Wireless Configuration
6-9
To configure EAP on a WLAN:
1. Select
Configuration
>
Wireless
>
Wireless LAN Policy
to display a high-level display of the existing
WLANs.
2. Select the
Add
button to create an additional WLAN, or select and existing WLAN and
Edit
to modify
the security properties of an existing WLAN.
3. Select
Security
.
4. Select
EAP, EAP PSK or EAP MAC
as the Authentication Type.
Either option enables the radio buttons for various encryption option as an additional measure of security
with the WLAN that can be used with EAP.
5. Either select an existing
AAA Policy
from the drop-down menu or select the
Create
icon to the right of
the AAA Policy parameter to display a screen where new AAA policies can be created. A default AAA
policy is also available if configuring a WLAN for the first time and there’s no existing policies. Select the
Edit
icon to modify the configuration of the selected AAA policy.
Authentication, authorization
, and
accounting
(AAA) is a framework for intelligently controlling access to
the network, enforcing user authorization policies and auditing and tracking usage. These combined
processes are central for securing wireless client resources and wireless network data flows. For
information on defining a new AAA policy, see
AAA Policy on page 6-50
.
6. Select the
Reauthentication
radio button to force EAP supported clients to reauthenticate. Use the
spinner control set the number of seconds (between 30 - 86,400) that, once exceeded, forces the EAP
supported client to reauthenticate to use the resources supported by the WLAN.
7. Select
OK
when completed to update the WLAN’s EAP configuration. Select
Reset
to revert the screen
back to the last saved configuration.
EAP, EAP PSK and EAP MAC Deployment Considerations
802.1x EAP, EAP PSK and EAP MAC
Before defining a 802.1x EAP, EAP PSK or EAP MAC supported configuration on a WLAN, refer to the
following deployment guidelines to ensure the configuration is optimally effective:
• Motorola Solutions recommends a valid certificate be issued and installed on devices providing 802.1X
EAP. The certificate should be issued from an Enterprise or public certificate authority to allow 802.1X
clients to validate the identity of the authentication server prior to forwarding credentials.
• If using an external RADIUS server for EAP authentication, Motorola Solutions recommends the round
trip delay over the WAN does not exceed 150ms. Excessive delay over a WAN can cause authentication
and roaming issues and impact wireless client performance.
6.1.2.2 MAC Authentication
Configuring WLAN Security
MAC is a device level authentication method used to augment other security schemes when legacy devices
are deployed using static WEP.
MAC authentication can be used for device level authentication by permitting WLAN access based on device
MAC address. MAC authentication is typically used to augment WLAN security options that do not use
authentication (such as static WEP, WPA-PSK and WPA2-PSK) MAC authentication can also be used to
assign VLAN memberships, Firewall policies and time and date restrictions.
MAC authentication can only identify devices, not users. MAC authentication only references a client
wireless interface card MAC address when authenticating the device, it does not distinguish the device’s
Содержание AP-6511
Страница 1: ...Motorola Solutions AP 6511 Access Point System Reference Guide ...
Страница 2: ...Motorola Solutions AP 6511 Access Point System Reference Guide 1 2 ...
Страница 24: ...Motorola Solutions AP 6511 Access Point System Reference Guide 2 12 ...
Страница 136: ...Motorola Solutions AP 6511 Access Point System Reference Guide 6 2 Figure 6 1 Configuration Wireless field ...
Страница 318: ...Motorola Solutions AP 6511 Access Point System Reference Guide 10 16 ...
Страница 409: ...Statistics 13 49 Figure 13 31 Access Point Firewall Packet Flow screen ...
Страница 433: ......