
Configuring the Wireless AP
Configuring VLAN Tags for Wireless APs
SCALANCE WLC711
User Guide, V8.11, 07/2012, C79000-G8976-C260-03 3-45
802.1x authentication credentials can be updated at any time, whether or not the Wireless AP is
connected with an active session. If the Wireless AP is connected, the new credentials are sent
immediately. If the Wireless AP is not connected, the new credentials are delivered the next time
the Wireless AP connects to the SCALANCE IWLAN Controller.
There are two main aspects to the 802.1x feature:
• Credential management — The SCALANCE IWLAN Controller and the Wireless AP are
responsible for the requesting, creating, deleting, or invalidating the credentials used in the
authentication process.
• Authentication — The Wireless AP is responsible for the actual execution of the EAP-TLS or
PEAP protocol.
802.1x authentication can be configured on a per-AP basis. For example, 802.1x authentication can
be applied to specific Wireless APs individually or with a multi-edit function.
The 802.1x authentication supports two authentication methods:
• PEAP (Protected Extensible Authentication Protocol)
– Is the recommended 802.1x authentication method
– Requires minimal configuration effort and provides equal authentication protection to
EAP-TLS
– Uses user ID and passwords for authentication of access points
• EAP-TLS
– Requires more configuration effort
– Requires the use of a third-party Certificate Authentication application
– Uses certificates for authentication of access points
– SCALANCE IWLAN Controller can operate in either proxy mode or pass through mode.
- Proxy mode — The SCALANCE IWLAN Controller generates the public and private
key pair used in the certificate.
- Pass through mode — The certificate and private key is created by the third-party
Certificate Authentication application.
Note:
Although a Wireless AP can support using both PEAP and EAP-TLS credentials simultaneously, it is not
recommended to do so. Instead, Siemens recommends that you use only one type of authentication and that
you install the credentials for only that type of authentication on the Wireless AP.
Configuring 802.1x PEAP Authentication
PEAP authentication uses user ID and passwords for authentication. To successfully configure
802.1x authentication of a Wireless AP, the Wireless AP must first be configured for 802.1x
authentication before the Wireless AP is deployed on a 802.1x enabled switch port.
To Configure 802.1x PEAP Authentication:
1. From the top menu, click Wireless APs. The Wireless AP screen displays.
2. In the Wireless AP list, click the Wireless AP for which you want to configure 802.1x PEAP
authentication.
Kommentare zu diesen Handbüchern