Specifications
RoamAbout Mobility System Software Configuration Guide 17-1
17
Configuring AAA for Network Users
About AAA for Network Users
Networkusersincludethefol lowing typesofusers:
•Wirelessusers—UserswhoaccessthenetworkbyassociatingwithanSSIDonan Enterasys
radio.
•Wiredauthenticationusers—UserswhoaccessthenetworkoveranEthernetconnectiontoa
RoamAboutswitchportthatisconfiguredasawiredauthentication(wired‐auth)port.
Youcan
configureauthenticationrulesforeachtypeofuser,onanindividualSSIDorwired
authenticationportbasis.MSSauthenticatesusersbasedonuserinformationonRADIUSservers
orintheRoamAboutswitch’slocaldatabase.TheRADIUSserversorlocaldatabaseauthorize
successfullyauthenticatedusersforspecificnetworkaccess,includingVLANmembership.
Optionally,youalsocanconfigureaccountingrulestotracknetworkaccessinformation.
ThefollowingsectionsdescribetheMSSauthentication,authorization,andaccounting(AAA)
featuresinmoredetail.
For information about... Refer to page...
About AAA for Network Users 17-1
AAA Tools for Network Users 17-8
Configuring 802.1X Authentication 17-13
Configuring Authentication and Authorization by MAC Address 17-19
Configuring Web Web Portal WebAAA 17-22
Configuring Last-Resort Access 17-36
Assigning Authorization Attributes 17-42
Overriding or Adding Attributes Locally with a Location Policy 17-52
Configuring Accounting for Wireless Network Users 17-55
Displaying the AAA Configuration 17-60
Avoiding AAA Problems in Configuration Order 17-61
Configuring a Mobility Profile 17-63
Network User Configuration Scenarios 17-64