Concept Guide

171 | Authentication and User Management Dell Networking W-Series Instant 6.4.3.1-4.2.0.0 | User Guide
Configuring Dynamic RADIUSProxy Parameters
The RADIUS server can be deployed at different locations and VLANs. In most cases, a centralized RADIUSor
local server is used to authenticate users. However, some user networks can use a local RADIUS server for
employee authentication and a centralized RADIUS based captive portal server for guest authentication. To
ensure that the RADIUS traffic is routed to the required RADIUS server, the dynamic RADIUSproxy feature
must be enabled.
The dynamic RADIUS proxy parameters configuration is not required if RadSec is enabled in the
RADIUSserver profile.
If the W-IAP clients need to authenticate to the RADIUS servers through a different IP address and VLAN,
ensure that the following steps are completed:
1. Enable dynamic RADIUSproxy.
2. Configure dynamic RADIUSproxy IP, VLAN. netmask, gateway for each authentication server.
3. Associate the authentication servers to SSID or a wired profile to which the clients connect.
After completing the above-mentioned configuration steps, you can authenticate the SSID users against the
configured dynamic RADIUSproxy parameters.
Enabling Dynamic RADIUS Proxy
You can enable RADIUS Server Support using the Instant UI or CLI.
In the Instant UI
To enable RADIUS server support:
1. In the Instant main window, click the System link. The System window is displayed.
2. On the General tab of the System window, select Enabled from the Dynamic RADIUS Proxy drop-down
list.
3. Click OK.
When dynamic RADIUS proxy is enabled, the Virtual Controller network uses the IP Address of the Virtual
Controller for communication with external RADIUS servers. Ensure that the Virtual Controller IP Address is
set as a NAS IP when configuring RADIUS server attributes with dynamic RADIUS proxy enabled. For more
information on configuring RADIUS server attributes, see Configuring an External Server for Authentication
on page 164.
In case of VPNdeployments, the tunnel IP received when establishing a VPN connection is used as the NASIP.
In such cases, the Virtual controller IP need not be configured for the external RADIUS servers.
In the CLI
To enable the dynamic RADIUS proxy feature:
(Instant AP)(config)# dynamic-radius-proxy
(Instant AP)(config)# end
(Instant AP)# commit apply
Configuring Dynamic RADIUS Proxy Parameters
You can configure DRP parameters for the authentication server by using the Instant UI or CLI.
In the Instant UI
1. Click the Security>Authentication Servers.