Configuring a Network to Use WPA2-Enterprise and Dynamic
VLANs
D-Link
Unified Wired and Wireless Access System
July 2012
Page 707
D-Link UWS User Manual
Configuring Client Information on the RADIUS Server
To use WPA-Enterprise and RADIUS-assigned VLANs, you must configure information about the clients on the
network RADIUS server. The configuration of your RADIUS server will vary depending on the manufacturer of
the RADIUS server, but the parameters for dynamic VLAN tagging are the same, regardless of the RADIUS
server you use.
The following parameters should be set to allow for Dynamic VLAN Tagging where <vlan-ID> is the VLAN to
assign to each user.
• Tunnel-Type = 13,
• Tunnel-Medium-Type = 6,
• Tunnel-Private-Group-ID = <vlan-ID>
This example describes how to configure the FreeRADIUS server (available from FreeRADIUS.org) with the
users in
To configure the FreeRADIUS server:
1.
Edit the etc/raddb/users.conf file, which contains the user account information, and add the new users.
The following code shows an example of the entry for the
accountant
and
engineer
users:
accountant User-Password == "accountant"
Tunnel-Type = 13,
Tunnel-Medium-Type = 6,
Tunnel-Private-Group-ID = 30
engineer User-Password == "engineer"
2.
Edit the etc/raddb/clients.conf file to allow the switch to act as a client for the RADIUS server.
The following code shows an example of the entry in the clients file that allows the switch to authenticate
with the RADIUS server:
client 10.27.65.0/24 {
secret
= secret12345
shortname
= private-network-1
}
The client network in the entry includes the IP address of the switch. The secret matches the secret to be
configured on the switch. The secret must match on both systems
Table 389: Wireless LAN Users
Username
Password
Group
VLAN
accountant
accountant
Accounting
VLAN 30
engineer
engineer
Corporate
None assigned
Summary of Contents for DWL-8600AP
Page 754: ......