Radius Server Requirements; Configuring Authentication For 802.1X Users Of A Third-Party Ap With Tagged Ssids - D-Link DWS-1008 - AirPremier MobileLAN Switch Product Manual

8 port 10/100 wireless switch with power over ethernet
Hide thumbs Also See for DWS-1008 - AirPremier MobileLAN Switch:
Table of Contents

Advertisement

• For 802.1X users, the usernames and passwords must be configured on the RADIUS
server.
• For non-802.1X users of a tagged SSID, the special username web-portal-ssid or last-
resort-ssid must be configured, where ssid is the SSID name. The fallthru authentication
type (web-portal or last-resort) specified for the wired authentication port connected to the
AP determines which username you need to configure.
• For any users of an untagged SSID, the special username web-portal-wired or last-resort-
wired must be configured, depending on the fallthru authentication type specified for the
wired authentication port.
Configuring Authentication for 802.1X Users of a Third-
To configure MSS to authenticate 802.1X users of a third-party AP, use the commands below to do the
following:
• Configure the port connected to the AP as a wired authentication port. Use the following
command:
set port type wired-auth port-list [tag tag-list] [max-sessions num]
[auth-fall-thru {last-resort | none | web-portal}]
• Configure a MAC authentication rule for the AP. Use the following command:
set authentication mac wired mac-addr-glob method1
Note: The switch system IP address must be the same as the IP address configured on
the VLAN that contains the proxy port.
• Configure the switch port connected to the AP as a RADIUS proxy for the SSID supported
by the AP. If SSID traffic from the AP is tagged, assign the same tag value to the switch
port. Use the following command:
set radius proxy port port-list [tag tag-value] ssid ssid-name
• Add a RADIUS proxy entry for the AP. The proxy entry specifies the IP address of the AP
and the UDP ports on which the switch listens for RADIUS access-requests and stop-
accounting records from the AP. Use the following command:
set radius proxy client address ip-address [port udp-port-number]
[acct-port acct-udp-port-number] key string
• Configure a proxy authentication rule for the AP's users. Use the following command:
set authentication proxy ssid ssid-name user-glob radius-server-group
D-Link DWS-1008 User Manual

RADIUS Server Requirements

Party AP with Tagged SSIDs
11

Advertisement

Table of Contents
loading

Table of Contents