Dell W-Series 304 Instant 6.5.1.0-4.3.1.0 User Guide - Page 153

Configuring Security Settings for a WLAN SSID Profile on Table 33

Page 153 highlights

Table 33: RADIUS Server Configuration Parameters Parameter Description RFC 3576 Select Enabled to allow the W-IAPs to process RFC 3576-compliant Change of Authorization (CoA) and disconnect messages from the RADIUS server. Disconnect messages cause a user session to be terminated immediately, whereas the CoA messages modify session authorization attributes such as data filters. RFC 5997 This helps to detect the server status of the RADIUS server. Every time there is an authentication or accounting request timeout, the W-IAP will send a status request enquiry to get the actual status of the RADIUS server before confirming the status of the server to be DOWN. l Authentication-Select this checkbox to ensure the W-IAP sends a status-server request to determine the actual state of the authentication server before marking the server as unavailable. l Accounting-Select this checkbox to ensure the W-IAP sends a status-server request to determine the actual state of the accounting server before marking the server as unavailable. NOTE: You can choose to select either the Authentication or Accounting checkboxes or select both checkboxes to support RFC5997. NAS IP address Allows you to configure an arbitrary IP address to be used as RADIUS attribute 4, NAS IP Address, without changing source IP Address in the IP header of the RADIUS packet. NOTE: If you do not enter the IP address, the VC IP address is used by default when Dynamic RADIUS Proxy is enabled. NAS Identifier Allows you to configure strings for RADIUS attribute 32, NAS Identifier, to be sent with RADIUS requests to the RADIUS server. Dead Time Specify a dead time for authentication server in minutes. When two or more authentication servers are configured on the W-IAP and a server is unavailable, the dead time configuration determines the duration for which the authentication server would be available if the server is marked as unavailable. Dynamic RADIUS proxy parameters Specify the following dynamic RADIUS proxy (DRP) parameters: l DRP IP-IP address to be used as source IP for RADIUS packets. l DRP Mask-Subnet mask of the DRP IP address. l DRP VLAN-VLAN in which the RADIUS packets are sent. l DRP Gateway-Gateway IP address of the DRP VLAN. For more information on dynamic RADIUS proxy parameters and configuration procedure, see Configuring Dynamic RADIUS Proxy Parameters on page 158. To assign the RADIUS authentication server to a network profile, select the newly added server when configuring security settings for a wireless or wired network profile. You can also add an external RADIUS server by selecting the New option when configuring a WLAN or wired profile. For more information, see Configuring Security Settings for a WLAN SSID Profile on page 86 and Configuring Security Settings for a Wired Profile on page 106. l LDAP-To configure an LDAP server, select the LDAP option and configure the attributes described in the following table: Dell Networking W-Series Instant 6.5.1.0-4.3.1.0 | User Guide Authentication and User Management | 153

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435

Parameter
Description
RFC 3576
Select
Enabled
to allow the W-IAPs to process RFC 3576-compliant Change of Authorization (CoA)
and disconnect messages from the RADIUS server. Disconnect messages cause a user session to
be terminated immediately, whereas the CoA messages modify session authorization attributes
such as data filters.
RFC 5997
This helps to detect the server status of the RADIUS server. Every time there is an authentication or
accounting request timeout, the W-IAP will send a status request enquiry to get the actual status of
the RADIUS server before confirming the status of the server to be DOWN.
l
Authentication
—Select this checkbox to ensure the W-IAP sends a status-server request to
determine the actual state of the authentication server before marking the server as
unavailable.
l
Accounting
—Select this checkbox to ensure the W-IAP sends a status-server request to
determine the actual state of the accounting server before marking the server as unavailable.
NOTE:
You can choose to select either the Authentication or Accounting checkboxes or select both
checkboxes to support RFC5997.
NAS IP
address
Allows you to configure an arbitrary IP address to be used as RADIUS attribute 4, NAS IP Address,
without changing source IP Address in the IP header of the RADIUS packet.
NOTE:
If you do not enter the IP address, the VC IP address is used by default when
Dynamic
RADIUS Proxy
is enabled.
NAS
Identifier
Allows you to configure strings for RADIUS attribute 32, NAS Identifier, to be sent with RADIUS
requests to the RADIUS server.
Dead Time
Specify a dead time for authentication server in minutes.
When two or more authentication servers are configured on the W-IAP and a server is unavailable,
the dead time configuration determines the duration for which the authentication server would be
available if the server is marked as unavailable.
Dynamic
RADIUS
proxy
parameters
Specify the following dynamic RADIUS proxy (DRP) parameters:
l
DRP IP—IP address to be used as source IP for RADIUS packets.
l
DRP Mask—Subnet mask of the DRP IP address.
l
DRP VLAN—VLAN in which the RADIUS packets are sent.
l
DRP Gateway—Gateway IP address of the DRP VLAN.
For more information on dynamic RADIUS proxy parameters and configuration procedure, see
Configuring Dynamic RADIUS Proxy Parameters on page 158
.
Table 33:
RADIUS Server Configuration Parameters
To assign the RADIUS authentication server to a network profile, select the newly added server when
configuring security settings for a wireless or wired network profile.
You can also add an external RADIUS server by selecting the
New
option when configuring a WLAN or wired
profile. For more information, see
Configuring Security Settings for a WLAN SSID Profile on page 86
and
Configuring Security Settings for a Wired Profile on page 106
.
l
LDAP
—To configure an LDAP server, select the
LDAP
option and configure the attributes described in the
following table:
Dell Networking W-Series Instant 6.5.1.0-4.3.1.0 | User Guide
Authentication and User Management |
153