Installation Guide

Table Of Contents
Task 15: Configuring a RADIUS server PMP 450i and PTP 450i Configuration and User
Guide
Table 59 SM Security tab attributes
Attribute Meaning
Authentication Key
The authentication key is a 32-character hexadecimal string used
when Authentication Mode is set to AP PreShared Key. By
default, this key is set to
0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF.
Select Key
This option allows operators to choose which authentication key is
used:
Use Key above means that the key specified in Authentication
Key is used for authentication
Use Default Key means that a default key (based off of the SM’s
MAC address) is used for authentication
Enforce
Authentication
The SM may enforce authentication types of AAA and AP Pre-
sharedKey. The SM will not finish the registration process if the
AP is not using the configured authentication method (and the SM
locks out the AP for 15 minutes). Enforce Authentication default
setting is Disable.
Phase 1
The protocols supported for the Phase 1 (Outside Identity) phase
of authentication are
EAPTTLS (Extensible Authentication
Protocol Tunneled Transport Layer
Security) or MSCHAPv2
(Microsoft Challenge-Handshake Authentication Protocol version
2).
Phase 2
Select the desired Phase 2 (Inside Identity) authentication
protocol from the Phase 2 options of PAP (Password
Authentication Protocol), CHAP (Challenge Handshake
Authentication
Protocol), and MSCHAP (Microsoft’s version of
CHAP, version 2 is used). The protocol
must
be
consistent with
the authentication protocol configured on the RADIUS
server.
Identity/Realm
If Realms are being used, select Enable Realm and configure an
outer identity in the
Identity
field and a Realm in the Realm
field. These must match the Phase 1/Outer Identity and
Realm
configured in the RADIUS server. The default Identity is
anonymous”. The Identity can be
up
to
128 non-special (no
diacritical markings) alphanumeric characters. The default
Realm
is
“canopy.net”. The Realm can also be up to 128 non-
special alphanumeric
characters.
Configure an outer Identity in the Username field. This must
match the Phase
1/Outer
Identity username configured in the
RADIUS server. The default Phase 1/Outer
Identity
Username is
anonymous. The Username can be up to 128 non-special (no
diacritical
markings) alphanumeric
characters.
pmp-0957 (April 2015) 193