Configuring Aaa For Users Of Third-Party Aps - D-Link DWS-1008 User Manual

Wireless 8 port switch with poe
Hide thumbs Also See for DWS-1008:
Table of Contents

Advertisement

DWS-1008 User's Manual
Configuring AAA for Users of Third-Party APs
A switch can provide network access for users associated with a third-party AP that has
authenticated the users with RADIUS. You can connect a third-party AP to a switch and
configure the switch to provide authorization for clients who authenticate and access the
network through the AP.
Authentication Process for Users of a Third-Party AP
1. MSS uses MAC authentication to authenticate the AP.
2. The user contacts the AP and negotiates the authentication protocol to be used.
3. The AP, acting as a RADIUS client, sends a RADIUS access-request to the switch.
The access-request includes the SSID, the user's MAC address, and the username.
4. For 802.1X users, the AP uses 802.1X to authenticate the user, using the switch as its
RADIUS server. The proxies RADIUS requests from the AP to a real RADIUS server,
depending on the authentication method specified in the proxy authentication rule for
the user.
For non-802.1X users, the AP does not use 802.1X. The switch sends a RADIUS query
for the special username web-portal-ssid or last-resort-ssid, where ssid is the SSID
name. The fallthru authentication type (web-portal or last-resort) specified for the
wired authentication port connected to the AP determines which username is used.
For any users of an AP that sends SSID traffic to the switch on an untagged VLAN, the
switch does not use 802.1X. The switch sends a RADIUS query for the special username
web-portal-wired or last-resort-wired, depending on the fallthru authentication type
specified for the wired authentication port.
5. After successful RADIUS authentication of the user (or special username, for non-
802.1X users), MSS assigns authorization attributes to the user from the RADIUS
server's access-accept response.
6. When the user's session ends, the third-party AP sends a RADIUS stop-accounting
record to the switch. The switch then removes the session.
D-Link Systems, Inc.
Configuring AAA for Network Users
290

Advertisement

Table of Contents
loading

Table of Contents