Chapter 4 HiveManager Examples
56
Aerohive
server. The default is 600 seconds (or 10 minutes). The minimum is 60 seconds and there is no maximum.
Generally, you want to make the retry interval fairly large so that supplicants (that is, wireless clients
requesting 802.1X authentication) do not have to wait unnecessarily as a HiveAP repeatedly tries to connect
to a primary server that is down for an extended length of time.
•
Accounting Interim Update Interval:
3600
(default)
This is the interval in seconds for updating the RADIUS accounting server with the cumulative length of a
client
’
s session.
•
RADIUS Server:
•
Click
Add
, enter the following, and then click
OK
:
—
IP Address:
10.1.1.15
—
Comment:
Primary RADIUS Server
—
Shared Secret:
J7ix2bbbLA
—
Repeat Secret:
J7ix2bbbLA
—
Auth Port:
1812
(default RADIUS authentication port number)
—
Acct Port:
1813
(default RADIUS accounting port number)
—
Server Priority:
First
•
Click
Add
, enter the following, and then click
OK
:
—
IP Address:
10.1.2.16
—
Comment:
Backup RADIUS Server
—
Shared Secret:
J8Dx2c13Mb
—
Repeat Secret:
J8Dx2c13Mb
—
Auth Port:
1812
—
Acct Port:
1813
—
Server Priority:
Second
3. To close the New RADIUS Profile dialog box, click
OK
.
RADIUS Server Attributes
On the two RADIUS servers (also referred to as "RADIUS home servers"), define the HiveAPs as RADIUS clients.
1
Also,
configure the following attributes for the realms to which user accounts matching the two user profiles belong:
The RADIUS server returns one of the above sets of attributes based on the realm to which an authenticating user
belongs. HiveAPs then use the combination of returned RADIUS attributes to assign users to user profile 2 ("IT") or 3
("Employees"). Note that these attributes do not create a GRE tunnel, which the tunnel type might seem to indicate.
Note:
The shared secret is a case-sensitive alphanumeric string that must be entered on each RADIUS server
exactly as shown above.
1. If you use RADIUS proxy servers, then direct RADIUS traffic from the HiveAPs to them instead of the RADIUS home servers. This
approach offers the advantage that you only need to define the proxy servers as clients on the RADIUS home servers. You can
then add and remove multiple HiveAPs without having to reconfigure the RADIUS home servers after each change.
Realm for IT (User Profile ID = 2)
Realm for Employees (User Profile ID = 3)
Tunnel Type = GRE (value = 10)
Tunnel Type = GRE (value = 10)
Tunnel Medium Type = IP (value = 1)
Tunnel Medium Type = IP (value = 1)
Tunnel Private Group ID = 2
Tunnel Private Group ID = 3
Содержание HiveAP 20 ag
Страница 1: ...Aerohive Deployment Guide...
Страница 6: ...HiveAP Compliance Information 6 Aerohive...
Страница 64: ...Chapter 4 HiveManager Examples 64 Aerohive...