Installation Guide

Table Of Contents
Task 5: Configuring security
Attribute Meaning
Enforce
Authentication
The SM may enforce authentication types of AAA and AP Pre-
sharedKey. The SM will not finish the registration process if
the AP is not using the configured authentication method (and
the SM locks out the AP for 15 minutes).
Phase 1 The protocols supported for the Phase 1 (Outside Identity)
phase of authentication are
EAPTTLS (Extensible
Authentication Protocol Tunneled Transport Layer
Security) or
MSCHAPv2 (Microsoft Challenge-Handshake Authentication
Protocol version 2).
Phase 2 Select the desired Phase 2 (Inside Identity) authentication
protocol from the Phase 2 options of PAP (Password
Authentication Protocol), CHAP (Challenge Handshake
Authentication
Protocol), and MSCHAP (Microsoft’s version of
CHAP, version 2 is used). The protocol
must
be
consistent with
the authentication protocol configured on the RADIUS
server.
Identity/Realm If Realms are being used, select Enable Realm and configure
an outer identity in the
Identity
field and a Realm in the
Realm field. These must match the Phase 1/Outer Identity and
Realm
configured in the RADIUS server. The default Identity
is anonymous”. The Identity can be
up
to
128 non-special (no
diacritical markings) alphanumeric characters. The default
Realm
is
“canopy.net”. The Realm can also be up to 128 non-
special alphanumeric
characters.
Configure an outer Identity in the Username field. This must
match the Phase
1/Outer
Identity username configured in the
RADIUS server. The default Phase 1/Outer
Identity
Username
isanonymous”. The Username can be up to 128 non-special
(no
diacritical
markings) alphanumeric
characters.
Username Enter a Username for the SM. This must match the username
configured for the SM on
the
RADIUS server. The default
Username is the SM’s MAC address. The Username can be
up
to
128 non-special (no diacritical markings) alphanumeric
characters.
Password Enter the desired password for the SM in the Password and
Confirm Password fields..
The
Password must match the
password configured for the SM on the RADIUS server.
The
default Password is password”. The Password can be up to
128 non-special (no
diacritical
markings) alphanumeric
characters
102
pmp-0957 (April 2015)