Authentication and User Management
14.7 Configuring 802.1X Authentication for a Network Profile
SCALANCE W1750D UI
224
Configuration Manual, 02/2018, C79000-G8976-C451-02
14.7
Configuring 802.1X Authentication for a Network Profile
The SCALANCE W network supports internal RADIUS server and external RADIUS server
for 802.1X authentication.
The steps involved in 802.1X authentication are as follows:
1.
The NAS requests authentication credentials from a wireless client.
2.
The wireless client sends authentication credentials to the NAS.
3.
The NAS sends these credentials to a RADIUS server.
4.
The RADIUS server checks the user identity and authenticates the client if the user
details are available in its database. The RADIUS server sends an Access-Accept
message to the NAS. If the RADIUS server cannot identify the user, it stops the
authentication process and sends an Access-Reject message to the NAS. The NAS
forwards this message to the client and the client must re-authenticate with appropriate
credentials.
5.
After the client is authenticated, the RADIUS server forwards the encryption key to the
NAS. The encryption key is used for encrypting or decrypting traffic sent to and from the
client.
Note
The NAS acts as a gateway to guard access to a protected resource. A client connecting to
the wireless network first connects to the NAS.
Configuring 802.1X Authentication for Wireless Network Profiles
You can configure 802.1X authentication for a wireless network profile in the SCALANCE W
UI or the CLI.
In the SCALANCE W UI
To enable 802.1X authentication for a wireless network:
1.
On the Network tab, click New to create a new network profile or select an existing profile
for which you want to enable 802.1X authentication and click edit.
2.
In the Edit <profile-name> or the New WLAN window, ensure that all required WLAN and
VLAN attributes are defined, and then click Next.
3.
On the Security tab, specify the following parameters for the Enterprise security level:
Select any of the following options from the Key management drop-down list.
–
WPA-2 Enterprise
–
WPA Enterprise
–
Both (WPA-2 & WPA)
–
Dynamic WEP with 802.1X
4.
If you do not want to use a session key from the RADIUS server to derive pairwise
unicast keys, set Session Key for LEAP to Enabled.
Содержание SCALANCE W1750D UI
Страница 18: ...About this guide SCALANCE W1750D UI 18 Configuration Manual 02 2018 C79000 G8976 C451 02 ...
Страница 28: ...About SCALANCE W 3 3 SCALANCE W CLI SCALANCE W1750D UI 28 Configuration Manual 02 2018 C79000 G8976 C451 02 ...
Страница 108: ...IPv6 Support 10 4 Debugging Commands SCALANCE W1750D UI 108 Configuration Manual 02 2018 C79000 G8976 C451 02 ...
Страница 326: ......
Страница 356: ......
Страница 374: ......
Страница 416: ......
Страница 440: ......
Страница 450: ...Intrusion Detection 27 4 Configuring IDS SCALANCE W1750D UI 450 Configuration Manual 02 2018 C79000 G8976 C451 02 ...
Страница 470: ......
Страница 480: ......
Страница 496: ......
Страница 518: ...Hotspot Profiles 33 3 Sample Configuration SCALANCE W1750D UI 518 Configuration Manual 02 2018 C79000 G8976 C451 02 ...
Страница 528: ......
Страница 552: ......
Страница 570: ...Appendix B 3 Glossary SCALANCE W1750D UI 570 Configuration Manual 02 2018 C79000 G8976 C451 02 ...