Specifications

About AAA for Network Users
RoamAbout Mobility System Software Configuration Guide 17-5
SSID Name “Any”
Inauthenticationrulesforwirelessaccess,youcanspecifythenameanyforthe SSID.Thisvalueis
awildcardthatmatchesonanySSIDstringrequestedbytheuser.
For802.1XandWebAAArulesthatmatchonSSIDany,MSScheckstheRADIUSserversorlocal
databaseforthe
username(andpassword,ifapplicable)enteredbytheuser.Iftheuser
informationmatches,MSSgrantsaccesstotheSSIDrequestedbytheuser,regardlessofwhich
SSIDnameitis.
ForMACauthentica tionrulesthatmatchonSSIDany,MSScheckstheRADIUSserversorlocal
databaseforthe
MACaddress(andpassword,ifapplicable)oftheusersdevice.Iftheaddress
matches,MSSgrantsaccesstotheSSIDrequestedbytheuser,regardlessofwhichSSIDnameitis.
However,inalastresortauthenticationruleforwirelessaccess,iftheSSIDnameinthe
authenticationruleisany
,MSScheckstheRADIUSserversorlocaldatabaseforusernamelast
resortany,exactlyasspelledhere.IfcheckingRADIUS,MSSalsochecksforapassword.Accessis
grantedonlyifthisusername(andpassword,ifapplicable)isfound.Otherwise,accessisdenied.
Last-Resort Processing
Whenauserwithoutausernameorpasswordrequestswirelessaccess,MSSchecksthe
configurationforalastresortauthenticationrulethatmatchesontheSSID.Iftheconfiguration
containstherule,MSSchecksthelocaldatabaseforusernamelastresortssid,wheressidisthe
SSIDrequestedbythe
user.TheguestuserisgrantedaccessonlyifthedatabaseorRADIUSserver
groupcontainslastresortssidfortheSSIDrequestedbytheuser.Otherwise,accessisdenied.
Thisprocessingofthelastresortusernameisdifferentfrom802.1X,MAC,orWebAAA,where
MSSchecksfortheexactusername
orMACaddress(andpassword,ifapplicable)oftheuser.MSS
doesnotappendtheSSIDtotheusername(orMACaddress)for802.1X,Web,orMAC
authentication.
User Credential Requirements
TheusercredentialsthatMSSchecksforonRADIUSserversorinthelocaldatabasediffer
dependingonthetypeofauthenticationrulethatmatchesontheSSIDorwiredaccessrequested
bytheuser.
•Forausertobesuccessfullyauthenticatedbyan802.1XorWebAAArule,theusernameand
passwordenteredbytheusermustbeconfiguredontheRADIUSserversusedbythe
authenticationruleorintheswitch’slocaldatabase,ifthelocaldatabaseisusedbytherule.
•ForausertobesuccessfullyauthenticatedbasedontheMACaddres softheusersdevice,the
MACaddress
mustbeconfiguredontheRADIUSserversusedbytheauthenticationruleor
intheswitch’slocaldatabase,ifthelocaldatabaseisusedbytherule.IftheMACaddressis
configuredinthelocaldatabase,nopasswordisrequired.However,sinceRADIUSrequiresa
password,iftheMACaddress
isontheRADIUSserver,MSSchecksforapassword.The
defaultwellknownpasswordisEnterasysbutisconfigurable.(Thesamepasswordappliesto
lastresortusers.)
•Forausertobesuccessfullyauthenticatedforlastresortaccess,theRADIUSseversorlocal
database(whichevermethodisusedbythe
lastresortauthenticationrule),mustcontaina
usernamedlastresortwired(forwiredauthenticationaccess)orlastresortssid,wheressidis
theSSIDrequestedbytheuser.Ifthematchinglastresortuserisconfiguredinthelocal
database,nopasswordisrequired.However,sinceRADIUSrequiresa
password,ifthe
matchinglastresortuserisontheRADIUSserver,MSSchecksforapassword.