User guide
Canopy System User Guide Using RADIUS for centralized AP and SM
user name and password management
pmp-0229 (Mar 2013)
457
Figure 157 User Authentication tab of the SM
Table 68: SM User Authentication attributes
Attribute Meaning
User Authentication Mode
•
Local: The local SM is checked for accounts. No centralized
RADIUS
accounting (access control)
is
performed.
•
Remote: Authentication by the centralized RADIUS server
is
required to gain access to the SM if the SM is registered to an
AP
that
has RADIUS AAA Authentication Mode selected. For up to
2
minutes
a test pattern will be displayed until the server responds
or
times
out.
•
Remote then Local: Authentication using the centralized
RADIUS
server is attempted. If the server sends a reject message, then
the
setting
of Allow Local Login after Reject from AAA determines
if
the local
user database is checked or not. If the configured
servers
do
not respond
within 2 minutes, then the local user database
is
used. The successful
login method is displayed in the
navigation
column of the SM.
Allow Local Login after
Reject from AAA
If a user authentication is rejected from the AAA server, the user will be
allowed to login locally to the radio’s management interface.
Accounting Messages
• disable – no accounting messages are sent to the RADIUS server
• deviceAccess – accounting messages are sent to the RADIUS server
regarding device access