Netgear WFS709TP WFS709TP Setup Manual - Page 127

Authentication Terminated on WFS709TP, Inner EAP = EAP-GTC or

Page 127 highlights

WFS709TP ProSafe Smart Wireless Switch Software Administration Manual For the WFS709TP to communicate with the authentication server, you must configure the IP address, authentication port, and accounting port of the server on the WFS709TP. The authentication server must be configured with the IP address of the RADIUS client, which here is the WFS709TP. Both the WFS709TP and the authentication server must be configured to use the same shared secret. As described in Chapter 1, "Overview of the WFS709TP", the client communicates with the WFS709TP through a Generic Routing Encapsulation (GRE) tunnel in order to form an association with an AP and to authenticate to the network. Therefore, the network authentication and encryption configured for an ESSID must be the same on both the client and the WFS709TP. "Configuring 802.1x Authentication" on page 7-4 describes 802.1x configuration on the WFS709TP. Authentication Terminated on WFS709TP Figure 7-2 is an overview of the parameters that you need to configure on 802.1x authentication components when 802.1x authentication is terminated on the WFS709TP (AAA FastConnect). User authentication is performed either via the WFS709TP's internal database or by a non-802.1x server. Client (Supplicant) WFS709TP (Autuenticator and authentication server) User authentication via internal database or non-802.1x server EAP type = EAP-PEAP Inner EAP = EAP-GTC or EAP- MSCHAPv2 ESSID Network authentication Data encryption Figure 7-2 EAP type = EAP-PEAP Inner EAP = EAP-GTC or EAP- MSCHAPv2 ESSID Network authentication Data encryption Configuring 802.1x Authentication 7-3 v1.0, June 2007

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222

WFS709TP ProSafe Smart Wireless Switch Software Administration Manual
Configuring 802.1x Authentication
7-3
v1.0, June 2007
For the WFS709TP to communicate with the authentication server, you must configure the IP
address, authentication port, and accounting port of the server on the WFS709TP. The
authentication server must be configured with the IP address of the RADIUS client, which here is
the WFS709TP. Both the WFS709TP and the authentication server must be configured to use the
same shared secret.
As described in
Chapter 1, “Overview of the WFS709TP”
, the client communicates with the
WFS709TP through a Generic Routing Encapsulation (GRE) tunnel in order to form an
association with an AP and to authenticate to the network. Therefore, the network authentication
and encryption configured for an ESSID must be the same on both the client and the WFS709TP.
“Configuring 802.1x Authentication” on page 7-4
describes 802.1x configuration on the
WFS709TP.
Authentication Terminated on WFS709TP
Figure 7-2
is an overview of the parameters that you need to configure on 802.1x authentication
components when 802.1x authentication is terminated on the WFS709TP (AAA FastConnect).
User authentication is performed either via the WFS709TP’s internal database or by a non-802.1x
server.
Figure 7-2
Client
(Supplicant)
User
authentication via
internal database
or non-802.1x
server
ESSID
Network authentication
Data encryption
ESSID
Network authentication
Data encryption
EAP type = EAP-PEAP
Inner EAP = EAP-GTC or
EAP- MSCHAPv2
EAP type = EAP-PEAP
Inner EAP = EAP-GTC or
EAP- MSCHAPv2
WFS709TP
(Autuenticator and
authentication server)
ESSID
Network authentication
Data encryption