
AAA Policy
Altitude
TM
4000 Series Access Point System Reference Guide
273
●
To support QoS, each multimedia application, wireless client and WLAN is required to support
WMM.
●
WMM enabled clients can co-exist with non-WMM clients on the same WLAN. Non-WMM clients
are always assigned a Best Effort access category.
●
Extreme Networks recommends default WMM values be used for all deployments. Changing these
values can lead to unexpected traffic blockages, and the blockages might be difficult to diagnose.
●
Overloading an access point radio with too much high priority traffic (especially voice) degrades the
overall service quality for all users.
●
TSPEC admission control is only available with newer voice over WLAN phones. Many legacy voice
devices do not support TPSEC or even support WMM traffic prioritization.
AAA Policy
Authentication, Authorization, and Accounting
(AAA) provides the mechanism network administrators
define access control within the access point managed network.
The access point can optionally use an external RADIUS and LDAP Servers (AAA Servers) to provide
user database information and user authentication data. Each WLAN managed by the access point can
maintain its own unique AAA configuration. Altitude 4532 and Altitude 4700 series access points have
an onboard RADIUS server resource, while Altitude 4511 and Altitude 4521/4522 models do not.
AAA provides a modular way of performing the following services:
Authentication
— Authentication provides a means for identifying users, including login and password
dialog, challenge and response, messaging support and (depending on the security protocol),
encryption. Authentication is the technique by which a user is identified before allowed access to the
access point managed network. Configure AAA authentication by defining a list of authentication
methods, and then applying the list to various access point interfaces. The list defines the authentication
schemes performed and their sequence. The list must be applied to an interface before the defined
authentication technique is conducted.
Authorization
— Authorization occurs immediately after authentication. Authorization is a method for
remote access control, including authorization for services and individual user accounts and profiles.
Authorization functions through the assembly of attribute sets describing what the user is authorized to
perform. These attributes are compared to information contained in a database for a given user and the
result is returned to AAA to determine the user's actual capabilities and restrictions. The database could
be located locally on the access point or be hosted remotely on a RADIUS server. Remote RADIUS
servers authorize users by associating
attribute-value
(AV) pairs with the appropriate user. Each
authorization method must be defined through AAA. When AAA authorization is enabled it’s applied
equally to all interfaces on the managed network.
Accounting
— Accounting is the method for collecting and sending security server information for
billing, auditing, and reporting user data; such as start and stop times, executed commands (such as
PPP), number of packets, and number of bytes. Accounting enables wireless network administrators to
track the services users are accessing and the network resources they are consuming. When accounting
is enabled, the network access server reports user activity to a RADIUS security server in the form of
accounting records. Each accounting record is comprised of AV pairs and is stored on an access control
server. The data can be analyzed for network management, client billing, and/or auditing. Accounting
methods must be defined through AAA. When AAA accounting is activated for the access point, it’s
applied equally to all interfaces on the access point’s access servers.
Содержание Altitude 4000 Series
Страница 14: ...Chapter 2 Overview AltitudeTM 4000 Series Access Point System Reference Guide 14...
Страница 44: ...Chapter 4 Quick Start AltitudeTM 4000 Series Access Point System Reference Guide 44...
Страница 58: ...Chapter 5 Dashboard AltitudeTM 4000 Series Access Point System Reference Guide 58...
Страница 116: ...Chapter 6 Device Configuration AltitudeTM 4000 Series Access Point System Reference Guide 116...
Страница 205: ...Adoption Overrides AltitudeTM 4000 Series Access Point System Reference Guide 205...
Страница 218: ...Chapter 6 Device Configuration AltitudeTM 4000 Series Access Point System Reference Guide 218...
Страница 328: ...Chapter 8 Security Configuration AltitudeTM 4000 Series Access Point System Reference Guide 328...
Страница 332: ...Chapter 9 Services Configuration AltitudeTM 4000 Series Access Point System Reference Guide 332...
Страница 368: ...Chapter 9 Services Configuration AltitudeTM 4000 Series Access Point System Reference Guide 368...
Страница 380: ...Chapter 10 Management Access Policy Configuration AltitudeTM 4000 Series Access Point System Reference Guide 380...
Страница 420: ...Chapter 12 Operations AltitudeTM 4000 Series Access Point System Reference Guide 420...
Страница 520: ...Appendix A Customer Support AltitudeTM 4000 Series Access Point System Reference Guide 520...
Страница 521: ......