensible Authentication Protocol (PEAP) is an 802.1X
authentication method that uses server-side public key certificates to authenticate clients with server. The
PEAP authentication creates an encrypted SSL / TLS tunnel between the client and the authentication server.
Exchange of information is encrypted and stored in the tunnel ensuring the user credentials are kept secure.
LEAP - Lightweight Extensible Authentication Protocol (LEAP) uses dynamic WEP keys for authentication
between the client and authentication server.
External RADIUS Server
In the external RADIUS server, IP address of the virtual controller is configured as the NAS IP address. Instant
RADIUS is implemented on the virtual controller. This feature eliminates the need to configure multiple NAS
clients for every IAP on the RADIUS server for client authentication.
Instant RADIUS dynamically forwards authentication requests from a NAS to a remote RADIUS server. The
RADIUS server responds to the authentication request with an Access-Accept or Access-Reject message. Users
are allowed or denied access to the network depending on the response from the RADIUS server.
Configuring an External RADIUS Server
To configure the external RADIUS server for the wireless network, perform the following steps:
1.
In the
Network
tab, click the network for which you want to configure the external RADIUS Server. The
edit
link for the network appears.
2.
Click the
edit
link. The
Edit
box for the network appears.
3.
Click
Next
and perform the following tasks in the
Security
tab:
1.
For a network with
Personal
or
Open
security level, select
External Radius Server
from the
MAC
Authentication
drop-down list.
2.
Click the
Primary
link and perform the following steps:
a.
Enter the IP address of the external RADIUS server in the
IP address
text box.
b.
Enter the authorization port number of the external RADIUS server in the
Auth Port
text box. The port
number is set to 1812 by default.
c.
Enter a shared key for communicating with the external RADIUS server in the
Shared key
text box.
d.
Enter the virtual controller IP address in the
NAS IP address
text box. The NAS IP address is the virtual
controller IP address that is sent in the data packets.
3.
Click the
Backup
link and set appropriate values for the backup RADIUS server.
NOTE:
Dell Instant does not ship with any 802.1x server certificate. EAP-TTLS and EAP-PEAP support is not available until the
administrator uploads a valid 802.1x server certificate to the Dell Instant network. By default, the 802.1x authentication is limited to
LEAP only.
NOTE:
Dell does not recommend the use of LEAP authentication method because it does not provide any resistance to network
attacks.