Specifications
Security
RoamAbout Access Point 3000 Configuration Guide 4-67
Whenyouenable802.1x,youcanalsoenablethebroadcastandsessionkeyrotationintervals.
– BroadcastKeyRefreshRatesetstheintervalatwhichthebroadcastkeysarerefreshedfor
stationsusing802.1xdynamickeying.(Range:0‐1440minutes;Default:0meansdisabled)
– SessionKeyRefreshRatespecifiestheintervalat
whichtheaccesspointrefreshesunicast
sessionkeysforassociatedclients.(Range:0‐1440minutes;Default:0meansdisabled)
– 802.1xSessionTimeoutsetsthetimeperiodafterwhichaconnectedclientmustbere‐
authenticated.Duringthere‐authenticationprocessofverifyingtheclient’scredentialson
theRADIUSserver,the
clientremainsconnectedtothenetwork.Onlyifre‐authentication
failsisnetworkaccessblocked.Default:60minutes.
• MACAuthenticationconfigureshowthe accesspointusesMACaddressestoauthorize
wirelessclientstoaccessthenetwork.Thisauthenticationmethodprovidesabasiclevelof
authenticationforwirelessclientsattemptingtogain
accesstothenetwork.Adatabaseof
authorizedMACaddressescanbestoredlocal ly ontheAccessPoint3000orremotelyona
centralRADIUSserver.(Default:LocalMAC)
– LocalMACindicatesthattheMACaddressoftheassociatingstationiscomparedagainst
thelocaldatabasestoredontheaccess
point.LocalMACAuthenticationenablesthelocal
databasetobesetup.
– RADIUSMACspecifiesthattheMA Caddressoftheassociatingstationissenttoa
configuredRADIUSserverforauthentication.
TouseaRADIUSauthentica tionserverforMACaddressau thentication,theaccesspoint
mustbeconfiguredtousea
RADIUSserver,seeRADIUS(page4‐9).
– Disablespecifiesthattheaccesspointdoesnotcheckanassociatingstation’sMACaddress.
IfyouspecifyRADIUSMACforthisdefaultinterfaceorVAP,youmustspecifythefollowing
parameters:
– MACAuthenticationPasswordspecifiestheauthenticationpasswordthisradiointerfaceor
VAP
sendstotheRADIUSservertoauthenticateMACaddresses.
– MACAuthenticationSessionTimeoutspecif iestheamountoftimeafterwhichyouwanta
MACauthenticationsessiontotimeoutbetweentheAPandtheRADIUSserver.
IfyouspecifyLocalMACforthisdefaultinterfaceorVAP,youmustspecifyLocal
MAC
AuthenticationsettingsthatconfigurethelocalMACauthenticationdatabase.TheMAC
databaseprovidesamechanismtotakecert ainactionsbasedonawirelessclient’sMAC
address.YoucanconfigureTheMAClistcanbeconfiguredtoallowordenynetworkaccessto
specificclients.
– SystemDefaultspecifiesadefault
actionforallunknownMACaddresses(thatis,thosenot
listedinthelocalMACdatabase).
‐ DenyblocksaccessforallMACaddressesexceptthoselistedinthelocaldatabaseas
“A l l o w ” .
‐ AllowpermitsaccessforallMACaddressesexceptthoselistedinthelocaldatabaseas
“Deny”.