Authentication and User Management
14.6 Configuring Authentication Survivability
SCALANCE W1750D UI
Configuration Manual, 02/2018 , C79000-G8976-C451-02
223
4. To enable authentication survivability, select
from the
Authentication survivability
drop-down list. On enabling this, the AP authenticates the previously connected clients
using EAP-PEAP and EAP-TLS authentication when connection to the external
authentication server is temporarily lost.
5. Specify the cache timeout duration, after which the cached details of the previously
authenticated clients expire. You can specify a value within the range of 1–99 hours and
the default cache timeout duration is 24 hours.
6. Click
and then click
to apply the changes.
Important Points to Remember
Any client connected through ClearPass Policy Manager and authenticated through AP
remains authenticated with the AP even if the client is removed from the ClearPass Policy
Manager server during the ClearPass Policy Manager downtime.
Do not make any changes to the authentication survivability cache timeout duration when the
authentication server is down.
For EAP-PEAP authentication, ensure that the ClearPass Policy Manager 6.0.2 or later
version is used for authentication. For EAP-TLS authentication, any external or third-party
server can be used.
For EAP-TLS authentication, ensure that the server and CA certificates from the
authentication servers are uploaded on the AP. For more information, see Uploading
Certificates (Page 238).
To configure authentication survivability for a wireless network:
(scalance)(config)# wlan ssid-profile <name>
(scalance)(SSID Profile <name>)# type {<Employee>|<Voice>|<Guest>}
(scalance)(SSID Profile <name>)# auth-server <server-name1> (
(scalance) (SSID Profile <name>)# auth-survivability
(scalance)(SSID Profile <name>)# exit
(scalance)(config)# auth-survivability cache-time-out <hours>
(scalance)(config)# end
(scalance)# commit apply
To view the cache expiry duration:
(scalance)# show auth-survivability time-out
To view the information cached by the AP:
(scalance)# show auth-survivability cached-info
To view logs for debugging:
(scalance)# show auth-survivability debug-log