3Com 8760 User Guide - Page 52

Supported: The access point supports 802.1X authentication only for clients

Page 52 highlights

CHAPTER 4: SYSTEM CONFIGURATION „ Local MAC: The MAC address of the associating station is compared against the local database stored on the access point. Use the Local MAC Authentication section of this web page to set up the local database, and configure all access points in the wireless network service area with the same MAC address database. „ RADIUS MAC: The MAC address of the associating station is sent to a configured RADIUS server for authentication. When using a RADIUS authentication server for MAC address authentication, the server must first be configured on the RADIUS page (see "RADIUS" on page 4-8). The database of MAC addresses and filtering policy must be defined in the RADIUS server. The MAC address of the associating station is used for both the username and password. For example, an associating station with a MAC address of 12-34-56-78-9A-BC would use a username and password of "12345678abc." The username and password sent to the server will use the format defined by "radius-server radius-mac-format" (See "RADIUS Client" on page 5-64), which has a default setting of "no-delimiter." NOTE: MAC addresses on the RADIUS server can be entered in four different formats (see "radius-server radius-mac-format" on page 5-68). You can enable 802.1X as optionally supported or as required to enhance the security of the wireless network. (Default: Disable) „ Disable: The access point does not support 802.1X authentication for any wireless client. After successful wireless association with the access point, each client is allowed to access the network. „ Supported: The access point supports 802.1X authentication only for clients initiating the 802.1X authentication process (i.e., the access point does not initiate 802.1X authentication). For clients initiating 802.1X, only those successfully authenticated are allowed to access the network. For those clients not initiating 802.1X, access to the network is allowed after successful wireless association with the access point. The 802.1X supported mode allows access for clients not using WPA or WPA2 security. „ Required: The access point enforces 802.1X authentication for all associated wireless clients. If 802.1X authentication is not initiated by a client, the access point will initiate authentication. Only those clients successfully authenticated with 802.1X are allowed to access the network. NOTE: If 802.1X is enabled on the access point, then RADIUS setup must be completed (See "RADIUS" on page 8.) 4-12

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261

4-12
C
HAPTER
4: S
YSTEM
C
ONFIGURATION
Local MAC: The MAC address of the associating station is compared against
the local database stored on the access point. Use the Local MAC
Authentication section of this web page to set up the local database, and
configure all access points in the wireless network service area with the same
MAC address database.
RADIUS MAC: The MAC address of the associating station is sent to a
configured RADIUS server for authentication. When using a RADIUS
authentication server for MAC address authentication, the server must first be
configured on the RADIUS page (see “RADIUS” on page 4-8). The database of
MAC addresses and filtering policy must be defined in the RADIUS server. The
MAC address of the associating station is used for both the username and
password. For example, an associating station with a MAC address of
12-34-56-78-9A-BC would use a username and password of “12345678abc.”
The username and password sent to the server will use the format defined by
“radius-server radius-mac-format” (See
“RADIUS Client” on page 5-64
), which
has a default setting of “no-delimiter.”
You can enable 802.1X as optionally supported or as required to enhance the
security of the wireless network. (Default: Disable)
Disable: The access point does not support 802.1X authentication for any
wireless client. After successful wireless association with the access point, each
client is allowed to access the network.
Supported: The access point supports 802.1X authentication only for clients
initiating the 802.1X authentication process (i.e., the access point does not
initiate 802.1X authentication). For clients initiating 802.1X, only those
successfully authenticated are allowed to access the network. For those clients
not initiating 802.1X, access to the network is allowed after successful wireless
association with the access point. The 802.1X supported mode allows access
for clients not using WPA or WPA2 security.
Required: The access point enforces 802.1X authentication for all associated
wireless clients. If 802.1X authentication is not initiated by a client, the access
point will initiate authentication. Only those clients successfully authenticated
with 802.1X are allowed to access the network.
NOTE:
MAC addresses on the RADIUS server can be entered in four different
formats (see “radius-server radius-mac-format” on page 5-68).
NOTE:
If 802.1X is enabled on the access point, then RADIUS setup must be
completed (See “RADIUS” on page 8.)