Specifications
Security Options 83
Chapter 5
Accounting
AOS-W supports standard RADIUS accounting for tracking user login/logout
times. Accounting will track logins accurately, but logouts may not be tracked
accurately since the user may roam out of range without logging out. To
configure accounting, navigate to ConfigurationÆSecurityÆAAA
ServersÆAccounting, as shown in the figure below.
FIGURE 5-17 RADIUS Accounting
Configuration parameters are:
Enable Accounting – Specifies whether or not accounting will be enabled.
Server – Specifies a list of configured RADIUS servers to which accounting
data will be sent. Servers must be configured under
Configuration > Security >
AAA Servers > RADIUS
before they appears as available options.
The equivalent CLI configuration for the example above is:
aaa radius-accounting mode enable
aaa radius-accounting auth-server test
Authentication Methods
Authentication provides a way to identify a user and provide appropriate
access to the network for that user. By default, all wireless users in an Alcatel
network start in the “logon” role, and use an authentication method to move
to an identified, authenticated role. One or more authentication methods may
be used, ranging from secure authentication methods such as 802.1x, VPN,
and captive portal to less secure “role mapping”. Role mapping should always
be combined with firewall policies to provide enhanced security.