Enterasys RoamAbout 3000 Guía de usuario Pagina 44

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 214
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 43
Configuration
2-8 Planning and Managing Your Wireless Network
Foreachserviceyouwanttoprovide,youconfigurethefollowingitemsinaserviceprofile:
•TheSSIDname
•SSIDadvertisement(whethertheSSIDnameisbeaconed)
•WhethertheSSIDnameisencryptedorclear(notencrypted)
•Webpage(ifusingWebAAA)
•Multipleencryptionchoices(Dynamic/staticWEP,WPA,WEP+WPA,802.11i)
Theencryption
youusedependsonthetypeofservicesyouareoffering.Employeeaccessis
typicallyencrypted,guestaccessistypicallyclear(noencryption),andmultihostor“multiple
virtualizedservicesservicecanbeencrypted,witheachSSIDbeingmatchedwithitsownservice
profile.Ifservicesarebeingusedfor
customercorporateentities(e.g.differentairlinesonan
airportwirelessnet),thentheywouldprobablyuse802.1Xandstrongencryptionwithwebguest
accessfortheirairportclubguests.Iftheservicesarebeingusedtoadvertisemultiplewireless
serviceproviders(WISP),suchasTMobile
TM
,Wayport®, andBoingoWireless
TM
,thenthese
serviceswouldprobablybecompletelyopen.However,theywouldlikelybeassignedtotheir
owndedicatedsubnetcontainingtheirproxyserver/billinggateway.
AAA Security Configuration
Anadministratorcancontrolthewayinwhichusersaccessthenetwork.Foreachserviceyou
provide,youcanconfigureuniqueauthentication,authorization,andaccounting(AAA)security
features,creatinganentirelyvirtualizedwirelessservice.Foreachservice,youconfigurethe
followingitems:
•Multipleauthenticationchoices(802.1X,Web,AAA,MACauthentication,Bonded
Auth,
open)
•AAAmethods(uptofourRADIUSservergroups,oralocaldatabaseontheRoamAbout
switch)
Authentication
Authenticationisthemethodofdeterminingwhetherauserisallowedaccesstoyournetwork.
UserscanbeauthenticatedbyaRADIUSserver(passthrough)orbytheRoamAboutswitchlocal
database(local).TheRoamAboutswi tch canalsoassisttheRADIUSserverbyperformingthe
ExtensibleAuthenticationProtocol(EAP)p rocessingfor
theserver(offload).
Toauthenticateusers,youwillneedtoconfigureuserseitherinthelocaldatabaseoronRADIUS
servers.Eachuserwillhaveausername,password,andRADIUSand/orvendorspecificattributes
(VSAs).Youwillalsoneedtoconfigureauthenticationrules(802.1X,MAC,lastresort,orweb
authentication).
Figure 2
4onpage 29showsaflowchartrepresentingtheauthenticationprocess.Generally,
802.1Xauthenticationisattemptedfirst.Iftheuserfails,thenMACauthenticationisattempted.If
thisfails,thenlastresortandwebauthenticationisused.Foraserviceprofile,youspecifyeither
webauthentication,lastresort,ornonein
theauthfallthrubox.Youcanonlyselectone.
Note: You also must configure AAA security configuration items for each service. For more
information, see “AAA Security Configuration” on page 2-8.
Vista de pagina 43
1 2 ... 39 40 41 42 43 44 45 46 47 48 49 ... 213 214

Comentarios a estos manuales

Sin comentarios