![AMX Modero ViewPoint MVP-5100 Скачать руководство пользователя страница 181](http://html1.mh-extra.com/html/amx/modero-viewpoint-mvp-5100/modero-viewpoint-mvp-5100_operation-reference-manual_2938973181.webp)
Appendix B: Wireless Technology
169
MVP-5100/5150 5.2" Modero Viewpoint Touch Panels
EAP Communication Overview
EAP Authentication goes a step beyond just encrypting data transfers, but also requires that a set of credentials
be validated before the client (panel) is allowed to connect to the rest of the network (FIG. 93). Below is a
description of this process. It is important to note that no user intervention is necessary during this process. It
proceeds automatically based on the configuration parameters entered into the panel.
1.
The client (panel) establishes a wireless connection with the AP specified by the SSID.
2.
The AP opens up a tunnel between itself and the RADIUS server configured via the access point. This
tunnel means that packets can flow between the panel and the RADIUS server but nowhere else.
The
network is protected until authentication of the client (panel) is complete and the ID of the client is
verified.
3.
The AP (Authenticator) sends an "EAP-Request/Identity" message to the panel as soon as the wireless
connection becomes active.
4.
The panel then sends a "EAP-Response/Identity" message through the AP to the RADIUS server
providing its identity and specifying which EAP type it wants to use. If the server does not support the
EAP type, then it sends a failure message back to the AP which will then disconnect the panel. As an
example, EAP-FAST is only supported by the Cisco server.
5.
If the EAP type is supported, the server then sends a message back to the client (panel) indicating what
information it needs. This can be as simple as a username (
Identity
) and password or as complex as
multiple CA certificates.
6.
The panel then responds with the requested information. If everything matches, and the panel provides
the proper credentials, the RADIUS server then sends a success message to the access point instructing it
to allow the panel to communicate with other devices on the network. At this point, the AP completes the
process for allowing LAN Access to the panel (possibly a restricted access based on attributes that came
back from the RADIUS server).
As an example, the AP might switch the panel to a particular VLAN or install a set of farewell rules.
FIG. 93
EAP security method in process
Client - Panel
(Supplicant)
802.1x
(EAP Over Wireless)
Authenticator
(Access Point)
LAN
Authentication Server
(RADIUS Server)
Содержание Modero ViewPoint MVP-5100
Страница 4: ......
Страница 12: ...viii Document Name Here Table of Contents ...
Страница 22: ...Introduction 10 MVP 5100 5150 5 2 Modero Viewpoint Touch Panels ...
Страница 34: ...Accessories 22 MVP 5100 5150 5 2 Modero Viewpoint Touch Panels ...
Страница 100: ...Protected Setup Pages 88 MVP 5100 5150 5 2 Modero Viewpoint Touch Panels ...
Страница 114: ...Upgrading Firmware 102 MVP 5100 5150 5 2 Modero Viewpoint Touch Panels ...
Страница 160: ...Programming 148 MVP 5100 5150 5 2 Modero Viewpoint Touch Panels ...
Страница 168: ...Battery Life and Replacement 156 MVP 5100 5150 5 2 Modero Viewpoint Touch Panels ...
Страница 176: ...Appendix A Text Formatting 164 MVP 5100 5150 5 2 Modero Viewpoint Touch Panels ...
Страница 184: ...Appendix B Wireless Technology 172 MVP 5100 5150 5 2 Modero Viewpoint Touch Panels ...
Страница 188: ...Appendix C Troubleshooting 176 MVP 5100 5150 5 2 Modero Viewpoint Touch Panels ...
Страница 189: ...Appendix 177 MVP 5100 5150 Modero Viewpoint Touch Panels ...