418Configuring AAA for Network Users

Configuring 802.1X Acceleration

You can configure the WSS switch to offload all EAP processing from server groups. In this case, the RADIUS server is not required to communicate using the EAP protocols.

For PEAP-MS-CHAP-V2 offload, you define a complete user profile in the local WSS database and only a username and password on a RADIUS server. For EAP-TLS offload, you define a complete user profile in the local database only.

For example, the following command authenticates all wireless users who request SSID marshes at example.com by offloading PEAP processing onto the WSS switch, while still performing MS-CHAP-V2 authentication through the server group shorebirds:

23x0# set authentication dot1x ssid marshes *@example.com peap-mschapv2 shorebirds

To offload both PEAP and MS-CHAP-V2 processing onto the WSS switch, use the following command:

23x0# set authentication dot1x ssid marshes *@example.com peap-mschapv2 local

320657-A

Page 418
Image 418
Nortel Networks 2300 manual Configuring 802.1X Acceleration