Netgear WC7500-Wireless User Manual - Page 123

Basic and Advanced Security Configuration Concepts, Configuration > Security > Advanced

Page 123 highlights

ProSAFE Wireless Controller Note: You can configure profiles to function with different authentication servers. For example, you could set up a guest profile with no authentication, an engineering profile that uses external RADIUS authentication, and a marketing profile that uses external LDAP authentication. You can also use additional external RADIUS servers in other profiles. • Captive portals and guest portals. If you want to use captive portals, guest portals, or both, first configure the portals: - Configure the basic portal on the basic Portal Settings page (see Configure a Basic Guest Portal or Captive Portal on page 224). - For more complex networks, configure additional portals on the advanced Captive Portal Settings page (see Configure an Advanced Guest Portal or Captive Portal on page 229). After you configure portals, you can then assign any portal to a security profile in a basic profile group or advanced profile group. • MAC authentication. If you want to use a MAC access control list (ACL) to control access of WiFi clients, first create one or more MAC ACLs: - Configure the basic MAC ACL on the basic MAC Authentication page (see Configure Basic Local MAC Authentication Settings on page 146). - For more complex networks, configure additional MAC ACLs on the advanced MAC Authentication page (see Configure a Local MAC Authentication Group on page 149). After you configure one or more MAC ACLs, you can then assign any MAC ACL to a security profile in a basic profile group or advanced profile group. • Cloning profiles. For faster setup, you can clone a profile and rename it. Cloning copies all settings except for the name and SSID. Basic and Advanced Security Configuration Concepts The basic security configuration model (Configuration > Security > Basic) does not apply strictly to the basic profile group, nor does the advanced security configuration model (Configuration > Security > Advanced) apply strictly to advanced profile groups. The reason is that you apply an authentication server and a MAC ACL to an individual profile and not to a profile group. • Basic security settings. You can apply the following security settings to any profile, whether in the basic profile group or in an advanced profile group: - Basic MAC authentication (the MAC ACL group that is called basic) - Basic authentication server (the RADIUS server that is called basic-Auth or the LDAP server that is called basic-LDAP) Manage Security Profiles and Profile Groups 123

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398

Manage Security Profiles and Profile Groups
123
ProSAFE Wireless Controller
Note:
You can configure profiles to function with different authentication
servers. For example, you could set up a guest profile with no
authentication, an engineering profile that uses external RADIUS
authentication, and a marketing profile that uses external LDAP
authentication. You can also use additional external RADIUS servers
in other profiles.
Captive portals and guest portals
. If you want to use captive portals, guest portals, or
both, first configure the portals:
-
Configure the basic portal on the basic Portal Settings page (see
Configure a Basic
Guest Portal or Captive Portal
on page 224).
-
For more complex networks, configure additional portals on the advanced Captive
Portal Settings page (see
Configure an Advanced Guest Portal or Captive Portal
on
page 229).
After you configure portals, you can then assign any portal to a security profile in a basic
profile group or advanced profile group.
MAC authentication
. If you want to use a MAC access control list (ACL) to control
access of WiFi clients, first create one or more MAC ACLs:
-
Configure the basic MAC ACL on the basic MAC Authentication page (see
Configure
Basic Local MAC Authentication Settings
on page 146).
-
For more complex networks, configure additional MAC ACLs on the advanced MAC
Authentication page (see
Configure a Local MAC Authentication Group
on page 149).
After you configure one or more MAC ACLs, you can then assign any MAC ACL to a
security profile in a basic profile group or advanced profile group.
Cloning profiles
. For faster setup, you can clone a profile and rename it. Cloning copies
all settings except for the name and SSID.
Basic and Advanced Security Configuration Concepts
The basic security configuration model (
Configuration > Security > Basic
) does not apply
strictly to the basic profile group, nor does the advanced security configuration model
(
Configuration > Security > Advanced
) apply strictly to advanced profile groups. The
reason is that you apply an authentication server and a MAC ACL to an individual profile and
not to a profile group.
Basic security settings
. You can apply the following security settings to
any
profile,
whether in the basic profile group or in an advanced profile group:
-
Basic MAC authentication (the MAC ACL group that is called basic)
-
Basic authentication server (the RADIUS server that is called basic-Auth or the LDAP
server that is called basic-LDAP)