Release 11.0 Release Notes and User Guide Supplement
Issue 1, Marc h 2011 Page 15
When RADIUS AAA is selected , up to 3 Authentication Server (RADIU S Server) IP addr esses
and Shared Secrets can be configu red. The IP addr ess(es) configur ed here must m atch the IP
address(es) of the RADIUS server(s). The shared secret(s) configured here must match the
shared secret(s) configured in the RADIUS server(s). Servers 2 and 3 are meant for backup and
reliability, not splitting the database. If Server 1 doesn’t respond, Server 2 is tried, and then server
3. If Server 1 rejects authentication, the SM is denied entry to the network, and does not progress
trying the oth er servers.
The default IP address is 0 .0.0.0 (which obviously won’t ma tch any RADIUS server). The defau lt
Shared Secret is “CanopyShare dSecret”. The Sh ared Secret can be up to 32 ASC II characters
(no diacritical marks or ligatures, for example).
Figure 2: AP's Configuration > Security tab
5.2.2 SM Auth entication Mode Require RADIU S or Follow AP
Refer to Figure 3: SM's Configuration > Security tab to see the GUI options.
If it is desired that an SM wi ll only authenticate to an A P that is using RADIUS, on th e SM’s
Configuration Security tab set Lock AAA to Enabled. With Lock AAA enabled, an SM will not
register to an AP that has any Authentication Mode other than RADIUS AAA selected.
If it is desired that an SM use the authentication method configured on the AP it is registering to,
set Lock AAA to Disabled. With Lock AAA disabled, an SM will attempt to register using
whichever Authentication Mode is configured on th e AP it is attem pting to registe r to.
Note, requiring SMs to use RADIUS by enabling Lock AAA avoids the security issue of SMs
possibly registering to “rogue” APs which have authentication disabled.