Specifications

AAA Tools for Network Users
17-8 Configuring AAA for Network Users
AAA Tools for Network Users
Authenticationverifiesnetworkuseridentityandisrequiredbeforeanetworkuserisgranted
accesstothenetwork.ARoamAboutSwitchauthenticatesuseridentitybyusernamepassword
matching,digitalsignaturesandcertificates,orothermethods(forexample,byMACaddress).
Youmustdecidewhethertoauthentica tenetworkuserslocallyonthe
RoamAboutSwitch,
remotelyviaoneormoreexternalRADIUSservergroups,orbothlocallyandremotely.(For
servergroupdetails,seeConfiguringRADIUSServerGroupsonpage 186.)
“Globs” and Groups for Network User Classification
“Globbing”letsyouclassifyusersbyusernameorMACaddressfordifferentAAAtreatments.A
userglobisastringusedbyAAAandIEEE802.1XorWebAAAmethodstomatchauserorsetof
users.MACaddressglobsmatchauthenticationmethodstoaMACaddressorsetofMAC
addresses.UserglobsandMACaddressglobscanmakeuseofwildcards.Fordetails,seeUser
Globs,MACAddressGlobs,andVLANGlobsonpage 14.
AusergroupisanamedcollectionofusersorMACaddressessharingacommonauthorization
policy.Forexample,youmightgroupallusers
onthefirstfloorofbuilding 17intothegroupbldg
171stfloor,orgroupallusersintheITgroupintothegroupinfotechpeople.
Wildcard “Any” for SSID Matching
AuthenticationrulesforwirelessaccessincludetheSSIDname,andmustmatchontheSSIDname
requestedbytheuserforMSStoattempttoauthenticatethe userforthatSSID.Tomakean
authenticationrulematchananySSIDstring,specifytheSSIDnameasanyintherule.
AAA Methods for IEEE 802.1X and Web Network Access
ThefollowingAAAmethodsaresupportedbyEnterasys Networksfor802.1XandWebnetwork
accessmode:
•Clientcertificatesissuedbyacertificateauthority(CA)forauthentication.
(Forthismethod,youassignanauthenticationprotocoltoauser.Forprotocoldetails,see
IEEE802.1XExtensibleAuthenticationProtocolTypesonpage 1711.)
•TheRoamAbout
switch’slocaldatabaseofusernamesandusergroupsforauthentication.
(Forconfigurationdetails,seeAddingandClearingLocalUsersforAdministrativeAccess
onpage 38,AuthenticatingviaaLocalDatabaseonpage 1714,andAddingandClearing
MACUsersandUserGroupsLocallyonpage 1719.)
•Anamed
groupofRADIUSservers.TheRoamAboutSwitchsupportsuptofourserver
groups,whichcaneachcontainbetweenoneandfourservers.
(Forservergroupdetails,seeConfiguringRADIUSServerGroupsonpage 186.)
YoucanusethelocaldatabaseorRADIUSserversforMACandlastresortaccessas
well.Ifyou
useRADIUSservers,makesureyouconfigurethepasswordfortheMACaddressorlastresort
userasnopassword.(Thisisthedefaultauthorizationpassword.Tochangeit,seeChangingthe
MACAuthorizationPasswordforRADIUSonpage 1721.)