
Configuring Network Access and Security
118
ProSafe 20-AP Wireless Controller WC7520
Guidelines for External MAC Authentication
To use an external ACL:
1. Config
ure an ACL on an external RADIUS server.
2. On an Edit
Profile screen (see Chapter 6, Managing Security Profiles and Profile Groups),
next to MAC ACL, select the External ra
dio button.
3. From
the External Radius Server drop-down list, select an external authentication server.
The wireless controller consults the MAC ACL at init
ial client authentication. While a client
roams, the wireless controller uses cached authentication information. After a client has
disassociated from the access point and then attempts to reassociate again, the wireless
controller once again consults the MAC ACL.
Note the following external RADIUS server guidelines:
• Fo
r each MAC authentication client, you need to configure a policy on the RADIUS
server.
• During MAC auth
entication, the wireless controller sends the following information to the
RADIUS server:
- MAC add
ress in the format xx:xx:xx:xx:xx:xx
- use
r name
- callin
g station ID
• Th
e wireless controller uses CHAP as the authentication protocol with the RADIUS
server.
• Y
ou can configure either MAC authentication with an external RADIUS server or network
authentication with an external RADIUS server (see Network Authentication and Data
Encryption Options on p
age 81), but not both. That is, if you configure an external
RADIUS server with WPA, WPA2, or WPA & WPA2, you cannot use external MAC
authe
ntication but are limited to internal MAC authentication.
Configure Basic Local MAC Authentication Settings
You would typically use the basic MAC authentication group in the profiles of a basic profile
group of a small-scale network. However, you can assign the basic MAC authentication
group to any profile, whether in the basic profile group or in an advanced profile group.
To set up basic MAC authentication:
1. Select Configuration
> Security > Basic > MAC ACL. The basic MAC Authentication
screen displays:
Comentarios a estos manuales