Configuring User Authentication
77
MSS checks the RADIUS server group or local database for matching
user information. If the MAC address (and password, if on a RADIUS
server) matches, MSS grants access. Otherwise, MSS attempts the
fallthru authentication type, which can be Web, last-resort, or none.
■
Web—A network user attempts to access a web page over the
network. The WX switch intercepts the HTTP or HTTPS request and
serves a login Web page to the user. The user enters the username
and password, and MSS checks the RADIUS server group or local
database for matching user information. If the username and
password match, MSS redirects the user to the web page she
requested. Otherwise, MSS denies access to the user.
■
Last-resort—A network user requests access to the network, without
entering a username or password. MSS checks for a last-resort
authentication rule for the requested SSID (or for
wired
, if the user is
on a wired authentication port). If a matching rule is found, MSS
checks the RADIUS server group or local database for username
last-resort-wired
(for wired authentication access) or
last-resort-
ssid
, where
ssid
is the SSID requested by the user. If the
user information is on a RADIUS server, MSS also checks for a
password.
Users cannot access the network unless they are authorized. You can
configure a WX switch to authenticate users with user information on a
group of RADIUS servers or in a local user database on the switch. You
also can configure a switch to offload some authentication tasks from the
server group.
■
Pass-through—The switch establishes an Extensible Authentication
Protocol (EAP) session directly between the client and RADIUS server.
All authentication information and certificate exchanges pass through
the switch. In this case, the switch does not need a certificate.
■
Local—The switch performs all authentication with information in a
local user database configured on the switch. No RADIUS servers are
required. In this case, the switch needs a certificate. If you plan to use
EAP with Transport Layer Security (EAP-TLS), the clients also need
certificates.
■
Offload—The switch offloads all EAP processing from a RADIUS server
by establishing a TLS session between the switch and the client. In this
case, the switch needs a certificate. If you plan to use the EAP-TLS
authentication protocol, the clients also need certificates.
Summary of Contents for 3CRWX120695A
Page 6: ......
Page 10: ...10 ABOUT THIS GUIDE...
Page 18: ...18 CHAPTER 1 WX SWITCH OVERVIEW...
Page 86: ...86 CHAPTER 3 CONFIGURING A WX SWITCH FOR BASIC SERVICE...
Page 90: ...90 APPENDIX A WX TECHNICAL SPECIFICATIONS...
Page 94: ...94 APPENDIX B WX TROUBLESHOOTING...
Page 108: ...108 INDEX troubleshooting 91 WX1200 11 WX4400 11...