3Com 3CRWX120695A, 3CRWX440095A Configuration Manual page 279

Wireless lan switch and controller
Table of Contents

Advertisement

Last-resort — A network user requests access to the network,
without entering a username or password. MSS checks for a
last-resort authentication rule for the requested SSID (or for wired, if
the user is on a wired authentication port). If a matching rule is found,
MSS checks the RADIUS server group or local database for username
last-resort-wired (for wired authentication access) or
last-resort-ssid, where ssid is the SSID requested by the user. If the
user information is on a RADIUS server, MSS also checks for a
password, which is 3Com by default.
Authentication Algorithm
MSS can try more than one of the authentication types described in
"Authentication Types" to authenticate a user. MSS tries 802.1X first. If
the user's NIC supports 802.1X but fails authentication, MSS denies
access. Otherwise, MSS tries MAC authentication next. If MAC
authentication is successful, MSS grants access to the user. Otherwise,
MSS tries the fallthru authentication type specified for the SSID or wired
authentication port. The fallthru authentication type can be one of the
following:
Web
Last-resort
None
Web and last-resort are described in "Authentication Types". None
means the user is automatically denied access. The fallthru authentication
type for wireless access is associated with the SSID (through a service
profile). The fallthru authentication type for wired authentication access is
specified with the wired authentication port. (For information about
service profiles, see "Service Profiles" on page 129. For information
about wired authentication port configuration, see "Setting a Port for a
Wired Authentication User" on page 52.)
The fallthru authentication type None is different from the authentication
method none you can specify for administrative access. The fallthru
authentication type None denies access to a network user. In contrast,
the authentication method none allows access to the WX switch by an
administrator. (See "Configuring AAA for Administrative and Local
Access" on page 31.)
Figure 10 shows how MSS tries the authentication types.
About AAA for Network Users
279

Advertisement

Table of Contents
loading

Table of Contents