Chapter 1: Configuration
Configuring a RADIUS server
Page
1-276
Note
Aradial 5.3 has a bug that prevents “remote device login”, so doesn’t support the user
name and password management feature.
Choosing Authentication Mode and Configuring for
Authentication Servers - AP
On the AP’s Configuration > Security tab, select the RADIUS AAA Authentication Mode. The
following describes the other Authentication Mode options for reference, and then the RADIUS AAA
option.
•
Disabled: Requires no authentication. Any SM (except a SM that itself has been configured to
require
RADIUS authentication by enabling Enforce Authentication as described below) is
allowed to register to the AP.
•
Authentication Server: Authentication Server in this instance refers to Wireless Manager in BAM-
only mode. Authentication is required for a SM to register to the AP. Only SMs listed by MAC
address in the Wireless Manager database is allowed to register to the AP.
•
AP Pre-Shared Key: Canopy offers a pre-shared key authentication option. In this case, an
identical key must be entered in the Authentication Key field on the AP’s Configuration > Security
tab and in the Authentication Key field on each desired SM’s Configuration > Security tab.
•
RADIUS AAA: To support RADIUS authentication of SMs, on the AP’s Configuration > Security
tab select RADIUS AAA. Only properly configured SMs with a valid certificate is allowed to
register to the AP.
When RADIUS AAA is selected, up to 3 Authentication Server (RADIUS Server) IP addresses and Shared
Secrets can be configured. The IP address(s) configured here must match the IP address(s) of the
RADIUS server(s). The shared secret(s) configured here must match the shared secret(s) configured in
the RADIUS server(s). Servers 2 and 3 are meant for backup and reliability, not splitting the database. If
Server 1 doesn’t respond, Server 2 is tried, and then server 3. If Server 1 rejects authentication, the SM is
denied entry to the network, and does not progress trying the other servers.
The default IP address is 0.0.0.0. The default Shared Secret is “CanopySharedSecret”. The Shared
Secret can be up to 32 ASCII characters (no diacritical marks or ligatures, for example).
Summary of Contents for PTP 450 Series
Page 51: ...Chapter 1 Configuration Quick link setup Page 1 23...
Page 155: ...Chapter 1 Configuration Configuring security Page 1 127...
Page 163: ...Chapter 1 Configuration Configuring security Page 1 135...
Page 164: ...Chapter 1 Configuration Configuring security Page 1 136...
Page 193: ...Chapter 1 Configuration Configuring radio parameters Page 1 165...
Page 194: ...Chapter 1 Configuration Configuring radio parameters Page 1 166...
Page 195: ...Chapter 1 Configuration Configuring radio parameters Page 1 167...
Page 206: ...Chapter 1 Configuration Configuring radio parameters Page 1 178...
Page 210: ...Chapter 1 Configuration Configuring radio parameters Page 1 182...
Page 636: ...Chapter 5 Troubleshooting Logs Page 5 16 Figure 95 SM Authorization log...