Task 12: Configuring a RADIUS
server
Chapter 2: Configuration and alignment
2-128
pmp-0050 (May 2012)
If
Enable Realm
is selected on the SM‘s
Configuration
>
Security
tab, then the same
Realm as appears there (or access to it).
The same Phase 2 (Inner Identity) protocol as configured on the SM‘s
Configuration
>
Security
tab under
Phase 2 options.
The username and password for each SM configured on each SM‘s Configuration > Security tab.
An IP address and NAS shared secret that is the same as the IP address and
Shared Secret
configured on
the AP‘s Configuration > Security tab for that RADIUS server.
A server private certificate, server key, and CA certificate that complement the public certificates
distributed to the SMs, as well as the Canopy dictionary file that defines Vendor Specific Attributes
(VSAa). Default certificate files and the dictionary file are available from the software site:
www.cambiumnetworks.com/support/pmp/software/
after entering your name, email address, and either
Customer Contract Number or the MAC address of a module covered under the 12 month warranty.
Optionally, operators may configure the RADIUS server response messages (Accept or Reject) so that the user
has information as to why they have been rejected. The AP displays the RADIUS Authentication Reply
message strings in the Session Status list as part of each SM‘s information. The SM will show this string (listed
as Authentication Response on the SM GUI )on the main Status page in the Subscriber Module Stats section.
(Note: Aradial AAA servers only support operator-configurable Authentication Accept responses, not
Authentication Reject responses).
Figure 31
AP display of RADIUS accept for SM
Summary of Contents for PMP 450
Page 1: ...Cambium PMP 450 Configuration and User Guide System Release 12 0...
Page 6: ......
Page 22: ......
Page 172: ......
Page 173: ...PMP 450 Configuration and User Guide pmp 0050 May 2012 3 1 Chapter 3 Reference information...
Page 178: ......