Specifications
About AAA for Network Users
RoamAbout Mobility System Software Configuration Guide 17-5
SSID Name “Any”
Inauthenticationrulesforwirelessaccess,youcanspecifythenameanyforthe SSID.Thisvalueis
awildcardthatmatchesonanySSIDstringrequestedbytheuser.
For802.1XandWebAAArulesthatmatchonSSIDany,MSScheckstheRADIUSserversorlocal
databaseforthe
username(andpassword,ifapplicable)enteredbytheuser.Iftheuser
informationmatches,MSSgrantsaccesstotheSSIDrequestedbytheuser,regardlessofwhich
SSIDnameitis.
ForMACauthentica tionrulesthatmatchonSSIDany,MSScheckstheRADIUSserversorlocal
databaseforthe
MACaddress(andpassword,ifapplicable)oftheuser’sdevice.Iftheaddress
matches,MSSgrantsaccesstotheSSIDrequestedbytheuser,regardlessofwhichSSIDnameitis.
However,inalast‐resortauthenticationruleforwirelessaccess,iftheSSIDnameinthe
authenticationruleisany
,MSScheckstheRADIUSserversorlocaldatabaseforusernamelast‐
resort‐any,exactlyasspelledhere.IfcheckingRADIUS,MSSalsochecksforapassword.Accessis
grantedonlyifthisusername(andpassword,ifapplicable)isfound.Otherwise,accessisdenied.
Last-Resort Processing
Whenauserwithoutausernameorpasswordrequestswirelessaccess,MSSchecksthe
configurationforalast‐resortauthenticationrulethatmatchesontheSSID.Iftheconfiguration
containstherule,MSSchecksthelocaldatabaseforusernamelast‐resort‐ssid,wheressidisthe
SSIDrequestedbythe
user.TheguestuserisgrantedaccessonlyifthedatabaseorRADIUSserver
groupcontainslast‐resort‐ssidfortheSSIDrequestedbytheuser.Otherwise,accessisdenied.
Thisprocessingofthelast‐resortusernameisdifferentfrom802.1X,MAC,orWebAAA,where
MSSchecksfortheexactusername
orMACaddress(andpassword,ifapplicable)oftheuser.MSS
doesnotappendtheSSIDtotheusername(orMACaddress)for802.1X,Web,orMAC
authentication.
User Credential Requirements
TheusercredentialsthatMSSchecksforonRADIUSserversorinthelocaldatabasediffer
dependingonthetypeofauthenticationrulethatmatchesontheSSIDorwiredaccessrequested
bytheuser.
•Forausertobesuccessfullyauthenticatedbyan802.1XorWebAAArule,theusernameand
passwordenteredbytheusermustbeconfiguredontheRADIUSserversusedbythe
authenticationruleorintheswitch’slocaldatabase,ifthelocaldatabaseisusedbytherule.
•ForausertobesuccessfullyauthenticatedbasedontheMACaddres softheuser’sdevice,the
MACaddress
mustbeconfiguredontheRADIUSserversusedbytheauthenticationruleor
intheswitch’slocaldatabase,ifthelocaldatabaseisusedbytherule.IftheMACaddressis
configuredinthelocaldatabase,nopasswordisrequired.However,sinceRADIUSrequiresa
password,iftheMACaddress
isontheRADIUSserver,MSSchecksforapassword.The
defaultwell‐knownpasswordisEnterasysbutisconfigurable.(Thesamepasswordappliesto
last‐resortusers.)
•Forausertobesuccessfullyauthenticatedforlast‐resortaccess,theRADIUSseversorlocal
database(whichevermethodisusedbythe
last‐resortauthenticationrule),mustcontaina
usernamedlast‐resort‐wired(forwiredauthenticationaccess)orlast‐resort‐ssid,wheressidis
theSSIDrequestedbytheuser.Ifthematchinglast‐resortuserisconfiguredinthelocal
database,nopasswordisrequired.However,sinceRADIUSrequiresa
password,ifthe
matchinglast‐resortuserisontheRADIUSserver,MSSchecksforapassword.