User`s guide
Configuration
2-8 Planning and Managing Your Wireless Network
Foreachserviceyouwanttoprovide,youconfigurethefollowingitemsinaserviceprofile:
•TheSSIDname
•SSIDadvertisement(whethertheSSIDnameisbeaconed)
•WhethertheSSIDnameisencryptedorclear(notencrypted)
•Webpage(ifusingWebAAA)
•Multipleencryptionchoices(Dynamic/staticWEP,WPA,WEP+WPA,802.11i)
Theencryption
youusedependsonthetypeofservicesyouareoffering.Employeeaccessis
typicallyencrypted,guestaccessistypicallyclear(noencryption),andmulti‐hostor“multiple
virtualizedservices”servicecanbeencrypted,witheachSSIDbeingmatchedwithitsownservice
profile.Ifservicesarebeingusedfor
customercorporateentities(e.g.differentairlinesonan
airportwirelessnet),thentheywouldprobablyuse802.1Xandstrongencryptionwithwebguest
accessfortheirairportclubguests.Iftheservicesarebeingusedtoadvertisemultiplewireless
serviceproviders(WISP),suchasT‐Mobile
TM
,Wayport®, andBoingoWireless
TM
,thenthese
serviceswouldprobablybecompletelyopen.However,theywouldlikelybeassignedtotheir
owndedicatedsubnetcontainingtheirproxyserver/billinggateway.
AAA Security Configuration
Anadministratorcancontrolthewayinwhichusersaccessthenetwork.Foreachserviceyou
provide,youcanconfigureuniqueauthentication,authorization,andaccounting(AAA)security
features,creatinganentirelyvirtualizedwirelessservice.Foreachservice,youconfigurethe
followingitems:
•Multipleauthenticationchoices(802.1X,Web,AAA,MACauthentication,Bonded
Auth,
open)
•AAAmethods(uptofourRADIUSservergroups,oralocaldatabaseontheRoamAbout
switch)
Authentication
Authenticationisthemethodofdeterminingwhetherauserisallowedaccesstoyournetwork.
UserscanbeauthenticatedbyaRADIUSserver(pass‐through)orbytheRoamAboutswitchlocal
database(local).TheRoamAboutswi tch canalsoassisttheRADIUSserverbyperformingthe
ExtensibleAuthenticationProtocol(EAP)p rocessingfor
theserver(offload).
Toauthenticateusers,youwillneedtoconfigureuserseitherinthelocaldatabaseoronRADIUS
servers.Eachuserwillhaveausername,password,andRADIUSand/orvendor‐specificattributes
(VSAs).Youwillalsoneedtoconfigureauthenticationrules(802.1X,MAC,last‐resort,orweb
authentication).
Figure 2‐
4onpage 2‐9showsaflowchartrepresentingtheauthenticationprocess.Generally,
802.1Xauthenticationisattemptedfirst.Iftheuserfails,thenMACauthenticationisattempted.If
thisfails,thenlastresortandwebauthenticationisused.Foraserviceprofile,youspecifyeither
webauthentication,last‐resort,ornonein
theauth‐fall‐thrubox.Youcanonlyselectone.
Note: You also must configure AAA security configuration items for each service. For more
information, see “AAA Security Configuration” on page 2-8.