Enterasys RBT-4102 Specifications Page 120

  • Download
  • Add to my manuals
  • Print
  • Page
    / 168
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 119
Security
4-84 Advanced Configuration
The802.1xEAPpacketsarealsousedtopassdynamicunicastsessionkeysandstatic
broadcastkeystowirelessclients.Sessionkeysareuniquetoeachclientandareusedto
encryptandcorrelatetrafficpassingbetweenaspecificclientandtheaccesspoint.Youcan
alsoenablebroadcastkeyrotation,
sotheaccesspointprovidesadynamicbroadcastkeyand
changesitataspecifiedinterval.
Youcanenable802.1xasoptionallysupportedorasrequiredtoenhancethesecurityofthe
wirelessnetwork.
Disableindicatesthattheaccesspointdoesnotsupport802.1xauthenticati onforany
wirelessclient.After
successfulwirelessassociationwiththeaccesspoint,eachclientis
allowedtoaccessthenetwork.
Supportedindicatesthattheaccesspointsupports802.1xauthenticationonlyforclients
initiatingthe802.1xauthenticationprocess(thatis,theaccesspointdoesnotinitiate
802.1xauthenticati on).Forclientsinitiating802.1x,onlythosesuccessfullyauthenticated
are
allowedtoaccessthenetwork.Forthoseclientsnotinitia ting802.1x,accesstothe
networkisallowedaftersuccessfulwirelessassociationwiththeaccesspoint.
Requiredindicatesthattheaccesspointenforces802.1xauthenticationforallassociated
wirelessclients.If802.1xauthenticationisnotinitiatedbyaclient,theaccess
pointwill
initiateauthentication.Onlythoseclientssuccessfullyauthenticatedwith802.1xare
allowedtoaccessthenetwork.
Whenyouenable802.1x,youcanalsoenablethebroadcastandsessionkeyrotationintervals.
BroadcastKeyRefreshRatesetstheintervalatwhichthebroadcastkeysarerefreshedfor
stationsusing802.1xdynamic
keying.(Range:01440minutes;Default:0meansdisabled)
SessionKeyRefreshRatespecifiestheintervalatwhichtheaccesspointrefreshesunicast
sessionkeysforassociatedclients.(Range:01440minutes;Default:0meansdisabled)
802.1xSessionTimeoutsetsthetimeperiodafterwhichaconnectedclientmustbere
authenticated.Duringthereauthenticationprocessofverifyingtheclient’scredentialson
theRADIUSserver,theclientremainsconnectedtothenetwork.Onlyifreauthentication
failsisnetworkaccessblocked.Default:60minutes.
MACAuthenticationconfigureshowtheaccesspointusesMACaddressestoauthorize
wirelessclientstoaccess
thenetwork.Thisauthenticationmethodprovidesabasiclevelof
authenticationforwirelessclientsattemptingtogainaccesstothenetwork.A databaseof
authorizedMACaddressescanbestoredlocal ly ontheRBT4102orremotelyonacentral
RADIUSserver.(Default:LocalMAC)
LocalMACindicatesthattheMAC
addressoftheassociatingstationiscomparedagainst
thelocaldatabasestoredontheaccesspoint.LocalMACAuthenticationenablesthelocal
databasetobesetup.
RADIUSMACspecifiesthattheMA Caddressoftheassociatingstationissenttoa
configuredRADIUSserverforauthentication.
Tousea
RADIUSauthenticationserverforMACaddressauthentication,theaccesspoint
mustbeconfiguredtouseaRADIUSserver,seeRADIUS(page411).
Disablespecifiesthattheaccesspointdoesnotcheckanassociatingstation’sMACaddress.
Page view 119
1 2 ... 115 116 117 118 119 120 121 122 123 124 125 ... 167 168

Comments to this Manuals

No comments