Extreme Networks Summit WM User Manual page 117

Table of Contents

Advertisement

immediately. If the Altitude AP is not connected, the new credentials are delivered the next time the
Altitude AP connects to the Summit WM Controller.
There are two main aspects to the 802.1X feature:
Credential management - The Summit WM Controller and the Altitude AP are responsible for the
requesting, creating, deleting, or invalidating the credentials used in the authentication process.
Authentication - The Altitude AP is responsible for the actual execution of the EAP-TLS or PEAP
protocol.
802.1X authentication can be configured on a per access point basis. For example, 802.1X authentication
can be applied to specific Altitude APs individually or with a multi-edit function.
The 802.1X authentication supports two authentication methods:
PEAP (Protected Extensible Authentication Protocol)
Is the recommended 802.1X authentication method
Requires minimal configuration effort and provides equal authentication protection to EAP-TLS
Uses user ID and passwords for authentication of access points
EAP-TLS
Requires more configuration effort
Requires the use of a third-party Certificate Authentication application
Uses certificates for authentication of access points
Summit WM Controller can operate in either proxy mode or pass through mode.
Proxy mode - The Summit WM Controller generates the public and private key pair used in
the certificate.
Pass through mode - The certificate and private key is created by the third-party Certificate
Authentication application.
NOTE
Although an Altitude AP can support using both PEAP and EAP-TLS credentials simultaneously, it is not
recommended to do so. Instead, it is recommended that only one type of authentication be used, and that only
credentials for that type of authentication get installed on the Altitude AP.
Configuring 802.1X PEAP authentication
PEAP authentication uses user ID and passwords for authentication. To successfully configure 802.1X
authentication of an Altitude AP, the Altitude AP must first be configured for 802.1X authentication
before the Altitude AP is deployed on a 802.1X enabled switch port.
NOTE
Usernames and passwords for PEAP authentication credentials each have a maximum length of 128 characters.
Summit WM User Guide, Software Version 5.3
117

Advertisement

Table of Contents
loading

Table of Contents