
Configuring WLAN Services
Configuring Accounting and Authentication
SCALANCE WLC711
User Guide, V8.11, 07/2012, C79000-G8976-C260-03 6-17
The configured values for the selected server are displayed in the table at the top.
8. For NAS IP Address, accept the default of “Use VNS IP address” or de-select the checkbox
and type the IP address of a Network Access Server (NAS).
9. For NAS Identifier, accept the default of “Use VNS name” or type the Network Access Server
(NAS) identifier. The NAS identifier is a RADIUS attribute that identifies the server
responsible for passing information to designated RADIUS servers and then acting on the
response returned.
10. Click OK.
11. To save your changes, click Save.
Configuring Authentication for a WLAN Service
• 802.1x Authentication — If 802.1x authentication mode is configured, the wireless device must
successfully complete the user authentication verification prior to being granted network
access. This enforcement is performed by both the user's client and the AP. The wireless
device's client utility must support 802.1x. The user's EAP packets request for network access
along with login identification or a user profile is forwarded by the SCALANCE IWLAN
Controller to a RADIUS server.
• Captive Portal Authentication — For Captive Portal authentication, the wireless device
connects to the network, but can only access the specific network destinations defined in the
non-authenticated filter. For more information, see “Filtering Rules” on page 5-3. One of these
destinations should be a server, either internal or external, which presents a Web login page —
the Captive Portal. The wireless device user must input an ID and a password. This request
for authentication is sent by the SCALANCE IWLAN Controller to a RADIUS server or other
authentication server. Based on the permissions returned from the authentication server, the
SCALANCE IWLAN Controller implements policy and allows the appropriate network
access.
Captive Portal authentication relies on a RADIUS server on the enterprise network. There are
three mechanisms by which Captive Portal authentication can be carried out:
– Internal Captive Portal — The SCALANCE IWLAN Controller displays the Captive
Portal Web page, carries out the authentication, and implements policy.
• RADIUS servers — RADIUS servers can perform the following for a WLAN Service:
– Authentication — RADIUS servers are configured to provide authentication.
Kommentare zu diesen Handbüchern