DellPowerConnect W- Series ArubaOS 6.2 | User Guide AuthenticationServers |168
Chapte r 12

Authentic ation Servers

The ArubaOSsoftware allows you to use an external authentication server or the controllerinternal user database to
authenticate clients who need to access the wireless network.
This chapter describes the following topics:
l"UnderstandingAuthentication Server Best P ractices and Exceptions" on page 168
l"UnderstandingServers and Server Groups"on page 16 8
l"ConfiguringServers" on page 169
l"Managingthe Internal Database" on page 17 5
l"ConfiguringServer Groups" on page 177
l"Assigning ServerGroups" on page 184
l"ConfiguringAuthentication Timers" on page 187

Understanding Authentication ServerBest Practices and Exceptions

lIn order for an externalauthentication server to process requests from the Dell controller, you must configure the
serverto recognize the controller.Refer to the vendor documentation for information on configuring the
authentication server.
lInstructions on how to configure Microsoft’s IAS and Act ive Directory can be viewed at:
Microsoft’s IAS
http://technet2.microsoft.com/windowsser ver/en/technologies/ias.mspx
Active Directory
http://www.microsoft.com/en-us/ser ver-cloud/windows-server/active-directory.aspx

Understanding S ervers and Server Groups

ArubaOSsupports the following external authentication servers:
lRADIUS (Remote Authenticati on Dial-In User Service)
l(Lightweight Directory Access Protocol)
lTACACS+ (TerminalA ccess controllerAccess Control System)
lWindows (For stateful NTLM authentication)
Additionally, you can use thec ontroller’sinternal database to authenticate users. You create entries in the database
for usersand their passwords and default role.
You can create
groups
of serversfor speci fic types of authentication. For example, you can specify one or more
RADIUS servers to be used for8 02.1x authentication. Thelist o fservers in a server group is an orderedlist. This
means that the first serverin the list i s always usedunless it is unavailable,in which case the next server in the list is
used.You can co nfigureservers of different types in one group — for example, you can include the internaldatabase
as a backupt o a RADIUS server.