21
C
ONFIGURING
AAA
FOR
N
ETWORK
U
SERS
The following sections describe the MSS authentication, authorization,
and accounting (AAA) features in detail.
About AAA for
Network Users
Network users include the following types of users:
Wireless users
— Users who access the network by associating with
an SSID on a 3Com radio.
Wired authentication users
— Users who access the network over
an Ethernet connection to a WX switch port that is configured as a
wired authentication (
wired-auth
) port.
You can configure authentication rules for each type of user, on an
individual SSID or wired authentication port basis. MSS authenticates
users based on user information on RADIUS servers or in the WX switch’s
local database. The RADIUS servers or local database authorize
successfully authenticated users for specific network access, including
VLAN membership. Optionally, you also can configure accounting rules to
track network access information.
Authentication
When a user attempts to access the network, MSS checks for an
authentication rule that matches the following parameters:
For wireless access, the authentication rule must match the SSID the
user is requesting, and the user’s username or MAC address.
For access on a wired authentication port, the authentication rule
must match the user’s username or MAC address.
If a matching rule is found, MSS then checks RADIUS servers or the WX
local user database for credentials that match those presented by the
user. Depending on the type of authentication rule that matches the SSID
or wired authentication port, the required credentials are the username
or MAC address, and in some cases, a password.
Summary of Contents for 3CRWX120695A
Page 138: ...138 CHAPTER 6 CONFIGURING AND MANAGING IP INTERFACES AND SERVICES ...
Page 272: ...272 CHAPTER 11 CONFIGURING RF LOAD BALANCING FOR MAPS ...
Page 310: ...310 CHAPTER 13 CONFIGURING USER ENCRYPTION ...
Page 322: ...322 CHAPTER 14 CONFIGURING RF AUTO TUNING ...
Page 350: ...350 CHAPTER 16 CONFIGURING QUALITY OF SERVICE ...
Page 368: ...368 CHAPTER 17 CONFIGURING AND MANAGING SPANNING TREE PROTOCOL ...
Page 412: ...412 CHAPTER 19 CONFIGURING AND MANAGING SECURITY ACLS ...
Page 518: ...518 CHAPTER 21 CONFIGURING AAA FOR NETWORK USERS ...
Page 530: ...530 CHAPTER 22 CONFIGURING COMMUNICATION WITH RADIUS ...
Page 542: ...542 CHAPTER 23 MANAGING 802 1X ON THE WX SWITCH ...
Page 598: ...598 CHAPTER 26 ROGUE DETECTION AND COUNTERMEASURES ...
Page 706: ...706 GLOSSARY ...