Deployment Guide
149
E
XAMPLE
1: M
APPING
L
OCATIONS
AND
I
NSTALLING
H
IVE
AP
S
Defining an SSID with 802.1X/EAP Authentication
Define an SSID that supports 802.1X/EAP authentication and directs the HiveAP RADIUS authenticators to forward
authentication requests from RADIUS supplicants to the RADIUS authentication server that you just defined.
Click Configuration > SSIDs > New, enter the following, leave all other values at their default settings, and then
click Save:
Profile Name: corp-wifi
SSID: corp-wifi
Description: Employee and IT WLAN access; 802.1X
SSID Access Security: WPA/WPA2 802.1X (Enterprise)
Use Default 802.1X Settings: (select)
By default, when a HiveAP hosts a WPA/WPA2 802.1X (Enterprise) SSID, it negotiations with clients
over the use of WPA or WPA2 for key management and TKIP or CCMP (AES) for encryption, and uses
whichever methods each client supports. The HiveAP and client use EAP (802.1X) for authentication
through an external RADIUS server.
RADIUS Server: RADIUS-10.1.1.10
User profile assigned if no attribute is returned from RADIUS after successful authentication: Emp(1)
The HiveAP RADIUS authenticator applies the user profile "Emp(1)" to users if the RADIUS
authentication server successfully authenticates them and returns a Tunnel-Private-Group-ID
attribute that matches the attribute for this user profile (1). The HiveAP also applies this profile to
users if the RADIUS authentication server does not return any attributes.
If the RADIUS server authenticates a user and returns attributes that do not match an existing user
profile, the user profile lookup will fail and HiveAP will reject the client.
User profiles assigned via attributes returned from RADIUS after successful authentication: Click IT(2) in the
Available User Profiles list, and then click the right arrow ( > ) to move it to the Selected User Profiles list.
The HiveAP RADIUS authenticator applies the "IT(2)" user profile only if the RADIUS authentication
server returns a Tunnel-Private-Group-ID attribute matching the attribute for this user profile (2).
Only the selected user profiles can be assigned via RADIUS for use with this SSID: (clear)
When cleared, this setting allows access to authenticated users even when the Tunnel-Private-
Group-ID attribute that the RADIUS authentication server returns matches another user profile
configured on the HiveAP but not specified for this SSID. If you do not mind granting access to all
valid user accounts on the RADIUS authentication server, disable this option by clearing the check
box. This is the default setting.
On the other hand, if you want to restrict access to authenticated users only when the RADIUS
authentication server returns attributes that match one of the specified user profiles for the SSID,
enable this option by selecting the check box and then specifying the action that you want to the
HiveAP to take: ban the client for a period of time, ban it indefinitely, or simply disconnect it. You
might want to enable this if the RADIUS authentication server contains accounts for users other
than employees and IT staff—perhaps there are accounts for contractors and guests. Even though
the server would approve authentication requests from such users if they submitted a correct user
name and password, you might not want them to use this SSID to access the WLAN.
SSID Broadcast Band: 2.4 GHz (11n/b/g)
Assigning an SSID to the 2.4 GHz radio in access mode allows HiveAPs to use their second radio,
which operates at 5 GHz, for wireless backhaul communications.
Содержание access point
Страница 1: ...Aerohive Deployment Guide ...
Страница 7: ...HiveAP Compliance Information 6 Aerohive ...
Страница 13: ...Contents 12 Aerohive ...
Страница 37: ...Chapter 2 The HiveAP 20 ag Platform 36 Aerohive ...
Страница 71: ...Chapter 4 The HiveAP 340 Platform 70 Aerohive ...
Страница 81: ...Chapter 5 The HiveAP 320 Platform 80 Aerohive ...
Страница 105: ...Chapter 8 The High Capacity HiveManager Platform 104 Aerohive ...
Страница 123: ...Chapter 10 Using HiveManager 122 Aerohive ...
Страница 209: ...Chapter 14 Deployment Examples CLI 208 Aerohive ...
Страница 217: ...Appenidix A Country Codes 216 Aerohive ...