Enterasys Networks RBT-4102 manual Authentication

Page 51

Authentication

Authentication

Wireless clients can be authenticated for network access by checking their MAC address against the local database configured on the access point, or by using a database configured on a central RADIUS server. Alternatively, authentication can be implemented using the IEEE 802.1X network access control protocol.

Client station MAC authentication occurs prior to the IEEE 802.1X authentication procedure configured for the access point. However, a client’s MAC address provides relatively weak user authentication, since MAC addresses can be easily captured and used by another station to break into the network. Using 802.1X provides more robust user authentication using user names and passwords or digital certificates. So, although you can configure the access point to use MAC address and 802.1X authentication together, it is better to choose one or the other, as appropriate. Use MAC address authentication for a small network with a limited number of users. MAC addresses can be manually configured on the access point itself without the need to set up a RADIUS server. Use IEEE 802.1X authentication for networks with a larger number of users and where security is the most important issue. For 802.1X authentication a RADIUS server is required in the wired network to control the user credentials of the wireless clients.

The access point can also operate in an 802.1X supplicant mode. This enables the access point itself to be authenticated with a RADIUS server using a configured MD5 user name and password. This prevents rogue access points from gaining access to the network.

RoamAbout RBT-4102 Wireless Access Point Configuration Guide 4-15

Image 51
Contents Enterasys RoamAbout Page Page Enterasys Networks, Inc. Firmware License Agreement Iii Page Enterasys Networks, Inc. Software License Agreement Page General Viii Contents Snmp Index Appendix a Default Settings Appendix B TroubleshootingXii Associated Documents Purpose of This ManualIntended Audience Firmware Version SupportConvention Description Getting HelpOverview IntroductionPolicy FeaturesApplications Applications Introduction Network Configuration Network Topologies Ad Hoc Wireless LAN no Access Point or BridgeInfrastructure Wireless LAN Infrastructure Wireless LANInfrastructure Wireless LAN for Roaming Infrastructure Wireless LAN for Roaming Wireless PCsInfrastructure Wireless Bridge Infrastructure Wireless BridgeNetwork Topologies Network Configuration Required Connections Initial Setup Using the CLILogging Enter no ip dhcp to disable Dhcp Using Web Management Initial Setup Using the CLI ```` Initial Setup Using the CLI Initial Setup Using the CLI Initial Setup Using the CLI Initial Setup Using the CLI Using the Command Line Interface CLI Using the Web InterfaceSnmp Identification Using Web Management to Configure System InformationSG Singapore Using the CLI to Configure System InformationEnabled DisabledTCP / IP Settings Using Web Management to Configure TCP/IP TCP / IP Settings TCP/IP Configuration Using the CLI to Configure TCP/IPEthernet Settings Configuration SSH ConfigurationTCP / IP Settings Radius Using Web Management to Configure Radius Radius Attributes Radius Accounting Attribute Description Using the CLI to Configure Radius Authentication Using Web Management to Configure Authentication Using the CLI to Configure Authentication LocalAllowed Filter Control and VLANs Using Web Management to Configure Filter Control and VLANsFilter Control and VLANs CLI Commands for Vlan Support Using the CLI to Configure Filter Control and VLANsFilter Control and VLANs CLI Commands for Filtering SVP Commands Using Web Management to Configure CDP CDP SettingsCDP Settings Using the CLI to Configure CDP Rogue AP Detection Using Web Management to Configure Rogue AP DetectionUsing the CLI to Configure Rogue AP Detection TT5 SsidSnmp Using Web Management to Configure SnmpSnmp Notifications Description Snmp Notifications Security Level Snmp Targets CLI Commands for Snmp Using the CLI to Configure SnmpTPS CLI Commands for Configuring SNMPv3 Users and GroupsSnmp CLI Commands for Configuring SNMPv3 Trap Filters CLI Commands for Configuring SNMPv3 TargetsChanging the Password AdministrationUsing Web Management to Change the Password Enabling and Disabling Com Port Using the CLI to Change the PasswordUsing Web Management to Enable and Disable Com Port Using the CLI to Enable and Disable Com PortUpgrading Firmware Using Web Management to Upgrade Firmware Using the CLI to Upgrade Firmware System Log Using Web Management to Configure System LogLogging Level Descriptions Error Level Using the CLI to Configure System Log Using Web Management to Configure Sntp TAIPEI, Beijing Using the CLI to Configure SntpWDS and STP Using Web Management to Configure WDS and STP WDS and STP WDS and STP Using the CLI to Configure WDS Using the CLI to Configure STP Radio Interface Radio Signal CharacteristicsUsing Web Management to Configure Interface Radio Settings Radio SettingsVlan ID Radius Attributes Number Value Radio Interface Radio Interface Radio Interface Example Dynamic WEPAES-TKIP Not SupportedAdmission Control No Example PRE Shared KEY LongTkip RequiredAC1Background Txop Limit 0.000 ms WMM Operation Wi-Fi Multimedia WMM ConfigurationWMM Backoff Wait times Using Web Management to Configure WMMSsid SW-WDS Using the CLI to Configure WMMAntenna Admission Control No AC2Video Txop Limit Using Web Management to Configure Virtual APs Virtual APs VAPs ConfigurationRadio Interface Using the CLI to Configure Virtual APs WPA-ONLY BIT EncryptionAdmission Control No WEP SecurityUsing Web Management to Configure Security Settings Wired Equivalent Privacy WEPSecurity Page Authentication 802.1x Authentication Security Security Using the CLI to Configure WPA over 802.1X Security Using the CLI to Configure WPA Pre-Shared KeyQuality of Service AC1Background LogCwMin LogCwMax Empty Using the CLI to Configure Local MAC AuthenticationNopassword Allowed Local Nopassword AllowedSecurity Using the CLI to Configure Radius MAC Authentication Remote Using the CLI to Configure WEP Shared Key Security Ssid WPA TKIP-WEPShared Ssid ETS Using the CLI to Configure WEP over 802.1x SecurityAuthentication Parameters AES Using the CLI to Configure WPA2 SecurityWPA2-ONLY Using the CLI to Configure WPA2 Pre-Shared Key Security WPA2-PSK Status Menu Description Status InformationUsing Web Management to View AP Status Status Information SQA Using the CLI to Display AP StatusUsing Web Management to View CDP Status Using the CLI to Display CDP Status Using Web Management to View Station Status Status Information Using Web Management to View Neighbor AP Detection Status DEMOWEP1 Using the CLI to View Neighbor AP Detection StatusIbss Gtac LAB R2Using Web Management to View WDS-STP Status Using the CLI to View WDS-STP Status Show bridgeSTP Child Status Show bridge linkNone Root Bridge StatusUsing Web Management to View Event Logs RoamAbout 4102#show events Using the CLI to View Event LogsOct 101551 Status Information Advanced Configuration Default Settings CDP WDS & STP VAP1 Nopassword Preamble Length Long Wireless Interface 802.11b/g Troubleshooting Steps TroubleshootingTroubleshooting Steps 80 m 264 ft Maximum Distance TablesMaximum Distance Tables Troubleshooting Index Radius MAC WDS 4-50bridge 4-52CLI Index-4
Related manuals
Manual 78 pages 58.85 Kb