Assumptions/Recommendations; Use Cases; Vendor Interoperability - Extreme Networks Summit WM Technical Reference Manual

Version 5.1
Hide thumbs Also See for Summit WM:
Table of Contents

Advertisement

Assumptions/recommendations

1 The MU session timeout is a very important factor in radius profiles definitions – timeouts. In order
to avoid an infinitive loop, the radius redundancy should happen within 30 sec, otherwise the
authentication requests will be sent to the non-responsive server.
2 MAC-based authentication is not available for the 3
3 Wireless AP keeps records of rejected MAC addresses in the SIB table (Station Information Base),
with the special status "cleared". The capacity of the table is 128 records. It could happen that the
limit is reached, for example when a number of unknown clients (MAC addresses) attempts to
authenticate. In that case a perfectly valid client can not associate, until a record in the SIB table is
timed out (2-3 min).

Use Cases

The MAC-based authentication could be used in different ways, as described in the MRD and design
document. It can be implemented as:
1 Corporate authentication mechanism.
2 Addition to the existing authentication mechanism in a form of the device (MAC) authentication.
In both cases the feature gives the network administrators an option to increase security by allowing
association with a WM-AD to authorized devices only. It will require RADIUS server with accounts
based on the MAC address for each device, which will be authorized to access a WM-AD, and update
for all new devices. The second level of authentication requires users' accounts for CP or 802.1X, which
are independent from the MAC accounts.
The MAC based authentication can be used for any type of the WM-AD assignment (3
Excluded).
In the environment with multiple RADIUS servers, a server may be dedicated to the device
authentication, while the other server may be used for the users' authentication, or one server can be
used for both levels. The system will allow redundancy on both levels.

Vendor Interoperability

MAC-based authentication has been tested with the following platforms:
Newbury Locale Server
IAS
FreeRADIUS
Funk Steel Belted RADIUS & Odyssesy
Summit WM Technical Reference Guide, Software Version 5.1
rd
Party AP WM-AD
rd
Party AP
117

Advertisement

Table of Contents
loading

Table of Contents