Chapter 7 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Customizing CN3000 and customer settings - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Chapter 7
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 151 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
• CHAP-Challenge (string): Randomly generated by the product. As defined in RFC
2865. Only present when the authentication method for the RADIUS profile is set to
CHAP. Length = 19 bytes.
• MSCHAP-Challenge (string): As defined in RFC 2433. Only present when the
authentication method for the RADIUS profile is set to MSCHAPv1 or MSCHAPv2.
Length = 8 bytes.
• MSCHAP-Response (string): As defined in RFC 2433. Only present when the
authentication method for the RADIUS profile is set to MSCHAPv1. Length = 49
bytes.
• MSCHAPv2-Response (string): As defined in RFC 2759. Only present when the
authentication method for the RADIUS profile is set to MSCHAPv2. Length = 49
bytes.
• EAP-Message (string): As defined in RFC 2869. Only present when the
authentication method for the RADIUS profile is set to EAP-MD5.
Access accept
• Session-Timeout (32-bit unsigned integer): Maximum time a session can be active.
The CN3000 re-authenticates itself when this timer expires. Omitting this attribute or
specifying 0 will disable the feature. (Note that the authentication interval is also
configurable on the
Security > Authentication
page.
• Class (string): As defined in RFC 2865. Multiple instances are supported.
• EAP-Message (string): Only supported when authentication is EAP-MD5. Note that
the content will not be read as the RADIUS Access Accept is overriding whatever
indication contained inside this packet.
• Colubris-AVPair: See the description in the section that follows.
Access reject
None.
Access challenge
None.
Accounting request
Accounting information is generated by default. To disable accounting support, open the
Security > Authentication -> Advanced Settings
page
.
• Acct-Session-Id (32-bit unsigned integer): Random value generated by the CN3000.
• NAS-Identifier (string): The NAS ID set on the
Security > RADIUS
page for the profile
being used.
• NAS-Ip-Address (32-bit unsigned integer): The IP address of the port the CN3000 is
using to communicate with the RADIUS server.
• NAS-Port (32-bit unsigned integer): Always 0.
• NAS-Port-Type (32-bit unsigned integer): Always set to 19, which represents
WIRELESS_802_11.
• Calling-Station-Id (string): The MAC address of the CN3000’s LAN port in IEEE
format. For example: 00-02-03-5E-32-1A.
• Called-Station-Id (string): The MAC address of the CN3000’s LAN port in IEEE
format. For example: 00-02-03-5E-32-1A.
• User-Name (string): The RADIUS username assigned to the CN3000 on the
Security
> Authentication
page.
Summary of Contents for CN3000
Page 1: ...CN3000 Administrator s Guide...
Page 8: ...Table of Contents 8...
Page 60: ...Chapter 2 How it works Chapter 2 60...
Page 94: ...Chapter 4 Scenarios Chapter 4 94...
Page 106: ...Chapter 5 Activating the public access interface Chapter 5 106...
Page 211: ...Chapter 10 SSL certificates Chapter 10 211...
Page 292: ...Chapter 13 The configuration file Chapter 13 292...
Page 370: ...Chapter 16 Sample setup Microsoft RADIUS Chapter 16 370...
Page 396: ...Chapter 16 Sample setup Microsoft RADIUS Chapter 16 396...
Page 414: ...Chapter 17 Experimenting with NOC authentication Chapter 17 414...