Authentication - 3Com 3CRWX120695A Reference Manual

Wireless lan mobility system wireless lan switch manager
Hide thumbs Also See for 3CRWX120695A:
Table of Contents

Advertisement

324
C
7: C
HAPTER
ONFIGURING

Authentication

A
, A
UTHENTICATION
UTHORIZATION
You can configure authentication rules for each type of user, on an
individual SSID or wired authentication port basis. MSS authenticates
users based on user information on RADIUS servers or in the WX switch's
local database. The RADIUS servers or local database authorize
successfully authenticated users for specific network access, including
VLAN membership. Optionally, you also can configure accounting rules to
track network access information.
The following sections describe the MSS authentication, authorization,
and accounting (AAA) features in more detail.
When a user attempts to access the network, MSS checks for an
authentication rule that matches the following parameters:
For wireless access, the authentication rule must match the SSID the
user is requesting, and the user's username or MAC address.
For access on a wired authentication port, the authentication rule
must match the user's username or MAC address.
If a matching rule is found, MSS then checks RADIUS servers or the WX
switch's local user database for credentials that match those presented by
the user. Depending on the type of authentication rule that matches the
SSID or wired authentication port, the required credentials are the
username or MAC address, and in some cases, a password.
Each authentication rule specifies where the user credentials are stored.
The location can be a group of RADIUS servers or the WX switch's local
database. In either case, if MSS has an authentication rule that matches
on the required parameters, MSS checks the username or MAC address
of the user and, if required, the password to make sure they match the
information configured on the RADIUS servers or in the local database.
The username or MAC address can be an exact match or can match a
userglob or MAC address glob, which allow wildcards to be used for all
or part of the username or MAC address. (For more information about
globs, see "Using User Globs and MAC Address Globs" on page 317.)
,
A
P
AND
CCOUNTING
ARAMETERS

Advertisement

Table of Contents
loading

This manual is also suitable for:

3crwx440095a

Table of Contents