User's Guide

Table Of Contents
Virtual Network Services concepts
hwc_vnsintro.fm
Authentication for a VNS
9034530-02, March 2010
234 HiPath Wireless Controller, Access Points and Convergence Software V7.11, User Guide
enable users to supply their user name and password. The user name
and password are sent to the configured RADIUS server for
authentication.
External Captive Portal – External Captive Portal can be classified
under the following two categories:
External Captive Portal with Internal Authentication – After an
external server displays the Captive Portal Web page, the HiPath
Wireless Controller carries out the authentication and implements
policy.
External Captive Portal with External Authentication — After an
external server displays the Captive Portal Web page and carries out
the authentication, the HiPath Wireless Controller implements policy.
GuestPortal – A GuestPortal provides wireless device users with
temporary guest network services. A GuestPortal is serviced by a
GuestPortal-dedicated WLAN Service. For more information, see Section
6.5, “Working with a GuestPortal VNS”, on page 285.
Guest Splash – Guest Splash provides minimal authorization. Login
information is not required when the user is re-directed to the
authorization Web page. The user is only required to select a button and
authorization is approved. This typically could be used where the user is
expected to read and accept some terms and conditions before being
granted network access.
MAC-based authentication – The RADIUS server authorizes the client
device on the basis of its MAC address. After MAC-based authorization, an
authorized client can go through the selected authentication method for the
applied WLAN service (Captive Portal or 802.1x). If the client device fails the
authentication, the controller will inform the Wireless AP to disassociate the
client device.
MAC-based authentication enables network access to be restricted to
specific devices by MAC address. In addition to the other types of
authentication, when MAC-based authentication is employed, the HiPath
Wireless Controller queries a RADIUS server to determine if the wireless
client's MAC address is authorized to access the network.
802.1x authentication – The RADIUS server typically authenticates the
client device on the basis of a certificate. After the client device is
authenticated, it can optionally (if so configured) also go through the Captive
Portal authentication. If the client device fails the Captive Portal
authentication, the controller will inform the Wireless AP to disassociate the
client device.