Authentication services
Using the integrated RADIUS server
11-3
Primary features
Provides termination of 802.1X sessions at the controller for clients using WPA/WPA2
with EAP-PEAP, EAP-TLS and EAP-TTLS. Support for other EAP protocols is available
using proxy mode.
Provides MAC-based authentication of wireless users connected to both controlled and
autonomous APs.
Can be used to validate login credentials for HTML-based users.
All locally defined user account options (user accounts, account profiles, and
subscription plans) presented on the Controller >> Users menu are handled by the
internal RADIUS server.
Allows RADIUS accounting data to be sent to an external RADIUS server. (The internal
RADIUS server does not provide support for accounting.)
Local user accounts and account profiles have been designed to match the same
functionality and support as can be provided by an external RADIUS server. Most of the
AVPairs supported on an external RADIUS server are also supported by the integrated
RADIUS server.
Server configuration
Configuration of the integrated RADIUS server is done using the Controller >>
Authentication > RADIUS server page. In most cases, the default settings on this page will
not need to be changed.