Alcatel-Lucent IAP93 Podręcznik Użytkownika Strona 149

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 148
149 | Authentication AOS-W Instant 6.3.1.1-4.0 | User Guide
Controller for communication with external RADIUS servers. Ensure that the Virtual Controller IP Address is set as
a NAS IP when configuring RADIUS server attributes with dynamic RADIUS proxy enabled. For more information
on configuring RADIUS server attributes, see Configuring an External Server for Authentication on page 144.
In the CLI
To enable the dynamic RADIUS proxy feature:
(Instant Access Point)(config)# dynamic-radius-proxy
(Instant Access Point)(config)# end
(Instant Access Point)# commit apply
Configuring Dynamic RADIUS Proxy Parameters for Authentication Servers
You can configure DRP parameters for the authentication server by using the AOS-W Instant UI or CLI.
In the AOS-W Instant UI
1. Click the Security>Authentication Servers.
2. To create a new server, click New and configure the required RADIUSserver parameters as described in Table
27.
3. Ensure that the following dynamic RADIUS proxy parameters are configured:
l DRP IP IP address to be used as source IP for RADIUS packets
l DRP Mask—Subnet mask of the DRP IP address.
l DRP VLANVLAN in which the RADIUS packets are sent.
l DRP GatewayGateway IP address of the DRP VLAN.
4. Click OK.
In the CLI
To configure dynamic RADIUS proxy parameters:
(Instant Access Point)(config)# wlan auth-server <profile-name>
(Instant Access Point)(Auth Server <profile-name>)# ip <IP-address>
(Instant Access Point)(Auth Server <profile-name>)# key <key>
(Instant Access Point)(Auth Server <profile-name>)# port <port>
(Instant Access Point)(Auth Server <profile-name>)# acctport <port>
(Instant Access Point)(Auth Server <profile-name>)# nas-id <NAS-ID>
(Instant Access Point)(Auth Server <profile-name>)# nas-ip <NAS-IP-address>
(Instant Access Point)(Auth Server <profile-name>)# timeout <seconds>
(Instant Access Point)(Auth Server <profile-name>)# retry-count <number>
(Instant Access Point)(Auth Server <profile-name>)# deadtime <minutes>
(Instant Access Point)(Auth Server <profile-name>)# drp-ip <IP-address> <mask> vlan <vlan>
gateway <gateway-IP-address>
(Instant Access Point)(Auth Server <profile-name>)# end
(Instant Access Point)# commit apply
Associate the AuthenticationServers with an SSID or Wired Profile
1. Access the WLAN wizard or Wired Settings window.
l To open the WLAN wizard, select an existing SSID in the Network tab, and click edit.
l To open the wired settings window, click More>Wired. In the Wired window, select a profile and click Edit.
You can also associate the authentication servers when creating a new WLAN or wired profile.
2. Click the Security tab.
3. If you are configuring authentication server for a WLAN SSID, under Security tab, slide to Enterprise security
level.
4. Ensure that an authentication type is enabled.
Przeglądanie stron 148
1 2 ... 144 145 146 147 148 149 150 151 152 153 154 ... 334 335

Komentarze do niniejszej Instrukcji

Brak uwag