![Extreme Networks Summit WM20 Скачать руководство пользователя страница 90](http://html.mh-extra.com/html/extreme-networks/summit-wm20/summit-wm20_user-manual_2454473090.webp)
WM Access Domain Services
Summit WM20 User Guide, Software Release 4.2
90
●
Extensible Authentication Protocol with Tunneled Transport Layer Security (EAP-TTLS)
– Relies
on mutual authentication of client and server through an encrypted tunnel. Unlike EAP-TLS, it
requires only server-side certificates. The client uses PAP, CHAP, or MS-CHAPv2 for authentication.
●
Protected Extensible Authentication Protocol (PEAP)
– Is an authentication protocol similar to TTLS
in its use of server side certificates for server authentication and privacy and its support for a variety
of user authentication mechanisms.
For 802.1x, the RADIUS server must support RADIUS extensions (RFC2869).
Until the access-accept is received from the RADIUS server for a specific user, the user is kept in an
unauthenticated state. 802.1x rules dictate no other packets other than EAP are allowed to traverse
between the AP and the Summit WM Controller until authentication completes. Once authentication is
completed (access-accept is received), the user's client is then allowed to proceed with IP services,
which typically implies the request of an IP address via DHCP.
In addition, the definition of a specific filter ID is optional configuration. If a specific filter ID is not
defined or returned by the access-accept operation, the Summit WM Controller assigns the WM-AD
default filter for authenticated users.
NOTE
The Summit WM Controller only assigns the device's IP after the client requests one.
Both Captive Portal and AAA (802.1x) authentication mechanisms in Summit WM Controller, Access
Points and Software rely on a RADIUS server on the enterprise network. You can identify and prioritize
up to three RADIUS servers on the Summit WM Controller—in the event of a failover of the active
RADIUS server, the Summit WM Controller will poll the other servers in the list for a response. Once
an alternate RADIUS server is found, it becomes the active RADIUS server, until it either also fails, or
the administrator redefines another.
Filtering for a WM-AD
The WM-AD capability provides a technique to apply policy, to allow different network access to
different groups of users. This is accomplished by packet filtering.
After setting authentication, define the filtering rules for the filters that apply to your network and the
WM-AD you are setting up. Several filter types are applied by the Summit WM Controller:
●
Exception filter
– Protect access to a system's own interfaces, including the WM-AD's own interface.
WM-AD exception filters are applied to user traffic intended for the Summit WM Controller's own
interface point on the WM-AD. These filters are applied after the user's specific WM-AD state
assigned filters.
●
Non-authenticated filter with filtering rules that apply before authentication
– Controls network
access and to direct users to a Captive Portal Web page for login.
●
Group filters, by filter ID, for designated user groups
– Controls access to certain areas of the
network, with values that match the values defined for the RADIUS filter ID attribute.
●
Default filter
– Controls access if there is no matching filter ID for a user.
Содержание Summit WM20
Страница 8: ...Table of Contents Summit WM20 User Guide Software Release 4 2 8 ...
Страница 20: ...About this Guide Summit WM20 User Guide Software Release 4 2 20 ...
Страница 54: ...Configuring the Summit WM Controller Summit WM20 User Guide Software Release 4 2 54 ...
Страница 96: ...WM Access Domain Services Summit WM20 User Guide Software Release 4 2 96 ...
Страница 150: ...WM Access Domain Services Configuration Summit WM20 User Guide Software Release 4 2 150 ...
Страница 168: ...Availability and Controller Functionality Summit WM20 User Guide Software Release 4 2 168 ...
Страница 172: ...Working With Third Party APs Summit WM20 User Guide Software Release 4 2 172 ...
Страница 184: ...Working With the Summit WM Series Spy Summit WM20 User Guide Software Release 4 2 184 ...
Страница 194: ...Working With Reports and Displays Summit WM20 User Guide Software Release 4 2 194 ...
Страница 216: ...Performing System Maintenance Summit WM20 User Guide Software Release 4 2 216 ...