Configuring AAA for network users 573
Nortel WLAN—Security Switch 2300 Series Configuration Guide
Network requirements
The VLAN where users will be placed must have an IP interface, and the subnet the interface is in must have access to
DHCP and DNS servers.
WSS recommendations
Consider installing a Web-based AAA certificate signed by a trusted CA, instead of one signed by the WSS itself.
Unless the client’s browser is configured to trust the signature on the switch’s Web-based AAA certificate, display
of the login page can take several seconds longer than usual, and might be interrupted by a dialog asking the user
what to do about the untrusted certificate. Generally, the browser is already configured to trust certificates signed by
a CA.
Client NIC recommendations
Configure the NIC to use DHCP to obtain its IP address.
Client Web browser recommendations
Use a well-known browser, such as Internet Explorer (Windows), Firefox (Mozilla-based), or Safari (Macintosh).
If the Web-based AAA certificate on the WSS is self-signed, configure the browser to trust the signature by
installing the certificate on the browser, so that the browser does not display a dialog about the certificate each time
the user tries to log on.