Netgear WC7600 Reference Manual - Page 110

Guidelines for External MAC Authentication, Con Basic Local MAC Authentication Settings

Page 110 highlights

ProSAFE Wireless Controller WC7600 Guidelines for External MAC Authentication Note the following external RADIUS server guidelines: • For each MAC authentication client, you must configure a policy on the RADIUS server. • During MAC authentication, the wireless controller sends the following information to the RADIUS server: - MAC address in the format xx:xx:xx:xx:xx:xx - User name - Calling station ID • The wireless controller uses CHAP as the authentication protocol with the RADIUS server. • You can configure either MAC authentication with an external RADIUS server or network authentication with an external RADIUS server, but not both. That is, if you configure an external RADIUS server with WPA, WPA2, or WPA & WPA2, you cannot use external MAC authentication but are limited to internal MAC authentication. Configure Basic Local MAC Authentication Settings You would typically use the basic MAC authentication group in the profiles of a basic profile group of a small-scale network. However, you can assign the basic MAC authentication group to any profile, whether in the basic profile group or in an advanced profile group. The wireless controller supports a maximum of 256 MAC addresses per SSID. Note: You cannot add multicast or broadcast MAC addresses to a MAC access control list (ACL).  To set up basic MAC authentication ACL: 1. Open a web browser. In the browser's address field, type the http:// followed by the IP address that you assigned to the wireless controller. By default, the IP address is 192.168.0.250. If you have not yet assigned another IP address to the wireless controller, type http://192.168.0.250. The wireless controller's login screen displays. 2. Enter your user name and password. If you have not yet personalized your user name and password, enter admin for the user name and password for the password, both in lowercase letters. 3. Click the Login button. The wireless controller's web management interface opens and displays the Summary screen. Manage Security Profiles and Profile Groups 110

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307

Manage Security Profiles and Profile Groups
110
ProSAFE Wireless Controller WC7600
Guidelines for External MAC Authentication
Note the following external RADIUS server guidelines:
For each MAC authentication client, you must configure a policy on the RADIUS server.
During MAC authentication, the wireless controller sends the following information to the
RADIUS server:
-
MAC address in the format xx:xx:xx:xx:xx:xx
-
User name
-
Calling station ID
The wireless controller uses CHAP as the authentication protocol with the RADIUS
server.
You can configure either MAC authentication with an external RADIUS server or network
authentication with an external RADIUS server, but not both. That is, if you configure an
external RADIUS server with WPA, WPA2, or WPA & WPA2, you cannot use external
MAC authentication but are limited to internal MAC authentication.
Configure Basic Local MAC Authentication Settings
You would typically use the basic MAC authentication group in the profiles of a basic profile
group of a small-scale network. However, you can assign the basic MAC authentication
group to
any
profile, whether in the basic profile group or in an advanced profile group.
The wireless controller supports a maximum of 256 MAC addresses per SSID.
Note:
You cannot add multicast or broadcast MAC addresses to a MAC
access control list (ACL).
To set up basic MAC authentication ACL:
1.
Open a web browser. In the browser’s address field, type the
http://
followed by the IP
address that you assigned to the wireless controller.
By default, the IP address is 192.168.0.250. If you have not yet assigned another IP
address to the wireless controller, type
.
The wireless controller’s login screen displays.
2.
Enter your user name and password.
If you have not yet personalized your user name and password, enter
admin
for the user
name and
password
for the password, both in lowercase letters.
3.
Click the
Login
button.
The wireless controller’s web management interface opens and displays the Summary
screen.