![Ruckus Wireless ZoneDirector 1200 User Manual Download Page 206](http://html1.mh-extra.com/html/ruckus-wireless/zonedirector-1200/zonedirector-1200_user-manual_1498797206.webp)
leverages the EAP authentication and RADIUS protocols to allow the network policy to
be effectively applied in real time, no matter where the user connects to the network.
AP Ethernet ports can be individually configured to serve as either an 802.1X supplicant
(authenticating the AP to an upstream authenticator switch port), or as an 802.1X
authenticator (receiving 802.1X authentication requests from downstream supplicants).
A single port cannot provide both supplicant and authenticator functionality at the same
time.
NOTE
If mesh mode is enabled on ZoneDirector, the 802.1X port settings will be
unavailable for any APs that support mesh.
AP Ethernet Port as Authenticator
The Access Point is similar in many ways to a wireless switch. On APs with two or more
wired ports, the AP acts as a network edge switch and can be configured to authenticate
downstream wired stations (which could include multiple clients connected to another
edge switch).
When the AP Ethernet port is configured as an 802.1X authenticator, it can be further
defined as either Port-based or MAC-based. MAC-based authenticator mode is only
supported if the port is an Access Port.
Table 28: Authenticator support vs. Port Type
General Port
Access Port
Trunk Port
X
X
X
Port-based mode
X
MAC-based mode
To configure an AP Ethernet port as an 802.1X authenticator:
1.
Go to
Configure
>
Access Points
and click the
Edit
link next to the AP whose ports
you want to configure.
2.
Locate the
Port Setting
section and select
Override Group Config
. The screen
changes to display the AP's Ethernet ports.
3.
For
Type
, select
Access Port
.
4.
For
802.1X
, select
Authenticator (MAC-based)
or
Authenticator (Port-based)
.
• In Port-based mode, only a single MAC host must be authenticated for all hosts
to be granted access to the network.
• In MAC-based mode, each MAC host is individually authenticated. Each
newly-learned MAC address triggers an EAPOL request-identify frame.
• Guest VLAN: (Default disabled). When a station fails to authenticate to this
port, it will be assigned to this “guest” VLAN, with access to Internet but not
to internal resources.
Ruckus Wireless ZoneDirector™ Release 10.0 User Guide
206
Managing Access Points
Configuring AP Ethernet Ports