Dell PowerConnect W-IAP3WN Dell Instant 6.2.0.0-3.2.0.0 User Guide - Page 116

X Authentication when Dell PowerConnect W-ClearPass Policy Manager is available

Page 116 highlights

l 802.1X Authentication when Dell PowerConnect W-ClearPass Policy Manager is available (refer to Figure 83) l 802.1X Authentication using cached crendentials when Dell PowerConnect W-ClearPass Policy Manager is not available (refer to Figure 82 ) l 802.1X Authentication when Dell PowerConnect W-ClearPass Policy Manager is available again (refer to Figure 83) Figure 81 depicts a process wherein the W-IAP offloads EAP method authentication to ClearPass over a remote link connection. After authenticating the user against Active Directory and deriving enforcement attributes for the user, the ClearPass Policy Manager returns additional information in the RADIUS Access Accept message which the IAP caches to support authentication survivability. As seen in the figure below, the information sent by the ClearPass Policy Manager varies depending on the authentication method used. Figure 81 - 802.1X Authentication when Dell PowerConnect W-ClearPass Policy Manager is reachable Figure 82 depicts a situation when the remote link is not available and the W-IAP is no longer able to reach the Dell PowerConnect W-ClearPass Policy Manager. Here, the W-IAP will terminate and complete the EAP authentication using the cached credentials information. NOTE: If both the W-IAP to which the client was associated and the CPPM are not available, then the client will be not be able to reauthenticate until the CPPM server is available again. 116 | Authentication Dell PowerConnect W-Series Instant Access Point 6.2.0.0-3.2.0.0 | User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296

116
|
Authentication
Dell PowerConnect W-Series Instant Access Point
6.2.0.0-3.2.0.0
|
User Guide
l
802.1X Authentication when Dell PowerConnect W-ClearPass Policy Manager is available
(refer to
Figure
83
)
l
802.1X Authentication using cached crendentials when Dell PowerConnect W-ClearPass
Policy Manager is not available (refer to
Figure
82
)
l
802.1X Authentication when Dell PowerConnect W-ClearPass Policy Manager is available
again (refer to
Figure
83
)
Figure
81
depicts a process wherein the W-IAP offloads EAP method authentication to ClearPass
over a remote link connection. After authenticating the user against Active Directory and deriving
enforcement attributes for the user, the ClearPass Policy Manager returns additional information
in the RADIUS Access Accept message which the IAP caches to support authentication
survivability.
As seen in the figure below, the information sent by the ClearPass Policy Manager varies
depending on the authentication method used.
Figure 81
- 802.1X Authentication when Dell PowerConnect W-ClearPass Policy Manager is
reachable
Figure
82
depicts a situation when the remote link is not available and the W-IAP is no longer able
to reach the Dell PowerConnect W-ClearPass Policy Manager. Here, the W-IAP will terminate and
complete the EAP authentication using the cached credentials information.
NOTE: If both the W-IAP to which the client was associated and the CPPM are not available,
then the client will be not be able to reauthenticate until the CPPM server is available again.