Cisco WAP200 Administration Guide - Page 40

Using multiple, authentication, mechanisms - manual

Page 40 highlights

Chapter 2 How it works Chapter 2 The Authentication settings page enables you to specify the following global parameters: • Supplicant timeout-Enter the maximum number of seconds for the WAP-200 to wait for a client station to respond to an Extensible Authentication Protocol (EAPOL) packet before resending it. Default is 3 seconds. If wireless client stations are configured to manually enter an 802.1x username or password or both, you must increase the Supplicant timeout to 15 to 20 seconds. • Group key update-Enable this checkbox in order to force updating of 802.1x group keys at the selected Key change interval. • Reauthentication-Enable this checkbox in order to force 802.1x clients to reauthenticate as determined by the following parameters: • Period-Select the interval at which client stations must reauthenticate. Select 15 or 30 minutes or 1, 2, 4, 8, or 12 hours. Default is 1 hour. • Terminate-Enable this checkbox to specify that client traffic is blocked during reauthentication and is reactivated only when authentication succeeds. Disable this checkbox to specify that client stations remain connected during reauthentication and that client traffic is blocked only if reauthentication fails. Using multiple authentication mechanisms 802.1x and MAC-based authentication are configurable for each virtual service community. Both options can be enabled at the same time for added flexibility. When this occurs, the result for 802.1x authentication takes precedence over the MAC authentication result. It is therefore possible for a client station to be authenticated via MAC and then refused via 802.1x, or refused by MAC and accepted by 802.1x. An additional option is available that can be used to force all client stations to authenticate via 802.1x. When active, even if a client station is authenticated via MAC, the client station will be refused if it cannot authenticate via 802.1x. Restriction Both MAC and 802.1x authentication options can only be active at the same time on the same VSC when the setting for wireless protection is: • 802.1x with no encryption (WEP option disabled) OR • 802.1x with WEP encryption enabled and static keys enabled Note: If you intend to only use dynamic keys, only 802.1x authentication is supported. The following table illustrates the results for all authentication scenarios. Active Authentication Method MAC 802.1x Not Mandatory 802.1x Mandatory Authentication result MAC 802.1x Failure - Success - - Success - Failure - - - Failure - Success - - Network Access? No Yes Yes No Yes No Yes No 40

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82

Chapter 2
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - How it works - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Chapter 2
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 40 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
The
Authentication settings
page enables you to specify the following global
parameters:
Supplicant timeout
—Enter the maximum number of seconds for the WAP-200 to
wait for a client station to respond to an Extensible Authentication Protocol (EAPOL)
packet before resending it. Default is 3 seconds.
If wireless client stations are configured to manually enter an 802.1x username or
password or both, you must increase the
Supplicant timeout
to 15 to 20 seconds.
Group key update
—Enable this checkbox in order to force updating of 802.1x group
keys at the selected
Key change interval.
Reauthentication
—Enable this checkbox in order to force 802.1x clients to
reauthenticate as determined by the following parameters:
Period
—Select the interval at which client stations must reauthenticate. Select 15 or
30 minutes or 1, 2, 4, 8, or 12 hours. Default is 1 hour.
Terminate
—Enable this checkbox to specify that client traffic is blocked during
reauthentication and is reactivated only when authentication succeeds. Disable this
checkbox to specify that client stations remain connected during reauthentication and
that client traffic is blocked only if reauthentication fails.
Using multiple
authentication
mechanisms
802.1x and MAC-based authentication are configurable for each virtual service
community. Both options can be enabled at the same time for added flexibility. When this
occurs, the result for 802.1x authentication takes precedence over the MAC
authentication result. It is therefore possible for a client station to be authenticated via
MAC and then refused via 802.1x, or refused by MAC and accepted by 802.1x.
An additional option is available that can be used to force all client stations to
authenticate via 802.1x. When active, even if a client station is authenticated via MAC,
the client station will be refused if it cannot authenticate via 802.1x.
Restriction
Both MAC and 802.1x authentication options can only be active at the same time on the
same VSC when the setting for wireless protection is:
802.1x with no encryption (WEP option disabled)
OR
802.1x with WEP encryption enabled and static keys enabled
Note:
If you intend to only use dynamic keys, only 802.1x authentication is supported.
The following table illustrates the results for all authentication scenarios.
Active Authentication Method
Authentication result
Network
Access?
MAC
802.1x
MAC
Failure
-
No
Success
-
Yes
802.1x Not Mandatory
-
Success
Yes
-
Failure
No
-
-
Yes
802.1x Mandatory
-
Failure
No
-
Success
Yes
-
-
No