User's Manual
RLX2 Industrial Hotspot Series
Page108of208 ProSoftTechnology,Inc.
February5,2015
Field
Description
AuthenticationMethod:
TheAuthenticationMethod,sometimesreferredtoasthe‘innerprotocol’
definesthemechanismusedtoauthenticatetheSupplicantoftheRLX2with
theRADIUSserver.Thefollowingauthenticationmethodsaresupported:
MS‐CHAPv2–Microsoft’sversionofthe‘ChallengeHandshake
AuthenticationProtocol’(CHAP).Thismethodprovidesmutual
authenticationbetweentheSupplicantandtheRADIUSserver,
usingaus
ernameandpasswordandchallengetextresponses.
MD5–‘MessageDigest’cryptographichashingalgorithmbasedon
ausernameandpassword.
TLS–Certificate‐basedinnerauthenticationprotocol.
UserName:
EntertheUserNameoftheaccountthatistobeauthenticated.Whenusing
EAP‐TLS,thisrepresentstheidentityoftheentityassignedtothedevice
certificatebeingused.
Password:
RequiredfieldwhenusingEAP‐PEAPorEAP‐TTLSwithMS‐CHAPv2orMD5.
Enterthepasswordoftheaccountcorrespondingtotheusername.
Certificates
OpensawindowthatdisplaysthecurrentcertificatesinstalledintheRLX2,
andprovidescontrolstouploadnewcertificatesintotheunit.Note:The
RLX2doesnotshipwithanycertificatesinstalled.
CertificateManagement
WhenusingEnterprise‐levelsecurity,someEAPmethodsrequiretheuseofX.509
certificates.TheCertificateManagementwebpageallowstheuploadingofcertificate
filestotheRLX2.
Therearetwocertificatetypes;acertificatefroma‘CertificationAuthority’usedto
authenticatetheRADIUSservertotheRLX2supplicant,anddeviceorcli
entcertificate
createdbytheRADIUSserverfortheRLX2.TheRLX2isabletoholdoneofeach
certificatetype.
IfPEAPauthenticationisused,you’llne edaCA Certificate(toauthenti catetheRADIUS
server)andausernameandpassword.
IfEAP‐TLSisused,you’llneedaCACertificate,aClientCertificateandPrivateKe
y
(containedinasinglep12file)toauthenticatetheclient.Thep12fileisencryptedand
requiresapassword.
TheITpersonwillprovideyouwiththeappropriatefilesthatyou’llneedtoloadtothe
RLX2Repeater.
Thefollowingcontrolsareusedforuploadingacer
tificate: