Owners manual

160 | Authentication and User Management Aruba Instant 6.4.0.2-4.1 | User Guide
Parameter Description
Shared key
Enter a shared key for communicating with the external RADIUS server.
Retype key Re-enter the shared key.
Timeout
Specify a timeout value in seconds. The value determines the timeout for one
RADIUS request. The IAP retries to send the request several times (as configured
in the Retry count), before the user gets disconnected. For example, if the Timeout
is 5 seconds, Retry counter is 3, user is disconnected after 20 seconds. The default
value is 5 seconds.
Retry count
Specify a number between 1 and 5. Indicates the maximum number of
authentication requests that are sent to the server group, and the default value is 3
requests.
RFC 3576
Select Enabled to allow the APs to process RFC 3576-compliant Change of
Authorization (CoA) and disconnect messages from the RADIUS server.
Disconnect messages cause a user session to be terminated immediately,
whereas the CoA messages modify session authorization attributes such as data
filters.
NAS IP address
Enter the Virtual Controller IP address. The NAS IP address is the Virtual Controller
IP address that is sent in data packets.
NOTE: If you do not enter the IP address, the Virtual Controller IP address is used
by default when Dynamic RADIUS Proxy is enabled.
NAS identifier Use this to configure strings for RADIUS attribute 32, NAS Identifier, to be sent with
RADIUS requests to the RADIUS server.
Dead Time Specify a dead time for authentication server in minutes.
When two or more authentication servers are configured on the IAP and a server is
unavailable, the dead time configuration determines the duration for which the
authentication server would be available if the server is marked as unavailable.
Dynamic RADIUS
proxy parameters
Specify the following dynamic RADIUS proxy parameters:
l DRP IP IP address to be used as source IP for RADIUS packets
l DRP Mask—Subnet mask of the DRP IP address.
l DRP VLAN—VLAN in which the RADIUS packets are sent.
l DRP Gateway—Gateway IP address of the DRP VLAN.
For more information on dynamic RADIUS proxy parameters and configuration
procedure, see Configuring Dynamic RADIUSProxy Parameters on page 162.
l LDAP Server —To configure an LDAP server, select the LDAP option and specify the attributes described in the
following table:
Parameter Description
Name
Enter the name of the LDAP server.
IP address
Enter the IP address of the LDAP server.
Auth port
Enter the authorization port number of the LDAPserver. The default port number is
389.
Table 33:
LDAPServer Configuration Parameters