Specifications

Security
RoamAbout Access Point 3000 Configuration Guide 4-67
Whenyouenable802.1x,youcanalsoenablethebroadcastandsessionkeyrotationintervals.
BroadcastKeyRefreshRatesetstheintervalatwhichthebroadcastkeysarerefreshedfor
stationsusing802.1xdynamickeying.(Range:01440minutes;Default:0meansdisabled)
SessionKeyRefreshRatespecifiestheintervalat
whichtheaccesspointrefreshesunicast
sessionkeysforassociatedclients.(Range:01440minutes;Default:0meansdisabled)
802.1xSessionTimeoutsetsthetimeperiodafterwhichaconnectedclientmustbere
authenticated.Duringthereauthenticationprocessofverifyingtheclient’scredentialson
theRADIUSserver,the
clientremainsconnectedtothenetwork.Onlyifreauthentication
failsisnetworkaccessblocked.Default:60minutes.
MACAuthenticationconfigureshowthe accesspointusesMACaddressestoauthorize
wirelessclientstoaccessthenetwork.Thisauthenticationmethodprovidesabasiclevelof
authenticationforwirelessclientsattemptingtogain
accesstothenetwork.Adatabaseof
authorizedMACaddressescanbestoredlocal ly ontheAccessPoint3000orremotelyona
centralRADIUSserver.(Default:LocalMAC)
LocalMACindicatesthattheMACaddressoftheassociatingstationiscomparedagainst
thelocaldatabasestoredontheaccess
point.LocalMACAuthenticationenablesthelocal
databasetobesetup.
RADIUSMACspecifiesthattheMA Caddressoftheassociatingstationissenttoa
configuredRADIUSserverforauthentication.
TouseaRADIUSauthentica tionserverforMACaddressau thentication,theaccesspoint
mustbeconfiguredtousea
RADIUSserver,seeRADIUS(page49).
Disablespecifiesthattheaccesspointdoesnotcheckanassociatingstation’sMACaddress.
IfyouspecifyRADIUSMACforthisdefaultinterfaceorVAP,youmustspecifythefollowing
parameters:
MACAuthenticationPasswordspecifiestheauthenticationpasswordthisradiointerfaceor
VAP
sendstotheRADIUSservertoauthenticateMACaddresses.
MACAuthenticationSessionTimeoutspecif iestheamountoftimeafterwhichyouwanta
MACauthenticationsessiontotimeoutbetweentheAPandtheRADIUSserver.
IfyouspecifyLocalMACforthisdefaultinterfaceorVAP,youmustspecifyLocal
MAC
AuthenticationsettingsthatconfigurethelocalMACauthenticationdatabase.TheMAC
databaseprovidesamechanismtotakecert ainactionsbasedonawirelessclient’sMAC
address.YoucanconfigureTheMAClistcanbeconfiguredtoallowordenynetworkaccessto
specificclients.
SystemDefaultspecifiesadefault
actionforallunknownMACaddresses(thatis,thosenot
listedinthelocalMACdatabase).
DenyblocksaccessforallMACaddressesexceptthoselistedinthelocaldatabaseas
“A l l o w .
AllowpermitsaccessforallMACaddressesexceptthoselistedinthelocaldatabaseas
“Deny”.