Alcatel-Lucent IAP93 Betriebsanweisung Seite 94

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 335
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 93
94 | Wireless Network Profiles AOS-W Instant 6.3.1.1-4.0 | User Guide
Parameter Description
Security Level
Type
Accounting To enable accounting, select Enabled from the Accounting drop-down list.
On setting this option to Enabled, APs post accounting information to the
RADIUS server at the specified Accounting interval.
Enterprise,
Personal, and Open
security levels.
Authentication
survivability
To enable authentication survivability, set Authentication survivability to
Enabled. Specify a value in hours for Cache timeout (global) to set the
duration after which the authenticated credentials in the cache must expire.
When the cache expires, the clients are required to authenticate again. You
can specify a value within range of 1 to 99 hours and the default value is 24
hours.
NOTE: The authentication survivability feature requires ClearPass Policy
Manager 6.0.2 or later, and is available only when the New server option is
selected authentication. On setting this parameter to Enabled, AOS-W
Instant authenticates the previously connected clients using EAP-PEAP
authentication even when connectivity to ClearPass Policy Manager is
temporarily lost. The Authentication survivability feature is not applicable
when a RADIUS server is configured as an internal server.
Enterprise security
level
MAC
authentication
To enable MAC address based authentication for Personal and Open
security levels, set MAC authentication to Enabled.
For Enterprise security level, the following options are available:
l Perform MAC authentication before 802.1X Select this check box to
use 802.1X authentication only when the MAC authentication is
successful.
l MAC authentication fail-thru On selecting this check box, the 802.1X
authentication is attempted when the MAC authentication fails.
Enterprise,
Personal, and Open
security levels.
Delimiter
character
Specify a character (for example, colon or dash) as a delimiter for MAC
address string. When configured, the OAW-IAP will use the delimiter in the
MAC authentication request. For example, if you specify colon as a
delimiter, MAC addresses in the xx:xx:xx:xx:xx:xx format are used. If the
delimiter is not specified, the MAC address in the xxxxxxxxxxxx format is
used.
This option is available only when MAC authentication is enabled.
Enterprise,
Personal, and Open
security levels.
Uppercase
support
Set to Enabled to allow the OAW-IAP to use uppercase letters in MAC
address string for MAC authentication.
This option is available only if MAC authentication is enabled.
Enterprise,
Personal, and Open
security levels.
Upload
Certificate
Click Upload Certificate and browse to upload a certificate file for the
internal server. For more information on certificates, see Uploading
Certificates on page 160.
Enterprise,
Personal, and Open
security levels.
Table 18:
Configuration Parameters for WLANSecurity Settings
4. Click Next to configure access rules. For more information, see Configuring Access Rules for a WLAN SSID
Profile on page 95.
In the CLI
To configure enterprise security settings for the employee and voice users of a WLAN SSID profile:
(Instant Access Point)(config)# wlan ssid-profile <name>
(Instant Access Point)(SSID Profile <name>)# opmode {wpa2-aes|wpa-tkip,wpa2-aes|wpa-psk-tkip,w
pa2-psk-aes|dynamic-wep}
(Instant Access Point)(SSID Profile <name>)# leap-use-session-key
(Instant Access Point)(SSID Profile <name>)# termination
(Instant Access Point)(SSID Profile <name>)# auth-server <server-name>
Seitenansicht 93
1 2 ... 89 90 91 92 93 94 95 96 97 98 99 ... 334 335

Kommentare zu diesen Handbüchern

Keine Kommentare