Using An External Server For Administrator Authentication - Ruckus Wireless ZoneDirector 1100 User Manual

Smart wi-fi controllers that support up to 1000 aps
Hide thumbs Also See for ZoneDirector 1100:
Table of Contents

Advertisement

Using an External Server for Administrator
Authentication
ZoneDirector supports additional administrator accounts that can be authenticated using an
external authentication server such as RADIUS, LDAP, Active Directory or TACACS+. Three
types of administrative privileges can be assigned to these administrator accounts:
Super Admin - Allows all types of configuration and management tasks
Operator Admin - Allows AP configuration only
Monitoring Admin – Allows monitoring operations only
This section provides basic instructions for setting up ZoneDirector to authenticate additional
administrator accounts with an external authentication server. For more information on AAA
server configuration, see
To authenticate ZoneDirector administrators using an AAA server
1. Set up Group Attributes on the AAA server.
RADIUS:
Ruckus Wireless private attribute
– Vendor ID: 25053
– Vendor Type/Attribute Number: 1 (Ruckus-User-Groups)
– Value Format: group_attr1,group_attr2,group_attr3,...
Cisco private attribute (if your network is using a Cisco access control server)
– Vendor ID: 9
– Vendor Type / Attribute Number: 1 (Cisco-AVPair)
– Value Format: shell:roles="group_attr1 group_attr2 group_attr3 ..."
Active Directory or LDAP:
Set up administrator groups.
Populate these groups with users to whom you want to grant administrator access. One
way to do this is to edit each user's Member of profile and add the group to which you
want the user to belong. Remember the group names that you set; you will enter this
information when you create administrator roles in ZoneDirector (see Step 3).
TACACS+: See
"TACACS+"
2. Set up ZoneDirector to use an AAA server (Configure > AAA Servers).
3. Create an Administrator Role in ZoneDirector (Configure > Roles).
Allow access to all/specific WLANs.
Allow/deny Guest Pass Generation.
Ensure that Allow ZoneDirector Administration is enabled, and choose the level of
administration privileges you want to allow for this role.
CAUTION: If you do not select the Allow ZoneDirector Administration check box, administra-
tors that are assigned this role will be unable to log into ZoneDirector even if all other settings
are configured correctly.

Using an External Server for Administrator Authentication

"Using an External AAA Server"
on
page 107
for more information.
Setting Administrator Preferences
on
page
89.
269

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zonedirector 3000Zonedirector 5000

Table of Contents