45
DWS-1008 User’s Manual
D-Link Systems, Inc.
Configuration (continued)
Configuration
• Local - The switch performs all authentication with information in a local user database
configured on the switch. No RADIUS servers are required. In this case, the switch
needs a certificate. If you plan to use EAP with Transport Layer Security (EAP-TLS),
the clients also need certificates.
• Offload - The switch offloads all EAP processing from a RADIUS server by establishing
a TLS session between the switch and the client. In this case, the switch needs a
certificate. If you plan to use the EAP-TLS authentication protocol, the clients also
need certificates.
This section provides examples for configuring Protected EAP with Microsoft Challenge
Handshake Authentication Protocol version 2 (PEAP-MS-CHAP-V2) authentication for
802.1X users, in pass-through and offload configurations.
VLANs and Users
For each user, an attribute must be set in the local database or on a RADIUS server to
assign the user to a VLAN. This is true regardless of the authentication type you use. You
can use either of the following attributes to assign a user to a VLAN:
•
Tunnel-Private-Group-ID
- This attribute is described in RFC 2868, RADIUS
attributes for Tunnel Protocol Support.
•
VLAN-Name
- This attribute is a D-Link vendor-specific attribute (VSA).
Note:
You cannot configure the Tunnel-Private-Group-ID attribute in the local user
database.
Specify the VLAN name, not the VLAN number. The examples in this chapter assume the
VLAN is assigned on a RADIUS server with either of the valid attributes. Other RADIUS
attributes and VSAs are optional.
Configuring Pass-Through Authentication
To configure a switch to use a group of RADIUS servers to perform all user authentication:
1. Configure the RADIUS servers and add them to a server group. You must configure a
server group even if you have only one server.
2. Set the authentication protocol to pass-through. Pass-through authentication does not
require local user information or user certificates on the switch.
Summary of Contents for DWS-1008
Page 1: ......