Download Print this page

Configuring The Nac Inclusion List - Extreme Networks Summit WM3000 Series Reference Manual

Summit wm3000 series controller system software version 4.0

Advertisement

Network Setup
SSID
Access Category
AIFSN
Transmit Ops
ECW Minimum
ECW Maximum
Max Retries
Use DSCP or 802.1p Select the DSCP or 802.1p radio buttons to choose between DSCP and
5 Refer to the Status field for the current state of the requests made from applet. This field displays
error messages if something goes wrong in the transaction between the applet and the controller.
6 Click OK to use the changes to the running configuration and close the dialog.
7 Click Cancel to close the dialog without committing updates to the running configuration.

Configuring the NAC Inclusion List

Using NAC, the controller acts as an enforcement entity before allowing MU access to specific network
resources. NAC performs a MU host integrity check wherein a MU sends host integrity information to
the NAC server. The NAC server configuration is defined on the controller on a per WLAN basis. NAC
verifies a MU's compliance with the NAC server's security policy (not the controller).
For a NAC configuration example using the controller CLI, see
the Controller CLI" on page
An include list is a list of MAC addresses configured for a WLAN. During EAP authentication, the EAP
server (Radius or NAC server) is determined based on the MU's MAC address.
All non-802.1x devices are partitioned into a WLAN (separate from a 802.1x enabled WLAN).
Communication between devices in a 802.1x supported WLAN and a non 802.1x supported WLAN
is achieved by merging the WLANs within the same VLAN.
The controller uses the include list to add devices that are NAC supported. The following explains how
authentication is achieved using 802.1x. The controller authenticates 802.1x enabled devices using one of
the following:
156
Service Set ID
Displays the
index. This SSID is read-only and cannot be modified within this screen.
Displays the Access Category for the intended radio traffic. The Access
Categories are the different WLAN-WMM options available to the radio.
The four Access Category types are:
Background -
Optimized for background traffic
Best-effort
- Optimized for best effort traffic
Video
- Optimized for video traffic. Video traffic receives priority.
Voice
- Optimized for voice traffic. Voice traffic receives priority.
Arbitrary Inter-frame Space Number
Define the current
priority traffic categories should have lower AIFSNs than lower-priority
traffic categories. This will causes lower-priority traffic to wait longer
before trying to access the medium.
Define the maximum duration a device can transmit after obtaining a
transmit opportunity. For higher-priority traffic categories, this value
should be set to a low number.
The ECW Minimum is combined with the ECW Maximum to make the
Contention screen. From this range, a random number is selected for the
back off mechanism. Select a lower value for high priority traffic.
The ECW Maximum is combined with the ECW Minimum to make the
Contention screen. From this range, a random number is selected for the
back off mechanism. Lower values are used for higher priority traffic
Define a maximum number of retries for each Access Category.
802.1p.
164.
(SSID) associated with the selected WMM
"NAC Configuration Examples Using
Summit WM3000 Series Controller System Reference Guide
(AIFSN). Higher-

Hide quick links:

Advertisement

loading

This manual is also suitable for:

Summit wm3600Summit wm3700