User`s guide

Configuration
2-8 Planning and Managing Your Wireless Network
Foreachserviceyouwanttoprovide,youconfigurethefollowingitemsinaserviceprofile:
•TheSSIDname
•SSIDadvertisement(whethertheSSIDnameisbeaconed)
•WhethertheSSIDnameisencryptedorclear(notencrypted)
•Webpage(ifusingWebAAA)
•Multipleencryptionchoices(Dynamic/staticWEP,WPA,WEP+WPA,802.11i)
Theencryption
youusedependsonthetypeofservicesyouareoffering.Employeeaccessis
typicallyencrypted,guestaccessistypicallyclear(noencryption),andmultihostor“multiple
virtualizedservicesservicecanbeencrypted,witheachSSIDbeingmatchedwithitsownservice
profile.Ifservicesarebeingusedfor
customercorporateentities(e.g.differentairlinesonan
airportwirelessnet),thentheywouldprobablyuse802.1Xandstrongencryptionwithwebguest
accessfortheirairportclubguests.Iftheservicesarebeingusedtoadvertisemultiplewireless
serviceproviders(WISP),suchasTMobile
TM
,Wayport®, andBoingoWireless
TM
,thenthese
serviceswouldprobablybecompletelyopen.However,theywouldlikelybeassignedtotheir
owndedicatedsubnetcontainingtheirproxyserver/billinggateway.
AAA Security Configuration
Anadministratorcancontrolthewayinwhichusersaccessthenetwork.Foreachserviceyou
provide,youcanconfigureuniqueauthentication,authorization,andaccounting(AAA)security
features,creatinganentirelyvirtualizedwirelessservice.Foreachservice,youconfigurethe
followingitems:
•Multipleauthenticationchoices(802.1X,Web,AAA,MACauthentication,Bonded
Auth,
open)
•AAAmethods(uptofourRADIUSservergroups,oralocaldatabaseontheRoamAbout
switch)
Authentication
Authenticationisthemethodofdeterminingwhetherauserisallowedaccesstoyournetwork.
UserscanbeauthenticatedbyaRADIUSserver(passthrough)orbytheRoamAboutswitchlocal
database(local).TheRoamAboutswi tch canalsoassisttheRADIUSserverbyperformingthe
ExtensibleAuthenticationProtocol(EAP)p rocessingfor
theserver(offload).
Toauthenticateusers,youwillneedtoconfigureuserseitherinthelocaldatabaseoronRADIUS
servers.Eachuserwillhaveausername,password,andRADIUSand/orvendorspecificattributes
(VSAs).Youwillalsoneedtoconfigureauthenticationrules(802.1X,MAC,lastresort,orweb
authentication).
Figure 2
4onpage 29showsaflowchartrepresentingtheauthenticationprocess.Generally,
802.1Xauthenticationisattemptedfirst.Iftheuserfails,thenMACauthenticationisattempted.If
thisfails,thenlastresortandwebauthenticationisused.Foraserviceprofile,youspecifyeither
webauthentication,lastresort,ornonein
theauthfallthrubox.Youcanonlyselectone.
Note: You also must configure AAA security configuration items for each service. For more
information, see “AAA Security Configuration” on page 2-8.