|
Function Specification
77
3.3.20.
Simple RADIUS Function
By enabling this function, the LAN terminal connected to the company network can be authenticated. Only the
authorized LAN terminal to the internal network can be connected by registering the account information of the LAN
terminal in the authentication database of this product.
Unauthorized connection to the internal network can be firmly prevented by using it in together with the MAC address
filtering function. For the setting method of simple RADIUS function, see Section 5.8.12.
[Uses of this function]
This product supports only authentication function out of the RADIUS protocol functions.
Two authentication methods are EAP-PEAP and EAP-TLS.
IEEE802.1X authentication is supported as a wireless LAN terminal authentication method.
The root certificate is generated automatically by this product. It can easily issue client certificates after user
registration.
Up to 20 external RADIUS clients can be registered when this product is operated as a RADIUS server.
The maximum number of users that can be registered in this product is 200 users. Up to two client certificates
can be issued per user account.
When the wireless LAN function of this product is enabled and the encryption mode is set to [802.1x (EAP)], this
product will operate as a RADIUS client.
When the RADIUS client in this product is used, only the terminals connected to this product via wireless LAN are
subject to authentication. Terminals that are wired to a LAN port are not subject to authentication.
When this product operates as a RADIUS client, you can choose whether to use the RADIUS server of this
product or to use an external RADIUS server.
In the configuration example on the right side, NA1000A/W (sold separately) is configured as a wireless LAN
access point. In this configuration, NA1000A/W operates as a RADIUS client, and this product operates as a
RADIUS server.
SA3500G as wireless AP
NA1000A/W as wireless AP
Authentication
Authentication