Configuring AAA for Network Users 465

set authentication console * none

set authentication mac ssid mycorp * local

set authentication dot1x ssid mycorp Geetha eap-tls

set authentication dot1x ssid mycorp * peap-mschapv2 sg1 sg2 sg3 set accounting dot1x Nin ssid mycorp stop-only sg2

set accounting admin Natasha start-stop local

set authentication last-resort ssid guestssid local

user Nin

Password = 082c6c64060b (encrypted)

Filter-Id = acl-999.in

Filter-Id = acl-999.out

user last-resort-guestssid

Vlan-Name = k2

mac-user 01:02:03:04:05:06 usergroup eastcoasters

session-timeout = 99

For information about the fields in the output, see the Nortel Mobility System Software Command Reference.

Avoiding AAA Problems in Configuration Order

Using the Wildcard “Any” as the SSID Name in Authentication Rules

You can configure an authentication rule to match on all SSID strings by using the SSID string any in the rule. For example, the following rule matches on all SSID strings requested by all users:

set authentication web ssid any ** sg1

WSS Software checks authentication rules in the order they appear in the configuration file. As a result, if a rule with SSID any appears in the configuration before a rule that matches on a specific SSID for the same authentication type and userwildcard, the rule with any always matches first.

To ensure the authentication behavior that you expect, place the most specific rules first and place rules with SSID any last. For example, to ensure that users who request SSID corpa are authenticated using RADIUS server group corpasrvr, place the following rule in the configuration before the rule with SSID any:

set authentication web ssid corpa ** corpasrvr

Here is an example of a AAA configuration where the most-specific rules for 802.1Xare first and the rules with any are last:

23x0# show aaa

...

Nortel WLAN Security Switch 2300 Series Configuration Guide

Page 465
Image 465
Nortel Networks 2300 Avoiding AAA Problems in Configuration Order, Vlan-Name = k2, Set authentication web ssid any ** sg1