User's Manual

hwc_vnsconfiguration.fm
Virtual Network configuration
Authentication for a VNS
A31003-W1050-U100-2-7619,
March 2008
HiPath Wireless Controller, Access Points and Convergence Software V5 R1 , C20/C2400 User Guide 189
•VNSs
SSID
The Vendor Specific Attributes must be defined on the RADIUS server.
11. If applicable, select the Set as primary server checkbox.
12. To save your changes, click Save.
Note: If you have already assigned a server to either MAC-based
authentication or accounting, and you want to use it again for authentication,
highlight its name in the list next to the Up and Down buttons and select the
Use server for Authentication checkbox. The server’s default information is
displayed.
6.6.4 Defining MAC-based authentication for a VNS
MAC-based authentication enables network access to be restricted to specific
devices by MAC address. The HiPath Wireless Controller queries a RADIUS
server for a MAC address when a wireless client attempts to connect to the
network.
MAC-based authentication can be set up on any type of VNS, in addition to the
Captive Portal or AAA authentication. To set up a RADIUS server for MAC-based
authentication, you must set up a user account with UserID=MAC and
Password=MAC (or a password defined by the administrator) for each user.
Specifying a MAC address format and policy depends on which RADIUS server
is being used.
If MAC-based authentication is to be used in conjunction with the 802.1x or
Captive Portal authentication, an additional account with a real UserID and
Password must also be set up on the RADIUS server.
MAC-based authentication responses may indicate to the HiPath Wireless
Controller what VNS a user should be assigned to. Authentication (if enabled) can
apply on every roam.
To define MAC-based authentication for a VNS:
1. From the main menu, click Virtual Network Configuration. The Virtual
Network Configuration page is displayed.
2. In the left pane Virtual Networks list, click the VNS you want to set up
MAC-based authentication for. The Topology tab is displayed.
3. Click the Auth & Acct tab. On the Auth & Acct tab, there are three options:
•Auth – Use to define authentication servers.