Alcatel-Lucent IAP93 Guide de l'utilisateur Page 142

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 335
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 141
Network Type Authentication Encryption
Employee 802.1X AES
Guest Network Captive Portal None
Voice Network or Handheld
devices
802.1X or PSK as
supported by the device
AES if possible, TKIP or WEP if
necessary (combine with security
settings assigned for a user role).
Table 26:
Recommended Authentication and Encryption Combinations
Understanding Authentication Survivability
The authentication survivability feature supports authorization survivability against remote link failure for
OmniAccess WLAN Switches when working with ClearPass Policy Manager (CPPM).
When enabled, this feature allows AOS-W Instant to authenticate the previously connected clients using EAP-
PEAP authentication even when connectivity to CPPM is temporarily lost.
The following figure illustrates the scenario where the OAW-IAP offloads EAP method authentication to ClearPass
over a remote link connection. After authenticating the user against Active Directory and deriving enforcement
attributes for the user, the CPPM returns additional information in the RADIUS
Access-Accept
message, which the
OAW-IAP caches to support authentication survivability.
As shown in the following figure, the information sent by the CPPM varies depending on the authentication method
used.
Figure 45 802.1X Authentication when CPPM is reachable
The following figure illustrates a scenario where when the remote link is not available and the OAW-IAP is no longer
able to reach the CPPM. Here, the OAW-IAP terminates and completes the EAP authentication using the cached
credentials.
AOS-W Instant 6.3.1.1-4.0 | User Guide Authentication | 142
Vue de la page 141
1 2 ... 137 138 139 140 141 142 143 144 145 146 147 ... 334 335

Commentaires sur ces manuels

Pas de commentaire