3Com 3CRWXR10095A, 3CRWX120695A WXR100 manual Viewing and Configuring WebAAA Network Access Rules

Models: 3CRWXR10095A WX4400 3CRWX440095A WX1200 3CRWX120695A WXR100

1 516
Download 516 pages 50.11 Kb
Page 315
Image 315

Viewing and Configuring WebAAA Network Access Rules 315

For EAP with Transport Layer Security (EAP-TLS) clients, the format is username@domain_name. For example, sydney@example.com specifies the user sydney in the domain name example.com. The *@marketing.example.com glob specifies all users in the marketing department at example.com. The user glob sydney@engineering.example.com specifies the user sydney in the engineering department at example.com.

4Click Next.

5If the authentication rule is disabled, select Enabled.

When a rule is disabled, 3WXM does not add it to the switch’s configuration.

6Select the authentication method(s) in the Available RADIUS Server Groups list and click Add.

An authentication method specifies where the switch will look for user information to authenticate users. You can select a RADIUS server group, LOCAL (the switch’s local user database), or both.

MSS tries the methods in the order they appear in the Current RADIUS Server Groups list. To reorder the methods, select a method and click Up or Down.

„If you specify a RADIUS server group as the first method and a user is denied access by the RADIUS server, no authentication and authorization are attempted with the other methods specified in the list.

„If you specify LOCAL as the first method and a user is not in the local user database on the WX, authentication and authorization are attempted with a RADIUS server group if one is defined in the method list.

The authentication methods you select are also used for authorization.

7Click Next.

8To enable this accounting rule for the SSID, select Enabled.

By default, accounting rules you configure in 3WXM are disabled, which means 3WXM does not add the rules to the switch’s configuration.

9Select one of the following record options:

„Select Start-Stopto specify that records are sent at the start of a session and the end of a session.

„Select Stop-Onlyto specify that records are sent only at the end of a session.

Page 315
Image 315
3Com 3CRWXR10095A, 3CRWX120695A WXR100, WX4400 3CRWX440095A WX1200 manual Viewing and Configuring WebAAA Network Access Rules