
Chapter 7: Wireless Configuration
Altitude
TM
4000 Series Access Point System Reference Guide
226
To configure EAP on a WLAN:
1
Select
Configuration
>
Wireless
>
Wireless LANs
to display a high-level display of the existing WLANs.
2
Select the
Add
button to create an additional WLAN, or select and existing WLAN and
Edit
to
modify the security properties of an existing WLAN.
3
Select
Security
.
4
Select
EAP
,
EAP PSK
or
EAP MAC
as the Authentication Type.
Either option enables the radio buttons for various encryption option as an additional measure of
security with the WLAN that can be used with EAP.
5
Either select an existing
AAA Policy
from the drop-down menu, or select the
Create
icon to the right
of the AAA Policy parameter tcreate a new AAA policy, or select the
Edit
icon to modify the
configuration of the selected AAA policy.
Authentication, authorization
, and
accounting
(AAA) is a framework for intelligently controlling access
to the network, enforcing user authorization policies and auditing and tracking usage. These
combined processes are central for securing wireless client resources and wireless network data
flows. For information on defining a new AAA policy, see
“AAA Policy” on page 273
.
6
Select the
Reauthentication
radio button to force EAP supported clients to reauthenticate. Use the
spinner control set the number of seconds (between 30 - 86,400) that, once exceeded, forces the EAP
supported client to reauthenticate to use the resources supported by the WLAN.
7
Select
OK
to update the WLAN’s EAP configuration. Select
Reset
to revert back to the last saved
configuration.
EAP, EAP PSK and EAP MAC Deployment Considerations
“802.1x EAP, EAP PSK and EAP MAC”
Before defining a 802.1x EAP, EAP PSK or EAP MAC supported configuration on a WLAN, refer to the
following deployment guidelines to ensure the configuration is optimally effective:
●
Extreme Networks recommends a valid certificate be issued and installed on devices providing
802.1X EAP. The certificate should be issued from an Enterprise or public certificate authority to
allow 802.1X clients to validate the identity of the authentication server prior to forwarding
credentials.
●
If using an external RADIUS server for EAP authentication, Extreme Networks recommends the
round trip delay over the WAN does not exceed 150ms. Excessive delay over a WAN can cause
authentication and roaming issues and impact wireless client performance.
MAC Authentication
“Configuring WLAN Security”
MAC is a device level authentication method used to augment other security schemes. MAC can be
used open, with WEP 64 or WEP 128, KeyGuard, TKIP or CCMP.
MAC authentication can be used for device level authentication by permitting WLAN access based on
device MAC address. MAC authentication is typically used to augment WLAN security options that do
not use authentication (such as static WEP, WPA-PSK and WPA2-PSK). MAC authentication can also be
used to assign VLAN memberships, Firewall policies and time and date access restrictions.
MAC authentication can only identify devices, not users. MAC authentication only references a client’s
wireless interface card MAC address when authenticating the device, it does not distinguish the
device’s user credentials. MAC authentication is somewhat poor as a standalone data protection
Содержание Altitude 4000 Series
Страница 14: ...Chapter 2 Overview AltitudeTM 4000 Series Access Point System Reference Guide 14...
Страница 44: ...Chapter 4 Quick Start AltitudeTM 4000 Series Access Point System Reference Guide 44...
Страница 58: ...Chapter 5 Dashboard AltitudeTM 4000 Series Access Point System Reference Guide 58...
Страница 116: ...Chapter 6 Device Configuration AltitudeTM 4000 Series Access Point System Reference Guide 116...
Страница 205: ...Adoption Overrides AltitudeTM 4000 Series Access Point System Reference Guide 205...
Страница 218: ...Chapter 6 Device Configuration AltitudeTM 4000 Series Access Point System Reference Guide 218...
Страница 328: ...Chapter 8 Security Configuration AltitudeTM 4000 Series Access Point System Reference Guide 328...
Страница 332: ...Chapter 9 Services Configuration AltitudeTM 4000 Series Access Point System Reference Guide 332...
Страница 368: ...Chapter 9 Services Configuration AltitudeTM 4000 Series Access Point System Reference Guide 368...
Страница 380: ...Chapter 10 Management Access Policy Configuration AltitudeTM 4000 Series Access Point System Reference Guide 380...
Страница 420: ...Chapter 12 Operations AltitudeTM 4000 Series Access Point System Reference Guide 420...
Страница 520: ...Appendix A Customer Support AltitudeTM 4000 Series Access Point System Reference Guide 520...
Страница 521: ......