3Com WX2200 manual To configure the Radius server, 3Com VSAs

Models: WX2200

1 204
Download 204 pages 42.7 Kb
Page 60
Image 60

60CHAPTER 3: CONFIGURING WIRELESS SERVICES

Configure Attributes on the RADIUS Server To authenticate users, you will need to configure users either in the local database or on RADIUS servers. To configure services for Employee access, the following items should be configured on the RADIUS server.

To configure the RADIUS server

1Configure RADIUS server to perform 802.1X using the recommended EAP method PEAP + MSCHAPV2.

2Setup each WX switch as a RADIUS client.

3Define any desired 3Com vendor-specific attributes (VSAs) in the RADIUS server’s dictionary.

The vendor-specific attributes (VSAs) created by 3Com are embedded according to the procedure recommended in RFC 2865, with Vendor-ID set to 14525. Table 10 describes the 3Com VSAs, listed in order by vendor type number.

Table 10 3Com VSAs

 

 

Rcv in

Sent in

Sent in

 

 

 

Access

Access

Acct

 

Attribute

Type

Resp?

Reqst?

Reqst?

Description

 

 

 

 

 

 

VLAN-Name

26, 43, 2

Yes

No

Yes

Name of the VLAN to

 

 

 

 

 

which the client belongs.

 

 

 

 

 

 

Mobility-

26, 43, 3

Yes

No

No

Name of the Mobility

Profile

 

 

 

 

Profile used by the

 

 

 

 

 

authorized client.

 

 

 

 

 

 

Encryption-

26, 43, 4

Yes

No

No

Type of encryption used

Type

 

 

 

 

to authenticate the client.

 

 

 

 

 

 

Time-Of-Day

26, 43, 5

Yes

No

No

Day(s) and time(s) during

 

 

 

 

 

which a user can log into

 

 

 

 

 

the network.

 

 

 

 

 

 

SSID

26, 43, 6

Yes

No

Yes

Name of the SSID you

 

 

 

 

 

want the user to use. The

SSID must be configured in a service profile, and the service profile must be used by a radio profile assigned to 3Com radios in the Mobility Domain.

Page 60
Image 60
3Com WX2200 manual To configure the Radius server, 3Com VSAs