Using an External Server for User Authentication
Role Based Access Control Policy
ZoneDirector 9.8 User Guide, 800-70599-001 Rev B 311
When using the internal user database, automatically generated user certificates
and keys are deleted whenever the associated user account is deleted from the
user database. In the case of using Windows Active Directory, LDAP or RADIUS as
an authentication server, you can delete the generated user keys and certificates by
following these steps:
1 Go to Monitor > Generated PSK/Certs. The Generated PSK/Certs page
appears.
2 Select the check boxes for the PSKs and Certificates that you want to delete.
3 Click Delete to delete the selected items.
The selected PSKs and Certificates are deleted from the system.
A user with a deleted PSK or a deleted certificate will not be able to connect to the
wireless network without obtaining a new key or a new certificate.
Using an External Server for User
Authentication
Once your wireless network is set up, you can instruct ZoneDirector to authenticate
wireless users using your existing Authentication, Authorization and Accounting
(AAA) server. The following types of AAA servers are supported:
• Active Directory
• LDAP
• RADIUS / RADIUS Accounting
The ZoneDirector web interface provides a sample template for each of the AAA
server types. These templates can be customized to match your specific network
setup, or you can create new AAA server objects and add them to the list.
To use an external authentication server:
1 Go to Configure > AAA Servers. The Authentication/Accounting Servers page
appears.
2 Click the Create New link in the Authentication/Accounting Servers table, or
click Edit next to the relevant server type in the list.
3 When the Create New form (or “Editing” form) appears, make the following
entries:
•In Name, type a descriptive name for this authentication server (for example,
“Active Directory”).
•In Ty pe , verify that one of the following options is selected: