
724-746-5500 | blackbox.com
Page 170
724-746-5500 | blackbox.com
Chapter 11: Deployment Examples CLI
The setup of cluster1 is complete. Wireless clients can now associate with the SmartPath APs using SSID “employee” and access
the network. The SmartPath APs communicate with each other to share client associations (to support fast roaming) and routing
data (to select optimal data paths).
11.3 Example 3: Using IEEE 802.1x Authentication
In this example, you use a Microsoft AD (Active Directory) server and a RADIUS server to authenticate wireless network users. To
accomplish this, you make the following modifications to the cluster set up in ”Deploying a Cluster:”
• Configure settings for the RADIUS server on the SmartPath APs
• Change the SSID parameters on the SmartPath APs and wireless clients to use IEEE 802.1X.
The basic network design is shown in Figure 11-7.
Wired Cluster Backhaul Communications
Wireless Cluster Backhaul Communications
Wireless Network Access Connections
WIred Ethernet Network Connections
Wireless Network-1
Wireless Network-2
DHCP server
SmartPath AP-1
SmartPath AP-3
SmartPath AP-2
Wireless Network-3
Active Directory
Server
Switch
Firewall
Internet
RADIUS Server
10.1.1.10
The SmartPath APs receive Protected (PEAP)
authentication requests from clients and forward
them inside RADIUS authentication packets to the
RADIUS server at 10.1.1.10. The RADIUS server is in
turn linked to the database of the Active Directory
server on which all the user accounts have previously
been created and stored.
Figure 11-7. Cluster and 802.1X authentication.
NOTE: This example assumes that the RADIUS and AD servers were previously configured and populated with user accounts that
have been in use on a wired network (not shown). The only additional configuration on these servers is to enable the
RADIUS server to accept authentication requests from the SmartPath APs.
Step 1: Define the RADIUS server on the SmartPath AP-1.
Configure the settings for the RADIUS server (IP address and shared secret) on SmartPath AP-1.
aaa radius-server first 10.1.1.10 shared-secret s3cr3741n4bl0X