
Configuring 802.1X authentication for a Wireless Network Profile
You can configure 802.1X authentication for a wireless network profile in the Instant UI or CLI.
In the Instant UI
To enable 802.1X authentication for a wireless network:
1. In the Network tab, click New to create a new network profile or select an existing profile for which you want to
enable 802.1X authentication and click edit.
2. In the Edit <profile-name> or New WLAN window, ensure that all required WLAN and VLAN attributes are
defined, and then click Next.
3. In the Security tab, specify the following parameters for the Enterprise security level:
a. Select any of the following options from the Key management drop-down list.
l WPA-2 Enterprise
l WPA Enterprise
l Both (WPA-2 & WPA)
l Dynamic WEP with 802.1X
4. If you do not want to use a session key from the RADIUS Server to derive pair wise unicast keys, set Session
Key for LEAP to Enabled.
5. To terminate the EAP portion of 802.1X authentication on the OAW-IAP instead of the RADIUS server, set
Termination to Enabled.
By default, for 802.1X authorization, the client conducts an EAP exchange with the RADIUS server, and the AP
acts as a relay for this exchange. When Termination is enabled, the OAW-IAP by itself acts as an authentication
server and terminates the outer layers of the EAP protocol, only relaying the innermost layer to the external
RADIUS server.
6. Specify the type of authentication server to use and configure other required parameters. For more information on
configuration parameters, see Configuring Security Settings for a WLAN SSID Profile on page 84
7. Click Next to define access rules, and then click Finish to apply the changes.
In the CLI
To configure 802.1X authentication for a wireless network:
(Instant Access Point) (config)# wlan ssid-profile <SSID-Name>
(Instant Access Point) (SSID Profile <"profile-name>")# type {<Employee>|<Voice>}
(Instant Access Point) (SSID Profile <"profile-name>")# opmode {<opensystem> |<wpa2-ae>|<wpa2-
psk-aes>|<wpa-tkip>|<wpa-psk-tkip>|<wpa-tkip>|<wpa2-aes>|<wpa-psk-tkip>|<wpa2-psk-aesstatic-
wep>|<dynamic-wep>}
(Instant Access Point) (SSID Profile <"profile-name>")# leap-use-session-key
(Instant Access Point) (SSID Profile <"profile-name>")# termination
(Instant Access Point) (SSID Profile <"profile-name>")# external-server
(Instant Access Point) (SSID Profile <"profile-name>")# auth-server <server-name>
(Instant Access Point) (SSID Profile <"profile-name>")# auth-survivability
(Instant Access Point) (SSID Profile <"profile-name>")# auth-survivability cache-time-out
<hours>
(Instant Access Point) (SSID Profile <"profile-name>")# radius-reauth-interval <minutes>
(Instant Access Point) (SSID Profile <"profile-name>")# end
(Instant Access Point)# commit apply
Configuring 802.1X authentication for Wired Profiles
You can configure 802.1X authentication for a wired profile in the Instant UI or CLI.
In the Instant UI
To enable 802.1X authentication for a wired profile:
AOS-W Instant 6.2.1.0-3.3| User Guide Authentication | 131
Kommentare zu diesen Handbüchern