Authentication - Hirschmann BAT54 Installation Manual

Dual-band outdoor access point / bridge
Table of Contents

Advertisement

Authentication

The access point supports IEEE 802.1x access control for wireless clients. This
control feature prevents unauthorized access to the network by requiring a 802.1x
client application to submit user credentials for authentication. Client authentication
is then verified via by a RADIUS server using EAP (Extensible Authentication
Protocol) before the access point grants client access to the network.
Client MAC addresses can also be used for authentication on the access point. For
local MAC authentication, first define the default filtering policy using the address
filter default command. Then enter the MAC addresses to be filtered, indicating if
they are allowed or denied. For RADIUS MAC authentication, the MAC addresses
and filtering policy must be configured on the RADIUS server.
Command
802.1x
802.1x broadcast-key-
refresh-rate
802.1x session-key-
refresh-rate
802.1x session-timeout
802.1x supplicant
address filter default
address filter entry
address filter delete
mac-authentication server
mac-authentication
session-timeout
show authentication
802.1x
This command configures 802.1x as optionally supported or as required for wireless
clients. Use the no form to disable 802.1x support.
Syntax
802.1x <supported | required>
no 802.1x
• supported - Authenticates clients that initiate the 802.1x authentication
process. Uses standard 802.11 authentication for all others.
• required - Requires 802.1x authentication for all clients.
Function
Configures 802.1x as disabled, supported, or required
Sets the interval at which the primary broadcast keys are
refreshed for stations using 802.1x dynamic keying
Sets the interval at which unicast session keys are
refreshed for associated stations using dynamic keying
Sets the timeout after which a connected client must be
re-authenticated
Sets the supplicant user name and password for the
access point and enables the feature
Sets filtering to allow or deny listed addresses
Enters a MAC address in the filter table
Removes a MAC address from the filter table
Sets address filtering to be performed with local or remote
options
Sets the interval at which associated clients will be
re-authenticated with the RADIUS server authentication
database
Shows all 802.1x authentication settings, as well as the
address filter table
7
Authentication
Mode
Page
GC
7-35
GC
7-36
GC
7-37
GC
7-38
GC
7-42
GC
7-39
GC
7-40
GC
7-40
GC
7-41
GC
7-41
Exec
7-42
7-35

Advertisement

Table of Contents
loading

This manual is also suitable for:

Bat54m

Table of Contents