Software User Manual
D-Link Unified Access System
02/15/2011
Document 34CS3000-SWUM104-D10
Page 207
Appendix B: Configuring the External RADIUS
Server
You can store the Valid AP configuration on a local database on the D-Link Unified Switch or on an external RADIUS server.
This appendix describes the attributes you must define for each feature to setup their configuration on the RADIUS server.
One important reason why you might define the AP information on the RADIUS server rather than on the switch is to allow
peer switches to obtain the data from a single source rather than having to define it on each switch.
C
ONFIGURING
RADIUS S
ETTINGS
FOR
A
CCESS
P
OINTS
Since the AP is identified by its physical MAC address, you must add a RADIUS entry for each AP with the User-Name
attribute set to the MAC address. <Link>Table 89 indicates the attributes to configure in the RADIUS server entry for each
AP. Add the vendor-specific attributes by using the D-Link vendor ID (6132) and the identifier D-Link-Wireless-AP-* (where
“*” represents the attribute name).
Note:
This appendix does not describe RADIUS configuration for AP network authentication using 802.1X. This
feature is separate from a valid AP configuration entry. The edge device that connects to the AP performs the
network authentication. The edge device might not be the Unified Switch.
Table 89: RADIUS Attributes for the Access Point
RADIUS Server Attribute Description
Range
Usage
User-Name (1)
Ethernet Address of the AP.
Valid Ethernet MAC Address
Required
User-Password (2)
A fixed password used to lookup an
AP entry.
8-63 characters, default
NOPASSWORD
Required
Vendor-Specific (26)
Location
A description for the AP, often based
on its location.
1-32 characters
Optional
Vendor-Specific (26)
Mode
Indicates whether this AP is
managed by the switch, by an
administrator, or is a rogue AP.
WS Managed (1)
Standalone (2)
Acknowledged Rogue (3)
Required
Vendor-Specific (26)
Profile-ID
If AP is managed by a switch, the ID
of the configuration profile for this
AP.
1-16
Required if mode is
WS managed.
Vendor-Specific (26)
Switch-IP
If there is more than one WS using
this RADIUS server, indicates the IP
address of the WS to managed this
AP.
Valid IP Address
Optional
Vendor-Specific (26)
Radio-1-Chan
Vendor-Specific (26)
Radio-2-Chan
Indicates a fixed channel for the
radio.
Valid channels depend on the
regulatory domain (country-
code) and the configured
mode for that radio in the
assigned AP profile. If the
channel is not valid, its
ignored.
0 indicates automatic channel
assignment.
Optional, if defined
and valid will
override auto
channel
configuration