Task 12: Configuring a RADIUS
server
Chapter 2: Configuration and alignment
2-122
pmp-0050 (May 2012)
Task 12: Configuring a RADIUS server
Configuring a RADIUS AAA (Authentication, Authorization, and Accounting) server in a PMP 450 network is
optional, but can provide added security, increase ease of network management and provide usage-based billing
data.
Understanding RADIUS for PMP 450
PMP 450 modules include support for the RADIUS (Remote Authentication Dial In User Service) protocol
supporting Authentication, Authorization, and Accounting (AAA).
RADIUS Functions
RADIUS protocol support provides the following functions:
SM Authentication
allows only known SMs onto the network (blocking ―rogue‖ SMs), and can be
configured to ensure SMs are connecting to a known network (preventing SMs from connecting to
―rogue‖ APs). RADIUS authentication is used for SMs, but is not used for APs.
SM Authorization
configures authenticated SMs with MIR (Maximum Information Rate), CIR
(Committed Information Rate), High Priority, and VLAN (Virtual LAN) parameters from the RADIUS
server when an SM registers to an AP.
SM Accounting provides
support for RADIUS accounting messages for usage-based billing. This
accounting includes indications for subscriber session establishment, subscriber session disconnection, and
bandwidth usage per session for each SM that connects to the AP.
Centralized AP and SM user name and password
management
allows AP and SM usernames and access
levels (Administrator, Installer, Technician) to be centrally administered in the RADIUS server instead
of on each radio and tracks access events (logon/logoff) for each username on the RADIUS server. This
accounting does
not
track and report specific configuration actions performed on radios or pull statistics
such as bit counts from the radios. Such functions require an Element Management System (EMS) such
as Cambium Networks Wireless Manager. This accounting is
not
the ability to perform accounting
functions on the subscriber/end user/customer account.
Framed IP
allows operators to use a RADIUS server to assign management IP addressing to SM modules
(framed IP address).
Tested RADIUS Servers
The Canopy RADIUS implementation has been tested and is supported on
FreeRADIUS, Version 2.1.8
Aradial RADIUS, Version 5.1.12
Summary of Contents for PMP 450
Page 1: ...Cambium PMP 450 Configuration and User Guide System Release 12 0...
Page 6: ......
Page 22: ......
Page 172: ......
Page 173: ...PMP 450 Configuration and User Guide pmp 0050 May 2012 3 1 Chapter 3 Reference information...
Page 178: ......