beautypg.com

Configuring radius profiles, Radius servers enforcing vlan access control, Adding or modifying a radius server profile – Proxim ORiNOCO AP-700 User Manual

Page 86

background image

Performing Advanced Configuration

AP-700 User Guide

Radius Profiles

86

Authentication servers for each VLAN shall be configured as part of the configuration options for that VLAN. RADIUS profiles are independent
of VLANs. The user can define any profile to be the default and associate all VLANs to that profile. Four profiles are created by default, “MAC
Authentication”, “EAP Authentication”, Accounting”, and “Management”.

RADIUS Servers Enforcing VLAN Access Control

A RADIUS server can be used to enforce VLAN access control in two ways:

Authorize the SSID the client uses to connect to the AP. The SSID determines the VLAN that the client gets assigned to.

Assigning the user to a VLAN by specifying the VLAN membership information of the user.

Configuring Radius Profiles

A RADIUS server Profile consists of a Primary and a Secondary RADIUS server that get assigned to act as either MAC Authentication
servers, 802.1x/EAP Authentication servers, or Accounting Servers in the VLAN Configuration. Refer to

Configuring Security Profiles

.

The RADIUS Profiles Sub-tab allows you to add new RADIUS profiles or modify or delete existing profiles.

Figure 4-33 RADIUS Server Profiles

Adding or Modifying a RADIUS Server Profile

Perform the following procedure to add a RADIUS server profile and to configure its parameters.
1. Click Add to create a new profile. To Modify an existing profile, select the profile and click Edit. To delete an existing profile, select the

profile and click Delete. You cannot delete a RADIUS server profile if you are using it in an SSID. Also, the four default RADIUS server
profiles cannot be deleted (indices 1.1, 1.2, 2.1, 2.2, 3.1, 3.2, and 4.1, 4.2.)

2. Configure the following parameters for the RADIUS Server profile (refer to

Figure 4-34

):

NOTE

This page configures only the Primary RADIUS Server associated with the profile. After configuring these parameters, save them by
clicking OK. Then, to configure the Secondary RADIUS Server, edit the profile from the main page.