Controller Security
Summit WM3000 Series Controller System Reference Guide
404
NOTE
EAP-TLS will not work with a default trustpoint. Proper CA and Server trustpoints must be configured for EAP-
TLS. For information on configuring certificates for the controller, see
“Creating Server Certificates” on page 411
.
4
Refer to the
LDAP Server Details
field to define the primary and secondary Radius LDAP server
configuration providing access to an external database used with the local Radius server.
5
Click the
Apply
button to save the changes made to within the screen.
6
Click the
Revert
button to cancel any changes made within the screen and revert back to the last
saved configuration.
Configuring Radius Users
Refer to the
Users
tab to view the current set of users and groups assigned for the Radius server. The
Users tab is employed when
Local
is selected as the Auth Data Source within the
Authentication &
Accounting
tab. The user information is ignored if an LDAP server is used for authentication.
To define the Radius user permissions for controller access:
1
Select
Security
>
Radius Server
from the main menu.
2
Select the
Users
tab.
CA Cert Trustpoint
Click the
View/Change
button to specify the CA certificate trustpoint from
which the Radius server automatically grants certificate enrollment
requests. A trustpoint is a representation of a CA or identity pair. A
trustpoint contains the identity of the CA, CA-specific configuration
parameters, and an association with one enrolled identity certificate.
If a CA trustpoint is not specified, the "default trustpoint's CA certificate
is used as a CA certificate. If the "Default trustpoint" does not have a CA
certificate, the server certificate is used as the CA certificate.
IP Address
Enter the IP address of the external LDAP server acting as the data
source for the Radius server. This server must be accessible from an
active controller subnet.
Port
Enter the TCP/IP port number for the LDAP server acting as the data
source.
Password Attribute
Enter the password attribute used by the LDAP server for authentication.
Bind DN
Specify the distinguished name to bind with the LDAP server.
Bind Password
Enter a valid password for the LDAP server.
Base DN
Specify a distinguished name that establishes the base object for the
search. The base object is the point in the LDAP tree at which to start
searching.
User Login Filter
Enter the login used by the LDAP server for authentication.
Group Filter
Specify the group filters used by the LDAP server.
Group Membership
Attribute
Specify the Group Member Attribute sent to the LDAP server when
authenticating users.
Group Attribute
Specify the group attribute used by the LDAP server.
Net Timeout
Enter a timeout value (between 1-10 seconds) the system uses to
terminate the connection to the Radius Server if no activity is detected.
Содержание Summit WM3000 Series
Страница 42: ...Controller Web UI Access and Image Upgrades Summit WM3000 Series Controller System Reference Guide 42 ...
Страница 139: ...Summit WM3000 Series Controller System Reference Guide 139 ...
Страница 478: ...Diagnostics Summit WM3000 Series Controller System Reference Guide 478 ...
Страница 480: ...Customer Support Summit WM3000 Series Controller System Reference Guide 480 ...
Страница 498: ...AP Management from Controller Summit WM3000 Series Controller System Reference Guide 498 ...
Страница 512: ...Troubleshooting Information Summit WM3000 Series Controller System Reference Guide 512 ...
Страница 513: ......