520
C
HAPTER
22: C
ONFIGURING
C
OMMUNICATION
WITH
RADIUS
Figure 33
Wireless Client, MAP, WX Switch, and RADIUS Servers
In the example shown in Figure 33, the following events occur:
1
The wireless user (client) requests an IEEE 802.11 association from the
MAP.
2
After the MAP creates the association, the WX switch sends an Extensible
Authentication Protocol (EAP) identity request to the client.
3
The client sends an EAP identity response.
4
From the EAP response, the WX switch gets the client’s username. The
WX switch then searches its AAA configuration, attempting to match the
client's username against the user globs in the AAA configuration.
When a match is found, the methods specified by the matching AAA
command in the WX configuration file indicate how the client is to be
authenticated, either locally on the WX switch, or via a RADIUS server
group.
5
If the client does not support 802.1X, MSS attempts to perform MAC
authentication for the client instead. In this case, if the switch’s
configuration contains a
set authentication mac
command that
matches the client’s MAC address, MSS uses the method specified by the
command. Otherwise, MSS uses local MAC authentication by default.
(For information about MAC client authentication, see “Configuring
MAC Authentication and Authorization” on page 457.)
WX switch
with local
database
Wireless
connection
Wired
connection(s)
RADIUS Server 1
RADIUS Server 2
1
3
2
4
Client (with laptop)
Client (with laptop)
Client (with PDA)
MAP
MAP
Содержание 3CRWX120695A
Страница 138: ...138 CHAPTER 6 CONFIGURING AND MANAGING IP INTERFACES AND SERVICES ...
Страница 272: ...272 CHAPTER 11 CONFIGURING RF LOAD BALANCING FOR MAPS ...
Страница 310: ...310 CHAPTER 13 CONFIGURING USER ENCRYPTION ...
Страница 322: ...322 CHAPTER 14 CONFIGURING RF AUTO TUNING ...
Страница 350: ...350 CHAPTER 16 CONFIGURING QUALITY OF SERVICE ...
Страница 368: ...368 CHAPTER 17 CONFIGURING AND MANAGING SPANNING TREE PROTOCOL ...
Страница 412: ...412 CHAPTER 19 CONFIGURING AND MANAGING SECURITY ACLS ...
Страница 518: ...518 CHAPTER 21 CONFIGURING AAA FOR NETWORK USERS ...
Страница 530: ...530 CHAPTER 22 CONFIGURING COMMUNICATION WITH RADIUS ...
Страница 542: ...542 CHAPTER 23 MANAGING 802 1X ON THE WX SWITCH ...
Страница 598: ...598 CHAPTER 26 ROGUE DETECTION AND COUNTERMEASURES ...
Страница 706: ...706 GLOSSARY ...