Motorola Solutions AP-6511 Access Point System Reference Guide
6-50
6.4 AAA Policy
Authentication, Authorization, and Accounting
(AAA) provides the mechanism network administrators define
access control within the network.
The AP-6511 can interoperate with external Radius and LDAP Servers (AAA Servers) to provide user
database information and user authentication data. Each WLAN can maintain its own unique AAA
configuration.
AAA provides a modular way of performing the following services:
Authentication
— Authentication provides a means for identifying users, including login and password
dialog, challenge and response, messaging support and (depending on the security protocol), encryption.
Authentication is the technique by which a user is identified before granted access. Configure AAA
authentication by defining a list of authentication methods, and then applying the list to various interfaces.
The list defines the authentication schemes performed and their sequence. The list must be applied to an
interface before the defined authentication technique is conducted.
Authorization
— Authorization occurs immediately after authentication. Authorization is a method for
remote access control, including authorization for services and individual user accounts and profiles.
Authorization functions through the assembly of attribute sets describing what the user is authorized to
perform. These attributes are compared to information contained in a database for a given user and the result
is returned to AAA to determine the user's actual capabilities and restrictions. Remote RADIUS servers
authorize users by associating
attribute-value
(AV) pairs with the appropriate user. Each authorization
method must be defined through AAA. When AAA authorization is enabled it’s applied equally to all
interfaces on the network.
Accounting
— Accounting is the method for collecting and sending security server information for billing,
auditing, and reporting user data; such as start and stop times, executed commands (such as PPP), number
of packets, and number of bytes. Accounting enables wireless network administrators to track the services
users are accessing and the network resources they are consuming. When accounting is enabled, the
network access server reports user activity to a RADIUS security server in the form of accounting records.
The data can be analyzed for network management, client billing, and/or auditing. Accounting methods must
be defined through AAA.
To define unique WLAN AAA configurations:
1. Select
Configuration
>
Wireless
>
AAA Policy
to display existing AAA policies.
The
Authentication, Authorization, and Accounting (AAA)
screen lists those AAA policies created
thus far. Any of these policies can be selected and applied.
Содержание AP-6511
Страница 1: ...Motorola Solutions AP 6511 Access Point System Reference Guide ...
Страница 2: ...Motorola Solutions AP 6511 Access Point System Reference Guide 1 2 ...
Страница 24: ...Motorola Solutions AP 6511 Access Point System Reference Guide 2 12 ...
Страница 136: ...Motorola Solutions AP 6511 Access Point System Reference Guide 6 2 Figure 6 1 Configuration Wireless field ...
Страница 318: ...Motorola Solutions AP 6511 Access Point System Reference Guide 10 16 ...
Страница 409: ...Statistics 13 49 Figure 13 31 Access Point Firewall Packet Flow screen ...
Страница 433: ......