Configuring AAA for network users 543

Nortel WLAN—Security Switch 2300 Series Configuration Guide

Authentication algorithm

WSS Software can try more than one of the authentication types described in “Authentication types” to authenticate a
user. WSS Software tries 802.1X first. If the user’s NIC supports 802.1X but fails authentication, WSS Software denies
access. Otherwise, WSS Software tries MAC authentication next. If MAC authentication is successful, WSS Software
grants access to the user. Otherwise, WSS Software tries the fallthru authentication type specified for the SSID or wired
authentication port. The fallthru authentication type can be one of the following:
•Web
• Last-resort
• None
Web and last-resort are described in “Authentication types” on page 542. None means the user is automatically denied
access. The fallthru authentication type for wireless access is associated with the SSID (through a service profile). The
fallthru authentication type for wired authentication access is specified with the wired authentication port. (For informa-
tion about service profiles, see “Service profiles” on page 280. For information about wired authentication port
configuration, see “Setting a port for a wired authentication user” on page 105.)
Figure 32 shows how WSS Software tries the authentication types for wireless access. (The authentication process is
similar for access through a wired authentication port, except last-resort access requires a last-resort-wired user.)
Note. The fallthru authentication type None is different from the authentication method
none you can specify for administrative access. The fallthru authentication type None
denies access to a network user. In contrast, the authentication method none allows
access to the WSS by an administrator. (See “Configuring Web-based AAA for
administrative and local access” on page 73.)