Configuring Authentication Servers; Supported Authentication Servers - Siemens SCALANCE W1750D UI Configuration Manual

Table of Contents

Advertisement

Authentication and User Management

14.4 Configuring Authentication Servers

14.4
Configuring Authentication Servers
14.4.1

Supported Authentication Servers

Based on the security requirements, you can configure internal or external authentication
servers. This section describes the types of servers that can be configured for client
authentication:
● Internal RADIUS Server
● External RADIUS Server
● Dynamic Load Balancing between Two Authentication Servers
You can configure TACACS+ server for authenticating management users. For more
information on management users and TACACS+ server-based authentication, see
Configuring Authentication Parameters for Management Users (Page 200).
Internal RADIUS Server
Each AP has an instance of free RADIUS server operating locally. When you enable the
internal RADIUS server option for the network, the client on the AP sends a RADIUS packet
to the local IP address. The internal RADIUS server listens and replies to the RADIUS
packet. SCALANCE W serves as a RADIUS server for 802.1X authentication. However, the
internal RADIUS server can also be configured as a backup RADIUS server for an external
RADIUS server.
External RADIUS Server
In the external RADIUS server, the IP address of the VC is configured as the NAS IP
address. SCALANCE W RADIUS is implemented on the VC and this eliminates the need to
configure multiple NAS clients for every AP on the RADIUS server for client authentication.
SCALANCE W RADIUS dynamically forwards all the authentication requests from a NAS to
a remote RADIUS server. The RADIUS server responds to the authentication request with
an Access-Accept or Access-Reject message, and the clients are allowed or denied access
to the network depending on the response from the RADIUS server. When you enable an
external RADIUS server for the network, the client on the AP sends a RADIUS packet to the
local IP address. The external RADIUS server then responds to the RADIUS packet.
SCALANCE W supports the following external authentication servers:
● RADIUS
● LDAP
● ClearPass Policy Manager Server for AirGroup CoA
To use an LDAP server for user authentication, configure the LDAP server on the VC, and
configure user IDs and passwords. To use a RADIUS server for user authentication,
configure the RADIUS server on the VC.
206
Configuration Manual, 02/2018, C79000-G8976-C451-02
SCALANCE W1750D UI

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents