User guide

RADIUS Authentication
Enterasys Wireless Standalone 802.11n AP User Guide 2-5
•MUstatistichistory
•Prea
uthentication
AclusterformswhenAPsoperatingwithi
nthesamesubnetareconfiguredwiththesamecluster
ID(sharedsecret).AclusterAPcanexistatanypointinyournetwork.Eachclustermember
periodically(30seconds)sendsasecureSIAPPmulticastmessagetoupdateothercluster
members.TheSIAPPmessageincludes:
•TheAPNa
me
•TheAPEthernetMA
Caddress
•TheAPIPaddress
•Theclientcount
•ThebaseBSSIDsforbothradios
EachAPcach
eslocallyinformationaboutotherclustermembersandmaintainsitsownviewof
thecluster.Formoreinformationaboutconfiguringacluster,seeConfigur
ingGeneralLAN
Settingsonpage42.
RADIUS Authentication
RemoteAuthenticationDialinUserService(RADIUS)isanauthenticationprotocolthatuses
softwarerunningonacentralservertocontrolaccesstoRADIUSawaredevicesonthenetwork.
Anauthenticationservercontainsadatabaseofusercredentialsforeachuserthatrequiresaccess
tothenetwork.
Youmustspeci
fyaprimaryRADIUSserverfortheAPtoimplementIEEE802.1x networkaccess
controlandWiFiProtectedAccess(WPA)wirelesssecurity.Youcanalsospecifyasecondary
RADIUSserverasabackup shouldtheprimaryserverfailorbecomeinaccessible.
Inaddition,theco
nfiguredRADIUSservercanalsoactasaRADIUSaccountingserverand
receiveusersessionaccountinginformationfromtheaccesspoint.RADIUSaccountingcanbe
usedtoprovidevaluableinformationonuseractivityinthenetwork.
Notes: This guide assumes that you already configured RADIUS server(s) to support the access
point. Configuration of RADIUS server software is beyond the scope of this guide. Refer to the
documentation provided with the RADIUS server software.
If you are using RADIUS, it is highly recommended that you assign the AP a static IP address to
ensure that the address doesn’t change via DHCP.
ForinformationaboutRADIUSconfiguration,seeConfiguringRADIUSAuthenticationon
page410.
About Network Security
TheAPprovidesfeaturesandfunctionalitytocontrolnetworkaccess.Thesearebasedon
standardwirelessnetworksecuritypractices.Currentwirelessnetworksecuritymethodsprovide
adegreeofprotection.ThesemethodsincludeanopensystemthatreliesonSSIDs.
TheAPsuppo
rtsthefollowingencryptionapproaches:
•WiredEquiv
alentPrivacy(WEP)Asecurityprotocolforwirelesslocalareanetworks
definedintheIEEE802.11bstandardthatprovidesstatickeymanagement,andWEP64bit,
128bit,and152bitciphers.