User's Guide

Table Of Contents
Configuring a VNS
hwc_vnsconfiguration.fm
Configuring WLAN Services
9034530-02, March 2010
324 HiPath Wireless Controller, Access Points and Convergence Software V7.11, User Guide
AP. The wireless device's client utility must support 802.1x. The user's EAP
packets request for network access along with login identification or a user profile
is forwarded by the HiPath Wireless Controller to a RADIUS server.
Captive Portal authentication
For Captive Portal authentication, the wireless device connects to the network,
but can only access the specific network destinations defined in the non-
authenticated filter. For more information, see Section 6.10.2, “About filtering
rules”, on page 352. One of these destinations should be a server, either internal
or external, which presents a Web login page — the Captive Portal. The wireless
device user must input an ID and a password. This request for authentication is
sent by the HiPath Wireless Controller to a RADIUS server or other authentication
server. Based on the permissions returned from the authentication server, the
HiPath Wireless Controller implements policy and allows the appropriate network
access.
Captive Portal authentication relies on a RADIUS server on the enterprise
network. There are three mechanisms by which Captive Portal authentication can
be carried out:
Internal Captive Portal – The HiPath Wireless Controller displays the
Captive Portal Web page, carries out the authentication, and implements
policy.
External Captive Portal – After an external server displays the Captive
Portal Web page and carries out the authentication, the HiPath Wireless
Controller implements policy.
External Captive Portal with internal authentication – After an external
server displays the Captive Portal Web page, the HiPath Wireless Controller
carries out the authentication and implements policy.
RADIUS servers
RADIUS servers can perform the following for a WLAN Service:
Authentication – RADIUS servers are configured to provide authentication.
MAC authentication – RADIUS servers are configured to provide MAC-
based authentication.
Accounting – RADIUS servers are configured to provide accounting
services.
MAC-based authentication
MAC-based authentication enables network access to be restricted to specific
devices by MAC address. The HiPath Wireless Controller queries a RADIUS
server for a MAC address when a wireless client attempts to connect to the
network.