Chapter 1: Configuration
Configuring a RADIUS server
Page
1-275
Configuring a RADIUS server
Configuring a RADIUS server in a PMP 450 Platform network is optional, but can provide added
security, increase ease of network management and provide usage-based billing data.
Understanding RADIUS for PMP 450 Platform Family
PMP 450 Platform modules include support for the RADIUS (Remote Authentication Dial In User
Service) protocol supporting Authentication and Accounting.
RADIUS Functions
RADIUS protocol support provides the following functions:
•
SM Authentication allows only known SMs onto the network (blocking “rogue” SMs), and can be
configured to ensure SMs are connecting to a known network (preventing SMs from connecting to
“rogue” APs). RADIUS authentication is used for SMs, but is not used for APs.
•
SM Configuration: Configures authenticated SMs with MIR (Maximum Information Rate), CIR
(Committed Information Rate), Medium Priority, High Priority, and Ultra High Priority Data channels,
and VLAN (Virtual LAN) parameters from the RADIUS server when a SM registers to an AP.
•
User Authentication allows users to configure a separate User authentication server along
with the SM authentication server. If firmware is upgraded while using this functionality and no
User authentication servers are configured, then AP continues to use the SM authentication server
for User authentication
•
SM Accounting provides support for RADIUS accounting messages for usage-based billing. This
accounting includes indications for subscriber session establishment, subscriber session
disconnection, and bandwidth usage per session for each SM that connects to the AP.
•
Centralized AP and SM user name and password management allows AP and SM usernames
and access levels (Administrator, Installer, Technician) to be centrally administered in the RADIUS
server instead of on each radio and tracks access events (logon/logoff) for each username on the
RADIUS server. This accounting does
not
track and report specific configuration actions
performed on radios or pull statistics such as bit counts from the radios. Such functions require an
Element Management System (EMS) such as Cambium Networks Wireless Manager. This
accounting is
not
the ability to perform accounting functions on the subscriber/end
user/customer account.
•
Framed IP allows operators to use a RADIUS server to assign management IP addressing to SM
modules (framed IP address).
Tested RADIUS Servers
The Canopy RADIUS implementation has been tested and is supported on
•
FreeRADIUS, Version 2.1.8
•
Aradial RADIUS, Version 5.1.12
•
Microsoft RADIUS (Windows Server 2012 R2 version)
•
Cisco ACS, Version 5.7.0.15
Summary of Contents for PMP 450 AP
Page 51: ...Chapter 1 Configuration Quick link setup Page 1 23 ...
Page 155: ...Chapter 1 Configuration Configuring security Page 1 127 ...
Page 163: ...Chapter 1 Configuration Configuring security Page 1 135 ...
Page 164: ...Chapter 1 Configuration Configuring security Page 1 136 ...
Page 193: ...Chapter 1 Configuration Configuring radio parameters Page 1 165 ...
Page 194: ...Chapter 1 Configuration Configuring radio parameters Page 1 166 ...
Page 195: ...Chapter 1 Configuration Configuring radio parameters Page 1 167 ...
Page 206: ...Chapter 1 Configuration Configuring radio parameters Page 1 178 ...
Page 210: ...Chapter 1 Configuration Configuring radio parameters Page 1 182 ...
Page 636: ...Chapter 5 Troubleshooting Logs Page 5 16 Figure 95 SM Authorization log ...