
Chapter 9: Services Configuration
Altitude
TM
4000 Series Access Point System Reference Guide
352
The access point’s local RADIUS server stores the user database locally, and can optionally use a remote
user database. It ensures higher accounting performance. It allows the configuration of multiple users,
and assign policies for the group authorization.
Altitude 4532 and Altitude 4700 series access points have an internal RADIUS server resource. However,
Altitude 4511 and Altitude 4521/4522 models do not have an onboard RADIUS server resource and an
external resource must be used.
The access point allows the enforcement of user-based policies. User policies include dynamic VLAN
assignment and access based on time of day. The access point uses a default trustpoint. A certificate is
required for EAP TTLS,PEAP and TLS RADIUS authentication (configured with the RADIUS service).
Dynamic VLAN assignment is achieved based on the RADIUS server response. A user who associates
to WLAN1 (mapped to VLAN1) can be assigned a different VLAN after authentication with the
RADIUS server. This dynamic VLAN assignment overrides the WLAN's VLAN ID to which the user
associates.
To view RADIUS configurations, select
Configuration
>
Services
.
Select
Configuration
>
Services
.
The upper, left-hand side of the user interface displays the
RADIUS
option. The
RADIUS
Group
screen
displays (by default).
For information on creating the groups, user pools and server policies needed to validate user
credentials against a server policy configuration, refer to the following:
●
Creating RADIUS Groups on page 352
●
Defining User Pools on page 355
●
Configuring the RADIUS Server on page 359
Creating RADIUS Groups
The access point’s RADIUS server allows the configuration of user groups with common user policies.
User group names and associated users are stored in the access point’s local database. The user ID in
the received access request is mapped to the associated wireless group for authentication. Group
configurations allow the enforcement of the following policies controlling user access:
●
The assignment of a VLAN to the user upon successful authentication
●
The creation of a start and end of time in (HH:MM) when a user is allowed to authenticate
●
The creation of a list of SSIDs to which a user belonging to this group is allowed to associate
●
the ability to set the days of the week a user is allowed to login
●
The ability to rate limit traffic
To review existing RADIUS groups and add, modify or delete group configurations:
1
Select
Configuration
>
Services
.
2
Select
RADIUS
.
A list of existing groups displays by default.
Содержание Altitude 4000 Series
Страница 14: ...Chapter 2 Overview AltitudeTM 4000 Series Access Point System Reference Guide 14...
Страница 44: ...Chapter 4 Quick Start AltitudeTM 4000 Series Access Point System Reference Guide 44...
Страница 58: ...Chapter 5 Dashboard AltitudeTM 4000 Series Access Point System Reference Guide 58...
Страница 116: ...Chapter 6 Device Configuration AltitudeTM 4000 Series Access Point System Reference Guide 116...
Страница 205: ...Adoption Overrides AltitudeTM 4000 Series Access Point System Reference Guide 205...
Страница 218: ...Chapter 6 Device Configuration AltitudeTM 4000 Series Access Point System Reference Guide 218...
Страница 328: ...Chapter 8 Security Configuration AltitudeTM 4000 Series Access Point System Reference Guide 328...
Страница 332: ...Chapter 9 Services Configuration AltitudeTM 4000 Series Access Point System Reference Guide 332...
Страница 368: ...Chapter 9 Services Configuration AltitudeTM 4000 Series Access Point System Reference Guide 368...
Страница 380: ...Chapter 10 Management Access Policy Configuration AltitudeTM 4000 Series Access Point System Reference Guide 380...
Страница 420: ...Chapter 12 Operations AltitudeTM 4000 Series Access Point System Reference Guide 420...
Страница 520: ...Appendix A Customer Support AltitudeTM 4000 Series Access Point System Reference Guide 520...
Страница 521: ......