D-Link DWL-2210AP Product Manual - Page 131

Network Infrastructure and Choosing Between Built-in or External, Authentication Server

Page 131 highlights

Appendix A: Configuring Security Settings on Wireless Clients • Configuring an External RADIUS Server to Recognize the D-Link DWL-2210AP • Obtaining a TLS-EAP Certificate for a Client Network Infrastructure and Choosing Between Built-in or External Authentication Server Network security configurations including Public Key Infrastructures (PKI), Remote Authentication Dial-in User Server (RADIUS) servers, and Certificate Authority (CA) can vary a great deal from one organization to the next in terms of how they provide Authentication, Authorization, and Accounting (AAA). Ultimately, the particulars of your infrastructure will determine how clients should configure security to access the wireless network. Rather than try to predict and address the details of every possible scenario, this document provides general guidelines about each type of client configuration supported by the D-Link DWL-2210AP. I Want to Use the Built-in Authentication Server (EAP-PEAP) If you do not have a RADIUS server or PKI infrastructure in place and/or are unfamiliar with many of these concepts, we strongly recommend setting up the D-Link DWL-2210APs with security that uses the Built-in Authentication Server on the AP. This will mean setting up the AP to use either IEEE 802.1x or WPA with RADIUS security mode. (The built-in authentication server uses EAP-PEAP authentication protocol.) • If the D-Link DWL-2210AP is set up to use IEEE 802.1x mode and the Built-in Authentication Server, then configure wireless clients as described in "IEEE 802.1x Client Using EAP/PEAP" in this manual. • If the D-Link DWL-2210AP is configured to use WPA with RADIUS mode and the Built-in Authentication Server, configure wireless clients as described in "WPA with RADIUS Client Using EAP/PEAP" in this manual. I Want to Use an External RADIUS Server with EAP-TLS Certificates or EAP-PEAP We make the assumption that if you have an external RADIUS server and PKI/CA setup, you will know how to configure client security options appropriate to your security infrastructure beyond the fundamental suggestions given here. Topics covered here that particularly relate to client security configuration in a RADIUS - PKI environment are: • "IEEE 802.1x Client Using EAP/TLS Certificate" in this manual. • "WPA with RADIUS Client Using EAP-TLS Certificate" in this manual. • "Configuring an External RADIUS Server to Recognize the D-Link DWL-2210AP" in this manual. • "Obtaining a TLS-EAP Certificate for a Client" in this manual. Details on how to configure an EAP-PEAP client with an external RADIUS server are not covered in this document. 131

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193

131
• Configuring an External RADIUS Server to Recognize the D-Link DWL-2210AP
• Obtaining a TLS-EAP Certificate for a Client
Network Infrastructure and Choosing Between Built-in or External
Authentication Server
Network security configurations including
Public Key Infrastructures
(PKI),
Remote
Authentication Dial-in User Server
(RADIUS) servers, and
Certificate Authority
(CA)
can vary a great deal from one organization to the next in terms of how they provide
Authentication, Authorization,
and
Accounting
(AAA). Ultimately, the particulars of
your infrastructure will determine how clients should configure security to access the
wireless network. Rather than try to predict and address the details of every possible
scenario, this document provides general guidelines about each type of client
configuration supported by the D-Link DWL-2210AP.
I Want to Use the Built-in Authentication Server (EAP-PEAP)
If you do not have a RADIUS server or PKI infrastructure in place and/or are
unfamiliar with many of these concepts, we strongly recommend setting up the D-Link
DWL-2210APs with security that uses the
Built-in Authentication Server
on the AP. This
will mean setting up the AP to use either IEEE 802.1x or WPA with RADIUS security
mode. (The built-in authentication server uses EAP-PEAP authentication protocol.)
I Want to Use an External RADIUS Server with EAP-TLS Certificates or EAP-PEAP
We make the assumption that if you have an external RADIUS server and PKI/CA
setup, you will know how to configure client security options appropriate to your security
infrastructure beyond the fundamental suggestions given here. Topics covered here that
particularly relate to client security configuration in a RADIUS - PKI environment are:
• “IEEE 802.1x Client Using EAP/TLS Certificate” in this manual.
• “WPA with RADIUS Client Using EAP-TLS Certificate” in this manual.
• “Configuring an External RADIUS Server to Recognize the D-Link DWL-2210AP” in
this manual.
• “Obtaining a TLS-EAP Certificate for a Client” in this manual.
Details on how to configure an EAP-PEAP client with an external RADIUS server are
not covered in this document.
If the D-Link DWL-2210AP is configured to use WPA with RADIUS mode and the
Built-in Authentication Server, configure wireless clients as described in “WPA with
RADIUS Client Using EAP/PEAP” in this manual.
If the D-Link DWL-2210AP is set up to use IEEE 802.1x mode and the Built-in
Authentication Server, then configure wireless clients as described in “IEEE 802.1x
Client Using EAP/PEAP” in this manual.
Appendix A: Configuring Security Settings on Wireless Clients