User`s guide

LAN-Cell 2 User’s Guide
283
CHAPTER 12
Authentication Server Screens
12.1 Overview
This chapter discusses how to configure the LAN-Cell’s authentication server feature.
A LAN-Cell set to be a VPN extended authentication server can use either the local user
database internal to the LAN-Cell or an external RADIUS server for an unlimited number of
users. The LAN-Cell uses the same local user database for VPN extended authentication and
wireless LAN security. See Appendix E on page 617 for more information about RADIUS.
12.1.1 What You Can Do in the Authentication Server Screens
Use the Local User Database Screen (Section 12.2 on page 284) to configure your LAN-
Cell’s list of local user profiles.
Use the RADIUS Screen (Section 12.3 on page 285) to configure external RADIUS
server settings.
12.1.2 What You Need To Know About Authentication Server
Local User Database
By storing user profiles locally on the LAN-Cell, your LAN-Cell is able to authenticate users
without interacting with a network RADIUS server. However, there is a limit on the number of
users you may authenticate in this way.
RADIUS
The LAN-Cell can use an external RADIUS server to authenticate an unlimited number of
users. RADIUS is based on a client-server model that supports authentication and accounting,
where access point is the client and the server is the RADIUS server.
• Authentication
Determines the identity of the users.
• Accounting
Keeps track of the client’s network activity.
RADIUS user is a simple package exchange in which your LAN-Cell acts as a message relay
between the wireless station and the network RADIUS server.