
Manage Security Profiles and Profile Groups
137
ProSAFE Wireless Controller WC9500
See the following configuration guidelines for external RADIUS servers:
- You need to add only the IP address of the wireless controller as a RADIUS client to
the RADIUS server
. All managed access points are then automatically known to the
RADIUS server.
- For configuration guidelines for external MAC authentication, see Guidelines for
External MAC Authentication on page 143.
- For configuration guidelines for external authentication of captive portal users, see
Manage Guest Network Access on page 217.
• External LDAP server. Y
ou can define one external LDAP server (commonly referred to
as an Active Directory [AD] server). You must specify its configuration on the basic
Authentication Server screen (see Configure Basic Authentication Server Settings on
page 137) so that you can select this authentication option during the configuration of a
profile.
By default, the external LDAP server for the basic authentication group is called
basic-LDAP.
Y
ou cannot change this name, and you cannot configure any LDAP servers
for the advanced authentication groups. You can assign the basic-LDAP server to both
the basic profile group and to advanced profile groups.
All three servers can be active so that the profiles that you set up can be configured to work
with different authentication servers. For example, you could set up a guest profile with no
authentication, an engineering profile that uses external RADIUS authentication, and a
marketing profile that uses external LDAP authentication.
Note: For authentication, you can configure and use a single LDAP server
only. However, you can configure and use several RADIUS servers.
The settings that you specify on the Authentication Server screen affect the selections that
are available in the Network Authentication menu and the corresponding Authentication
Server field on the Edit Profile screens. For information about how to configure security
profiles, see Configure a Profile in the Basic Profile Group on page 119 and Configure a
Profile in an Advanced Profile Group on page 126.
Configure Basic Authentication Server Settings
Use the basic Authentication Server screen to set up the internal authentication server, the
basic external RADIUS server (which is called Auth-basic), and the external LDAP server
(which is called Auth-LDAP). After you set up these authentication servers, you can assign
any of them to any profile, whether in the basic profile group or in an advanced profile group.
To configure a basic authentication server:
1. Open a web browser. In the browser
’s address field, type the wireless controller’s IP
address.
By default, the IP address is 192.168.0.250.
Comentarios a estos manuales