Technical data
xii Meru System Director Configuration Guide © 2012 Meru Networks, Inc.
Configure RSA SecurID . . . . . . . . . . . . . . . . . . . 139
Configure MAC Filtering . . . . . . . . . . . . . . . . . . . 140
Configure MAC Filtering . . . . . . . . . . . . . . . . . . 141
Configure a Deny MAC Filtering List . . . . . . . . . . . . . 142
Configure a Remote Radius Server for MAC Filtering . . . . . . . . 143
Configure an ESS Profile for MAC Filtering . . . . . . . . . . . . 144
Security Certificates . . . . . . . . . . . . . . . . . . . . 144
Generate a CSR on a Controller . . . . . . . . . . . . . . . 145
Import the Certificate . . . . . . . . . . . . . . . . . . . 145
Assign a Server Certificate to an Application . . . . . . . . . . . 146
Troubleshooting Certificates . . . . . . . . . . . . . . . . 147
Chapter 9
Authentication . . . . . . . . . . . . . . . . . . . . . . 149
Radius Authentication . . . . . . . . . . . . . . . . . . . . 149
Conceptual 802.1X Model for Radius Authentication . . . . . . . . 149
Configure Radius Authentication for Users With the Web UI . . . . . . 150
Configure Radius Authentication for Administrators With the Web UI . . 151
Configure Radius Authentication for Administrators With the CLI . . . . 152
CLI Example for Setting Authentication Mode to Radius . . . . . . 152
Radius Authentication Attributes . . . . . . . . . . . . . . . 153
Attributes for 802.1X . . . . . . . . . . . . . . . . . . 153
Radius Accounting for Clients . . . . . . . . . . . . . . . . 154
Configure Radius Accounting for Captive Portal . . . . . . . . . . 158
Radius-Based ESS Profile Restriction . . . . . . . . . . . . . . 158
TACACS+ Authentication . . . . . . . . . . . . . . . . . . . 159
Configure TACACS+ Authentication Mode with the CLI . . . . . . . . 160
CLI Example for Setting Authentication Mode to TACACS+ . . . . . 160
Configure TACACS+ Authentication Mode with the Web UI . . . . . . 161
Local Admin Authentication . . . . . . . . . . . . . . . . . . 162
Configure an Admin for Local Authentication Mode With the CLI . . . . 162
CLI Example for Configuring a Local Admin . . . . . . . . . . 163
Configure Local Authentication and Add an Admin with the Web UI . . . 163
802.1X Authentication . . . . . . . . . . . . . . . . . . . . 165
802.1X Components . . . . . . . . . . . . . . . . . . . 165
About the EAP Types . . . . . . . . . . . . . . . . . . . 165
EAP-TLS . . . . . . . . . . . . . . . . . . . . . . 166
EAP-TTLS (Tunneled Transport Layer Security) . . . . . . . . . 166
LEAP (Lightweight Extensible Authentication Protocol) . . . . . . 166
PEAP (Protected Extensible Authentication Protocol) . . . . . . . 166
Chapter 10
Captive Portals for Temporary Users . . . . . . . . . . . . 169
Configuring Meru Captive Portal . . . . . . . . . . . . . . . . 169
Optionally Customize and Use Your Own HTML Pages . . . . . . . . 170
Create Custom Pages . . . . . . . . . . . . . . . . . . 171
Implement New Custom HTML Files Using the CLI . . . . . . . . 172
Implement New Custom HTML Files Using the GUI . . . . . . . . 173
Configure Meru Captive Portal with the CLI . . . . . . . . . . . 175
Create Meru Captive Portal Guest User IDs Locally . . . . . . . . . 176