Specifications
AAA Tools for Network Users
17-8 Configuring AAA for Network Users
AAA Tools for Network Users
Authenticationverifiesnetworkuseridentityandisrequiredbeforeanetworkuserisgranted
accesstothenetwork.ARoamAboutSwitchauthenticatesuseridentitybyusername‐password
matching,digitalsignaturesandcertificates,orothermethods(forexample,byMACaddress).
Youmustdecidewhethertoauthentica tenetworkuserslocallyonthe
RoamAboutSwitch,
remotelyviaoneormoreexternalRADIUSservergroups,orbothlocallyandremotely.(For
servergroupdetails,see“ConfiguringRADIUSServerGroups”onpage 18‐6.)
“Globs” and Groups for Network User Classification
“Globbing”letsyouclassifyusersbyusernameorMACaddressfordifferentAAAtreatments.A
userglobisastringusedbyAAAandIEEE802.1XorWebAAAmethodstomatchauserorsetof
users.MACaddressglobsmatchauthenticationmethodstoaMACaddressorsetofMAC
addresses.UserglobsandMACaddressglobscanmakeuseofwildcards.Fordetails,see“User
Globs,MACAddressGlobs,andVLANGlobs”onpage 1‐4.
AusergroupisanamedcollectionofusersorMACaddressessharingacommonauthorization
policy.Forexample,youmightgroupallusers
onthefirstfloorofbuilding 17intothegroupbldg‐
17‐1st‐floor,orgroupallusersintheITgroupintothegroupinfotech‐people.
Wildcard “Any” for SSID Matching
AuthenticationrulesforwirelessaccessincludetheSSIDname,andmustmatchontheSSIDname
requestedbytheuserforMSStoattempttoauthenticatethe userforthatSSID.Tomakean
authenticationrulematchananySSIDstring,specifytheSSIDnameasanyintherule.
AAA Methods for IEEE 802.1X and Web Network Access
ThefollowingAAAmethodsaresupportedbyEnterasys Networksfor802.1XandWebnetwork
accessmode:
•Clientcertificatesissuedbyacertificateauthority(CA)forauthentication.
(Forthismethod,youassignanauthenticationprotocoltoauser.Forprotocoldetails,see
“IEEE802.1XExtensibleAuthenticationProtocolTypes”onpage 17‐11.)
•TheRoamAbout
switch’slocaldatabaseofusernamesandusergroupsforauthentication.
(Forconfigurationdetails,see“AddingandClearingLocalUsersforAdministrativeAccess ”
onpage 3‐8,“AuthenticatingviaaLocalDatabase”onpage 17‐14,and“AddingandClearing
MACUsersandUserGroupsLocally”onpage 17‐19.)
•Anamed
groupofRADIUSservers.TheRoamAboutSwitchsupportsuptofourserver
groups,whichcaneachcontainbetweenoneandfourservers.
(Forservergroupdetails,see“ConfiguringRADIUSServerGroups”onpage 18‐6.)
YoucanusethelocaldatabaseorRADIUSserversforMACandlast‐resortaccessas
well.Ifyou
useRADIUSservers,makesureyouconfigurethepasswordfortheMACaddressorlast‐resort
userasnopassword.(Thisisthedefaultauthorizationpassword.Tochangeit,see“Changingthe
MACAuthorizationPasswordforRADIUS”onpage 17‐21.)