Specifications

Configuring AAA for Users of Third-Party APs
17-38 Configuring AAA for Network Users
Requirements
Third-Party AP Requirements
•ThethirdpartyAPmustbeconnectedtotheRoamAboutSwitchthroughawiredLayer2
link.MSScannotprovidedataservicesiftheAPandR oamAboutSwitchareindifferentLayer
3subnets.
•TheAPmustbeconfiguredastheRoamAboutSwitch’sRADIUSclient.
•TheAPmustbeconfiguredsothat
alltrafficforagivenSSIDismappedtothesame802.1Q
taggedVLAN.IftheAPhasmultipleSSIDs,eachSSIDmustuseadifferenttagvalue.
•TheAPmustbeconfiguredtosendthefollowinginformationinaRADIUSaccessrequest,for
eachuserwhowantstoconnectto
theWLANthroughtheRoamAboutSwitch:
–SSIDrequestedbytheuser.TheSSIDcanbeattachedtotheendofthecalledstationid
(perCongdon),orcanbeinaVSA(forexample,ciscovsa:ssid=r12cisco1).
–Callingstationidthatincludesthe usersMACaddress.TheMACaddresscan
beinany
ofthefollowingformats:
Separatedbycolons(forexample,AA:BB:CC:DD:EE:FF)
Separatedbydashes(forexample,AABBCCDDEEFF)
Separatedbydots(forexample,AABB.CCDD.EEFF)
Username
•TheAPmustbeconfiguredtosendaRADIUSstopaccountingrecordwhenauserssession
ends.
RoamAbout Switch Requirements
•TheRoamAboutSwitchportconnectedtothethirdpartyAPmustbeconfiguredasawired
authenticationport.IfSSIDtrafficfromtheAPistagged,thesameVLANtagvaluemustbe
usedonthewiredauthenticationport.
•AMACauthenticationrulemustbeconfiguredtoauthenticatetheAP.
•TheRoamAbout
SwitchmustbeconfiguredasaRADIUSproxyfortheAP.TheRoamAbout
SwitchisaRADIUSservertotheAPbutremainsaRADIUSclienttotherealRADIUSservers.
•AnauthenticationproxyrulemustbeconfiguredfortheAP’susers.Therulematchesbased
onSSIDandusername,and
selectstheauthenticationmethod(aRADIUSservergroup)for
proxying.
Note: The RoamAbout Switch system IP address must be the same as the IP address configured on
the VLAN that contains the proxy port.