Netgear WC7660SKT Reference Manual - Page 104

Manage Authentication Servers and Authentication Server Groups, Authentication Server Concepts

Page 104 highlights

ProSAFE Wireless Controller WC7600 Manage Authentication Servers and Authentication Server Groups You can set up internal and external authentication servers and server groups that the wireless controller can use for authentication. Authentication Server Concepts You can specify three types of authentication servers: internal, external RADIUS, and external LDAP: • Internal authentication server. The wireless controller handles authentication. If you use this setting, set up WiFi clients on the User Management screen (see Manage Users, Accounts, and Passwords on page 150.) • External RADIUS server. You can define a basic external RADIUS server that you would typically use in the profiles of a basic profile group of a small-scale network. You must specify its configuration on the basic Authentication Server screen (see the next section) so that you can select this authentication option during the configuration of a profile. As part of the advanced authentication server settings, you can define multiple external RADIUS servers that you would typically use in a more complex network with many profiles. You can then assign different RADIUS servers to different profiles. By default, the external RADIUS server for the basic authentication group is called basic-Auth. You cannot change this name. By default, the external RADIUS authentication servers for the advanced authentication groups are called Auth1 through Auth8, and you can change these names. You can assign the basic-Auth server to an advanced profile group, and you can assign a RADIUS server of an advanced authentication group to the basic profile group. See the following configuration guidelines for external RADIUS servers: - You need to add only the IP address of the wireless controller as a RADIUS client to the RADIUS server. All managed access points are then automatically known to the RADIUS server. - For configuration guidelines for external MAC authentication, see Guidelines for External MAC Authentication on page 110. - For configuration guidelines for external authentication of captive portal users, see Manage Guest Network Access on page 145. • External LDAP server. You can define one external LDAP server (commonly referred to as an Active Directory [AD] server). You must specify its configuration on the basic Authentication Server screen (see the next section) so that you can select this authentication option during the configuration of a profile. By default, the external LDAP server for the basic authentication group is called basic-LDAP. You cannot change this name, and you cannot configure any LDAP servers Manage Security Profiles and Profile Groups 104

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307

Manage Security Profiles and Profile Groups
104
ProSAFE Wireless Controller WC7600
Manage Authentication Servers and Authentication
Server Groups
You can set up internal and external authentication servers and server groups that the
wireless controller can use for authentication.
Authentication Server Concepts
You can specify three types of authentication servers: internal, external RADIUS, and
external LDAP:
Internal authentication server
. The wireless controller handles authentication. If you
use this setting, set up WiFi clients on the User Management screen (see
Manage Users,
Accounts, and Passwords
on page
150.)
External RADIUS server
. You can define a basic external RADIUS server that you would
typically use in the profiles of a basic profile group of a small-scale network. You must
specify its configuration on the basic Authentication Server screen (see the next section)
so that you can select this authentication option during the configuration of a profile. As
part of the advanced authentication server settings, you can define multiple external
RADIUS servers that you would typically use in a more complex network with many
profiles. You can then assign different RADIUS servers to different profiles.
By default, the external RADIUS server for the basic authentication group is called
basic-Auth
. You cannot change this name. By default, the external RADIUS
authentication servers for the advanced authentication groups are called
Auth1
through
Auth8
, and you
can
change these names. You can assign the
basic-Auth
server to an
advanced profile group, and you can assign a RADIUS server of an advanced
authentication group to the basic profile group.
See the following configuration guidelines for external RADIUS servers:
-
You need to add only the IP address of the wireless controller as a RADIUS client to
the RADIUS server. All managed access points are then automatically known to the
RADIUS server.
-
For configuration guidelines for external MAC authentication, see
Guidelines for
External MAC Authentication
on page
110.
-
For configuration guidelines for external authentication of captive portal users, see
Manage Guest Network Access
on page
145.
External LDAP server
. You can define one external LDAP server (commonly referred to
as an Active Directory [AD] server). You must specify its configuration on the basic
Authentication Server screen (see the next section) so that you can select this
authentication option during the configuration of a profile.
By default, the external LDAP server for the basic authentication group is called
basic-LDAP
. You cannot change this name, and you cannot configure any LDAP servers