SMC Networks SMCWHSG44-G manual Robustness

Page 75

For the SMCWHSG44-G, the RADIUS client component of the Router is shared by the IEEE 802.1x and Web redirection components. The RADIUS settings are for the RADIUS client to communicate with backend RADIUS servers.

NOTE: When configured for EAP authentication, the RADIUS server supports either EAP-TLS or EAP-MD5, but not both at the same time. As a result, not all combinations of EAP-MD5, EAP-TLS, PAP and CHAP authentication meth- ods are available if both IEEE 802.1x and Web redirection are enabled. The following table shows the allowable IEEE 802.1x and Web redirection authen- tication modes on the Wireless Advanced edition of access Router.

Table 2. Allowable Authentication Modes.

The SMCWHSG44-G can be configured to communicate with two RADIUS servers. When the primary RADIUS server fails to respond, the SMCWHSG44-G will try to communicate with the secondary RADIUS server. You can specify the length of timeout and the number of retries before communicating with the secondary RADIUS server after failing to communicate with the primary RA-DIUS server.

The SMCWHSG44-G and its RADIUS server(s) share a secret key so that they can authenticate each other. In addition to its IP address, the SMCWHSG44-G can identify itself by an NAS (Network Access Server) iden- tifier. Each SMCWHSG44-G must have a unique NAS identifier.

2.6.2.2. Robustness

Fig. 91. RADIUS Robustness Settings.

The Router can be configured to notify the RADIUS server after it reboots. The RADIUS server can make use of the notification to clean up user authentication session records in the event that the Router reboots unexpectedly due to abnormal operation.

Select the Notify RADIUS server after reboot check box to enable this capability, and then specify the name of the pseudo user (default to “reboot”) for this operation in the Reboot user name text box.

74

Image 75
Contents SMCWHSG44-G Page Trademarks CopyrightLimited Warranty Page Federal Communication Commission Interference Statement FCC Radiation Exposure StatementIndustry Canada Class B EC Conformance Declaration Power Cord Safety Safety ComplianceSchuko Page Wichtige Sicherheitshinweise Germany Schuko Page Table of Contents System Page SMCWHSG44-G SMCWHS-POS Introduction Overview Features User Authentication, Authorization, and Accounting AAAIeee 802.11b/g Compliant Wireless Operation Internet Connection Sharing Network Security Firmware Tools Package Checklist LED DefinitionRear Panel POE enabled LAN Port Position Selecting a Power Supply MethodMounting the SMCWHSG44-G on a Wall Changing the TCP/IP Settings of the Managing Computer Preparing for ConfigurationEntering the Password Configuring the SMCWHSG44-GHome Setup Wizard Selecting an Operational ModePage Router with a Static-IP DSL/Cable Connection Router with a DHCP-Based DSL/Cable ConnectionRouter with Multiple DSL/Cable Connections Setup Wizard Configuring Ieee 802.11 Settings Setup Wizard Configuring Dhcp Server SettingsWeb Redirection Configuring User Authentication SettingsAuthentication protocol Local Authentication SeverPage Account Table List How to Setup the Mini-POS Ticket PrinterIeee Radius Settings Allowable Authentication Modes Configuring Radius SettingsDeploying the SMCWHSG44-G Setting up Client ComputersConfiguring Ieee 802.11-Related Settings To establish a wireless link to an APConfiguring TCP/IP-Related Settings Page Authentication Success Overview Menu StructureLogout Page Save, Save & Restart, and Cancel Commands Home and Refresh CommandsStatus Associated Wireless Clients Account Table Authenticated UsersManaged LAN Devices Session ListSystem Specifying Operational ModeManaging Firmware Changing PasswordBacking up and Restoring Configuration Settings by Http To upgrade firmware of the SMCWHSG44-G by HttpUpgrading Firmware by Http Upgrading Firmware by Tftp To upgrade firmware of the SMCWHSG44-G by TftpTo back up configuration of the SMCWHSG44-G by Tftp Backing up and Restoring Configuration Settings by TftpTo restore configuration of the SMCWHSG44-G by Tftp Resetting Configuration to Factory Defaults Configuring TCP/IP Related Settings AddressTime Zone Router with a DHCP-Based DSL/Cable Connection Router with a Static-IP DSL/Cable Connection DNS DNS Proxy NAT Basic Host Address ResolutionTo expose preset internal servers Virtual Server MappingsDhcp Server Ii. Static Dhcp Mappings Dhcp Server BasicDhcp Relay Load BalancingTo always assign an IP address to a specific Dhcp client Configuring Ieee 802.11-Related Settings Wireless Basic Zero Client ReconfigurationWireless Distribution System To enable a WDS link Wireless Distribution System SettingsNetwork Topology Containing a Loop SecurityPage MAC-Address-Based Access Control Settings MAC-Address-Based Access ControlTo deny wireless clients access to the wireless network To grant wireless clients access to the wireless networkIeee 802.1x/RADIUS Ieee 802.1x/RADIUS Settings Configuring Authentication Settings AAA Basic Default Authentication Failure Warning To specify an uncontrolled computer by MAC address Unrestricted ClientsRadius Basic Walled GardenRobustness Log-On Page Customization Settings Authentication Session ControlAuthentication Success Page Customization Settings Ddns Advertisement Links SettingsIcmp TCP UDP Vlan FirewallTo set a rule for packet filtering URL Filters Management BasicTo block Http traffic to an unwelcome Web site System Log UPnPSnmp Access RulesLAN Device Management Unrestricted Host MAC Address SettingsTo specify a LAN device to manage Example for LAN Device ManagementAppendix a Default SettingsLED Definitions TCP/IP Setting Problems Page Other Problems Wireless Settings ProblemsAppendix C Distances and Data Rates Standards Network ConfigurationTransmission output Power Configuration and ManagementKeypad Ad Hoc Access PointAuthentication Basic Service Set BSSEncryption Dynamic Host Configuration Protocol DhcpExtended Service Set ESS Extensible Authentication Protocol EAPLocal Area Network LAN Inter Access Point Protocol IappPower over Ethernet PoE InfrastructureSession Key Service Set Identifier SsidWireless Distribution System WDS Wi-Fi Protected AccessWPA Pre-shared Key PSK Wired Equivalent Privacy WEPPage For Technical SUPPORT, Call