
LANCOM WLC series
Chapter 4: Configuring the WLAN Controller
108
EN
RADIUS server can change the realms in the user names for the purpose of
RADIUS forwarding:
The value defined for "Standard realm" replaces an existing realm of an
incoming request if no forwarding is defined for that existing realm.
The value defined under "Empty realm" is
only used if
the incoming user
name
does not yet have
a realm.
An entry in the forwarding table causes all authentication requests with a cer-
tain realm to be forwarded to a RADIUS server. If no matching entry exists in
the forwarding table, the request is refused.
If a realm is found to be an empty realm, the authentication request
is
always
checked with the internal RADIUS database in the
LANCOM.
The following flow diagram illustrates the method used by the RADIUS server
to process realms:
Using different realm tags allows different RADIUS servers to be targeted with
requests. The way in which the LANCOM's RADIUS server makes decisions for
the two requests is shown in the diagram.
쐃
Because the user names for guest access accounts are generated auto-
matically, they are suffixed with an appropriate realm, such as "PSpot".
Because the forwarding table does not contain this entry and the standard
realm is empty, all authentication requests with this realm are forwarded
to the internal RADIUS server.
쐇
To limit the amount of work required for the configuration, internal users
are listed without a realm. The RADIUS server in the LANCOM can auto-
matically replace an empty realm with another realm in order to identify
internal users. In this example, the empty realm is replaced by the domain
Yes
No
Yes
No
Yes
realm=empty
Forward
to defined
server
Reject request
No
Check request
with local
RADIUS database
Request
쐃
Realm
available in forwarding
table?
Replace realm
with
„default realm“
Set realm
to
„empty realm“
Realm
available in forwarding
table?
Realm
available in
user name?
Request
쐇