Switch Security
6-101
4. Select LDAP Group Verification Details checkbox. Refer to the
LDAP Server Details
field to define the
primary and secondary Radius LDAP server configuration providing access to an external database used
with the local Radius server.
5. Enable the
Enable Primary Ldap Agent
checkbox to support the PEAP-MSCHAPv2 authentication
system with user/password database as Active Directory.
Cert Trustpoint
Click the
View/Change
button to specify the trustpoint from which the Radius
server automatically grants certificate enrollment requests. A trustpoint is a
representation of a CA or identity pair. A trustpoint contains the identity of the CA,
CA-specific configuration parameters, and an association with one enrolled
identity certificate. If the server certificate trustpoint is not used, the default
trustpoint is used instead.
CA Cert Trustpoint
Click the View/Change button to specify the CA certificate trustpoint from which
the Radius server automatically grants certificate enrollment requests. A
trustpoint is a representation of a CA or identity pair. A trustpoint contains the
identity of the CA, CA-specific configuration parameters, and an association with
one enrolled identity certificate.
If a CA trustpoint is not specified, the "default trustpoint's CA certificate is used
as a CA certificate. If the "Default trustpoint" does not have a CA certificate, the
server certificate is used as the CA certificate.
NOTE:
EAP-TLS will not work with a default trustpoint. Proper CA and Server trustpoints
must be configured for EAP-TLS. For information on configuring certificates for the switch,
see
Creating Server Certificates on page 6-108
.
IP Address
Enter the IP address of the external LDAP server acting as the data source for the
Radius server. This server must be accessible from an active switch subnet.
Port
Enter the TCP/IP port number for the LDAP server acting as the data source.
Password Attribute
Enter the password attribute used by the LDAP server for authentication.
Bind DN
Specify the distinguished name to bind with the LDAP server.
Bind Password
Enter a valid password for the LDAP server.
Base DN
Specify a distinguished name that establishes the base object for the search. The
base object is the point in the LDAP tree at which to start searching.
User Login Filter
Enter the login used by the LDAP server for authentication.
Group Filter
Specify the group filters used by the LDAP server.
Group Membership
Attribute
Specify the Group Member Attribute sent to the LDAP server when authenticating
users.
Group Attribute
Specify the group attribute used by the LDAP server.
Net Timeout
Enter a timeout value (between 1-10 seconds) the system uses to terminate the
connection to the Radius Server if no activity is detected.
Domain Name
Enter the Active Directory domain name.
e.g. MotorolaAD.com
Domain Admin User
Enter the Administrator Username of the LDAP server
Содержание RFS Series
Страница 1: ...M Motorola RFS Series Wireless LAN Switches WiNG System Reference Guide ...
Страница 10: ...TOC 8 Motorola RF Switch System Reference Guide ...
Страница 56: ...2 8 Motorola RF Switch System Reference ...
Страница 334: ...5 52 Motorola RF Switch System Reference 2 Select the MU Status tab ...
Страница 510: ...7 32 Motorola RF Switch System Reference Guide ...
Страница 534: ...8 24 Motorola RF Switch System Reference Guide ...
Страница 570: ...C 14 Motorola RF Switch System Reference Guide ...
Страница 589: ......
Страница 590: ...MOTOROLA INC 1303 E ALGONQUIN ROAD SCHAUMBURG IL 60196 http www motorola com 72E 132942 01 Revision C December 2010 ...