Dell W-Series 207 Instant 6.5.1.0-4.3.1.0 User Guide - Page 165

Enabling 802.1X Supplicant Support, Configuring a W-IAP for 802.1X Supplicant Support

Page 165 highlights

5. Specify the type of authentication server to use and configure other required parameters. For more information on configuration parameters, see Configuring Security Settings for a Wired Profile on page 106. 6. Click Next to define access rules, and then click Finish to apply the changes. 7. Assign the profile to an Ethernet port. For more information, see Assigning a Profile to Ethernet Ports on page 109. In the CLI To enable 802.1X authentication for a wired profile: (Instant AP)(config)# wired-port-profile (Instant AP)(wired ap profile )# type {|} (Instant AP)(wired ap profile )# dot1x (Instant AP)(wired ap profile )# auth-server (Instant AP)(wired ap profile )# auth-server (Instant AP)(wired ap profile )# server-load-balancing (Instant AP)(wired ap profile )# radius-reauth-interval (Instant AP)(wired ap profile )# end (Instant AP)# commit apply Enabling 802.1X Supplicant Support The 802.1X authentication protocol prevents the unauthorized clients from gaining access to the network through publicly accessible ports. If the ports to which the W-IAPs are connected, are configured to use the 802.1X authentication method, ensure that you configure the W-IAPs to function as an 802.1X client or supplicant. If your network requires all wired devices to authenticate using PEAP or TLS protocol, you need to configure the W-IAP uplink ports for 802.1X authentication, so that the switch grants access to the W-IAP only after completing the authentication as a valid client. To enable the 802.1X supplicant support on a W-IAP, ensure that the 802.1X authentication parameters are configured on all W-IAPs in the cluster and are stored securely in the W-IAP flash. The 802.1X supplicant support feature is not supported with mesh and Wi-Fi uplink. Configuring a W-IAP for 802.1X Supplicant Support To enable 802.1X supplicant support, configure 802.1X authentication parameters on every W-IAP using the Instant UI or the CLI. In the UI 1. To use PEAP protocol-based 802.1X authentication method, complete the following steps: a. In the Access Points tab, click the W-IAP on which you want to set the variables for 802.1X authentication, and then click the edit link. b. In the Edit Access Point window, click the Uplink tab. c. Under PEAP user, enter the username, password, and retype the password for confirmation. The W-IAP username and password are stored in W-IAP flash. When the W-IAP boots, the /tmp/ap1xuser and /tmp/ap1xpassword files are created based on these two variables. The default inner authentication protocol for PEAP is MS-CHAPV2. 2. To upload server certificates for validating the authentication server credentials, complete the following steps: Dell Networking W-Series Instant 6.5.1.0-4.3.1.0 | User Guide Authentication and User Management | 165

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435

5. Specify the type of authentication server to use and configure other required parameters. For more
information on configuration parameters, see
Configuring Security Settings for a Wired Profile on page 106
.
6. Click
Next
to define access rules, and then click
Finish
to apply the changes.
7. Assign the profile to an Ethernet port. For more information, see
Assigning a Profile to Ethernet Ports on
page 109
.
In the CLI
To enable 802.1X authentication for a wired profile:
(Instant AP)(config)# wired-port-profile <name>
(Instant AP)(wired ap profile <name>)# type {<employee>|<guest>}
(Instant AP)(wired ap profile <name>)# dot1x
(Instant AP)(wired ap profile <name>)# auth-server <server1>
(Instant AP)(wired ap profile <name>)# auth-server <server2>
(Instant AP)(wired ap profile <name>)# server-load-balancing
(Instant AP)(wired ap profile <name>)# radius-reauth-interval <Minutes>
(Instant AP)(wired ap profile <name>)# end
(Instant AP)# commit apply
Enabling 802.1X Supplicant Support
The 802.1X authentication protocol prevents the unauthorized clients from gaining access to the network
through publicly accessible ports. If the ports to which the W-IAPs are connected, are configured to use the
802.1X authentication method, ensure that you configure the W-IAPs to function as an 802.1X client or
supplicant. If your network requires all wired devices to authenticate using PEAP or TLS protocol, you need to
configure the W-IAP uplink ports for 802.1X authentication, so that the switch grants access to the W-IAP only
after completing the authentication as a valid client.
To enable the 802.1X supplicant support on a W-IAP, ensure that the 802.1X authentication parameters are
configured on all W-IAPs in the cluster and are stored securely in the W-IAP flash.
The 802.1X supplicant support feature is not supported with mesh and Wi-Fi uplink.
Configuring a W-IAP for 802.1X Supplicant Support
To enable 802.1X supplicant support, configure 802.1X authentication parameters on every W-IAP using the
Instant UI or the CLI.
In the UI
1. To use PEAP protocol-based 802.1X authentication method, complete the following steps:
a.
In the
Access Points
tab, click the W-IAP on which you want to set the variables for 802.1X
authentication, and then click the
edit
link.
b. In the
Edit Access Point
window, click the
Uplink
tab.
c.
Under PEAP user, enter the username, password, and retype the password for confirmation. The W-IAP
username and password are stored in W-IAP flash. When the W-IAP boots, the
/tmp/ap1xuser
and
/tmp/ap1xpassword
files are created based on these two variables.
The default inner authentication protocol for PEAP is MS-CHAPV2.
2. To upload server certificates for validating the authentication server credentials, complete the following
steps:
Dell Networking W-Series Instant 6.5.1.0-4.3.1.0 | User Guide
Authentication and User Management |
165