ZyXEL Communications NWA3560-N User Manual page 293

Nwa3000-n series wireless n business wlan 3000 series access point
Hide thumbs Also See for NWA3560-N:
Table of Contents

Advertisement

RADI US is a sim ple package exchange in which your AP act s as a m essage relay bet ween t he
wireless client and t he net work RADI US server.
Types of RADIUS Messages
The following t ypes of RADI US m essages are exchanged bet ween t he access point and t he RADI US
server for user aut hent icat ion:
Access- Request
Sent by an access point request ing aut hent icat ion.
Access- Rej ect
Sent by a RADI US server rej ect ing access.
Access-Accept
Sent by a RADI US server allowing access.
Access- Challenge
Sent by a RADI US server request ing m ore inform at ion in order t o allow access. The access point
sends a proper response from t he user and t hen sends anot her Access- Request m essage.
The following t ypes of RADI US m essages are exchanged bet ween t he access point and t he RADI US
server for user account ing:
Account ing- Request
Sent by t he access point request ing account ing.
Account ing- Response
Sent by t he RADI US server t o indicat e t hat it has st art ed or st opped account ing.
I n order t o ensure net work securit y, t he access point and t he RADI US server use a shared secret
key, which is a password, t hey bot h know. The key is not sent over t he net work. I n addit ion t o t he
shared key, password inform at ion exchanged is also encrypt ed t o prot ect t he net work from
unaut horized access.
Types of EAP Authentication
This sect ion discusses som e popular aut hent icat ion t ypes: EAP- MD5, EAP-TLS, EAP-TTLS, PEAP and
LEAP . Your wireless LAN device m ay not support all aut hent icat ion t ypes.
EAP ( Ext ensible Aut hent icat ion Prot ocol) is an aut hent icat ion prot ocol t hat runs on t op of t he I EEE
802.1x t ransport m echanism in order t o support m ult iple t ypes of user aut hent icat ion. By using EAP
t o int eract wit h an EAP- com pat ible RADI US server, an access point helps a wireless st at ion and a
RADI US server perform aut hent icat ion.
The t ype of aut hent icat ion you use depends on t he RADI US server and an int erm ediary AP( s) t hat
support s I EEE 802.1x. .
For EAP-TLS aut hent icat ion t ype, you m ust first have a wired connect ion t o t he net work and obt ain
t he cert ificat e( s) from a cert ificat e aut horit y ( CA) . A cert ificat e ( also called digit al I Ds) can be used
t o aut hent icat e users and a CA issues cert ificat es and guarant ees t he ident it y of each cert ificat e
owner.
NWA3000-N Series User's Guide
Appendix C Wireless LANs
293

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Nwa3160-n

Table of Contents