
147 | Authentication AOS-W Instant 6.3.1.1-4.0 | User Guide
Parameter Description
Directory, the value is sAMAccountName
Timeout Enter a value between 1 and 30 seconds. The default value is 5.
Retry count Enter a value between 1 and 5. The default value is 3.
l CPPMServer for AirGroup CoA — To configure a CPPM server used for AirGroup CoA (Change of
Authorization), select the CoA only check box. The RADIUSserver is automatically selected.
Parameter Description
Name
Enter the name of the server.
IP address
Enter the IP address of the server.
Air Group CoA port
Enter a port number for sending AirGroup CoA on a different port than on the
standard CoA port. The default value is 5999.
Shared key
Enter a shared key for communicating with the external RADIUS server.
Retype key Re-enter the shared key.
Table 29:
CPPM Server Configuration Parameters for AirGroupCoA
4. Click OK.
The CPPM server acts as a RADIUS server and asynchronously provides the AirGroup parameters for
the client device including shared user, role, and location.
To assign the RADIUSauthentication server to a network profile, select the newly added server when configuring
security settings for a wireless or wired network profile.
You can also add an external RADIUSserver by selecting New for Authentication Server when
configuring a WLAN or wired profile. For more information, see Configuring Security Settings for a WLAN
SSID Profile on page 90 and Configuring Security Settings for a Wired Profile on page 104.
In the CLI
To configure a RADIUS server:
(Instant Access Point)(config)# wlan auth-server <profile-name>
(Instant Access Point)(Auth Server <profile-name>)# ip <IP-address>
(Instant Access Point)(Auth Server <profile-name>)# key <key>
(Instant Access Point)(Auth Server <profile-name>)# port <port>
(Instant Access Point)(Auth Server <profile-name>)# acctport <port>
(Instant Access Point)(Auth Server <profile-name>)# nas-id <NAS-ID>
(Instant Access Point)(Auth Server <profile-name>)# nas-ip <NAS-IP-address>
(Instant Access Point)(Auth Server <profile-name>)# timeout <seconds>
(Instant Access Point)(Auth Server <profile-name>)# retry-count <number>
(Instant Access Point)(Auth Server <profile-name>)# rfc3576
(Instant Access Point)(Auth Server <profile-name>)# deadtime <minutes>
(Instant Access Point)(Auth Server <profile-name>)# drp-ip <IP-address> <mask> vlan <vlan>
gateway <gateway-IP-address)
(Instant Access Point)(Auth Server <profile-name>)# end
(Instant Access Point)# commit apply
Kommentare zu diesen Handbüchern