User's Manual

RLX2 Industrial Hotspot Series
Page108of208 ProSoftTechnology,Inc.
February5,2015
Field
Description
AuthenticationMethod:
TheAuthenticationMethod,sometimesreferredtoasthe‘innerprotocol’
definesthemechanismusedtoauthenticatetheSupplicantoftheRLX2with
theRADIUSserver.Thefollowingauthenticationmethodsaresupported:
MSCHAPv2Microsoft’sversionofthe‘ChallengeHandshake
AuthenticationProtocol’(CHAP).Thismethodprovidesmutual
authenticationbetweentheSupplicantandtheRADIUSserver,
usingaus
ernameandpasswordandchallengetextresponses.
MD5‘MessageDigest’cryptographichashingalgorithmbasedon
ausernameandpassword.
TLSCertificatebasedinnerauthenticationprotocol.
UserName:
EntertheUserNameoftheaccountthatistobeauthenticated.Whenusing
EAPTLS,thisrepresentstheidentityoftheentityassignedtothedevice
certificatebeingused.
Password:
RequiredfieldwhenusingEAPPEAPorEAPTTLSwithMSCHAPv2orMD5.
Enterthepasswordoftheaccountcorrespondingtotheusername.
Certificates
OpensawindowthatdisplaysthecurrentcertificatesinstalledintheRLX2,
andprovidescontrolstouploadnewcertificatesintotheunit.Note:The
RLX2doesnotshipwithanycertificatesinstalled.
CertificateManagement
WhenusingEnterpriselevelsecurity,someEAPmethodsrequiretheuseofX.509
certificates.TheCertificateManagementwebpageallowstheuploadingofcertificate
filestotheRLX2.
Therearetwocertificatetypes;acertificatefroma‘CertificationAuthority’usedto
authenticatetheRADIUSservertotheRLX2supplicant,anddeviceorcli
entcertificate
createdbytheRADIUSserverfortheRLX2.TheRLX2isabletoholdoneofeach
certificatetype.
IfPEAPauthenticationisused,you’llne edaCA Certificate(toauthenti catetheRADIUS
server)andausernameandpassword.
IfEAPTLSisused,you’llneedaCACertificate,aClientCertificateandPrivateKe
y
(containedinasinglep12file)toauthenticatetheclient.Thep12fileisencryptedand
requiresapassword.
TheITpersonwillprovideyouwiththeappropriatefilesthatyou’llneedtoloadtothe
RLX2Repeater.
Thefollowingcontrolsareusedforuploadingacer
tificate: