Dell W-Series 207 Instant 6.4.3.1-4.2 User Guide - Page 160

External RADIUS Server, RADIUS Server Authentication with VSA

Page 160 highlights

External RADIUS Server In the external RADIUS server, the IP address of the Virtual Controller is configured as the NAS IP address. Instant RADIUS is implemented on the Virtual Controller, and this eliminates the need to configure multiple NAS clients for every W-IAP on the RADIUS server for client authentication. Instant RADIUS dynamically forwards all the authentication requests from a NAS to a remote RADIUS server. The RADIUS server responds to the authentication request with an Access-Accept or Access-Reject message, and the clients are allowed or denied access to the network depending on the response from the RADIUS server. When you enable an external RADIUS server for the network, the client on the W-IAP sends a RADIUS packet to the local IP address. The external RADIUS server then responds to the RADIUS packet. Instant supports the following external authentication servers: l RADIUS (Remote Authentication Dial-In User Service) l LDAP (Lightweight Directory Access Protocol) l CPPM Server for AirGroup CoA To use an LDAP server for user authentication, configure the LDAP server on the Virtual Controller, and configure user IDs and passwords. To use a RADIUS server for user authentication, configure the RADIUS server on the Virtual Controller. RADIUS Server Authentication with VSA An external RADIUS server authenticates network users and returns to the W-IAP the vendor-specific attribute (VSA) that contains the name of the network role for the user. The authenticated user is placed into the management role specified by the VSA. Instant supports the following VSAs for user role and VLAN derivation rules: l AP-Group l AP-Name l ARAP-Features l ARAP-Security l ARAP-Security-Data l ARAP-Zone-Access l Acct-Authentic l Acct-Delay-Time l Acct-Input-Gigawords l Acct-Input-Octets l Acct-Input-Packets l Acct-Interim-Interval l Acct-Link-Count l Acct-Multi-Session-Id l Acct-Output-Gigawords l Acct-Output-Octets l Acct-Output-Packets l Acct-Session-Id l Acct-Session-Time l Acct-Status-Type l Acct-Terminate-Cause l Acct-Tunnel-Packets-Lost Dell Networking W-Series Instant 6.4.3.1-4.2.0.0 | User Guide Authentication and User Management | 160

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403

External RADIUS Server
In the external RADIUS server, the IP address of the Virtual Controller is configured as the NAS IP address.
Instant RADIUS is implemented on the Virtual Controller, and this eliminates the need to configure multiple
NAS clients for every W-IAP on the RADIUS server for client authentication. Instant RADIUS dynamically
forwards all the authentication requests from a NAS to a remote RADIUS server. The RADIUS server responds
to the authentication request with an
Access-Accept
or
Access-Reject
message, and the clients are allowed
or denied access to the network depending on the response from the RADIUS server. When you enable an
external RADIUS server for the network, the client on the W-IAP sends a RADIUS packet to the local IP address.
The external RADIUS server then responds to the RADIUS packet.
Instant supports the following external authentication servers:
l
RADIUS (Remote Authentication Dial-In User Service)
l
LDAP (Lightweight Directory Access Protocol)
l
CPPM Server for AirGroup CoA
To use an LDAP server for user authentication, configure the LDAP server on the Virtual Controller, and
configure user IDs and passwords. To use a RADIUS server for user authentication, configure the RADIUS
server on the Virtual Controller.
RADIUS Server Authentication with VSA
An external RADIUS server authenticates network users and returns to the W-IAP the vendor-specific attribute
(VSA) that contains the name of the network role for the user. The authenticated user is placed into the
management role specified by the VSA.
Instant supports the following VSAs for user role and VLAN derivation rules:
l
AP-Group
l
AP-Name
l
ARAP-Features
l
ARAP-Security
l
ARAP-Security-Data
l
ARAP-Zone-Access
l
Acct-Authentic
l
Acct-Delay-Time
l
Acct-Input-Gigawords
l
Acct-Input-Octets
l
Acct-Input-Packets
l
Acct-Interim-Interval
l
Acct-Link-Count
l
Acct-Multi-Session-Id
l
Acct-Output-Gigawords
l
Acct-Output-Octets
l
Acct-Output-Packets
l
Acct-Session-Id
l
Acct-Session-Time
l
Acct-Status-Type
l
Acct-Terminate-Cause
l
Acct-Tunnel-Packets-Lost
Dell Networking W-Series Instant 6.4.3.1-4.2.0.0 | User Guide
Authentication and User Management |
160