Configuring Administrator Profiles On The Radius Server - Alvarion BreezeACCESS Wi2 System Manual

Table of Contents

Advertisement

9.1.3

Configuring Administrator Profiles on the RADIUS Server

To support more than one administrator username and password, you must use a RADIUS server to
manage them. The AP itself supports a single administrator name and password internally.
CAUTION
Improper configuration of the administrator profile could expose the AP to access by any user with a
valid account. The only thing that distinguishes an administrative account from that of a standard
user account is the setting of the service type. Make sure that a user is not granted access if the
service type is not Administrative.
This section presents all supported RADIUS and Alvarion attributes that can be used to configure an
administrator profile on a RADIUS server. Attributes starting with MS are Microsoft and are not
standard.
NOTE
In the following definitions strings are defined as 1 to 253 characters long.
.
NOTE
Only Access Request packets are supported. Access Accept, Access Reject, Access Challenge,
Accounting Request, or Accounting Response requests are not supported.
9.1.3.1
Access Request Attributes
The following are supported Access Request RADIUS attributes.
User-Name (string): The username assigned to the user or a device when using MAC
authentication.
NAS-Identifier (string): The NAS ID set on the Security > RADIUS page for the profile being
used.
Service-Type (32-bit unsigned integer): As defined in RFC 2865. Set as follows:
Web Admin is SERVICE_TYPE_ADMINISTRATIVE
Framed-MTU (32-bit unsigned integer): Hard-coded value of 1496.
BreezeMAX Wi² and BreezeACCESS Wi² System Manual
.
.
Using a RADIUS Server
159

Advertisement

Table of Contents
loading

This manual is also suitable for:

Breezemax wi2

Table of Contents