Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
1-29
Introduction
ProCurve Wireless Edge Services xl Module
Authenticating to a RADIUS Server. Each of the authentication methods
described in the sections above involve an authentication server. This server
decides whether a station can connect to the network based on whether:
the user provides the right login credentials
the policies configured on the server allow wireless access at this time
and location
The Wireless Edge Services xl Module supports authentication to an external
RADIUS server or to its internal server.
External RADIUS Server. The Wireless Edge Services xl Module can con-
tact an external RADIUS for these types of authentication:
MAC authentication—The module can send either a PAP or a CHAP
request to the external server, placing the station’s MAC address in both
the username and password fields. You can configure the format in which
the module sends the MAC address (that is, the type and placement of
delimiters).
Web-AuthThe module authenticates Web-Auth users to an external
server using either PAP or CHAP requests. The module fills in the user-
name and password fields from the information that a user enters into the
Web-Auth login screen.
802.1X with EAP—The module acts as the 802.1X authenticator, and the
external RADIUS server is the authentication server. The Wireless Edge
Services module has been certified for these EAP methods:
EAP-Transport Layer Security (TLS)
EAP-Tunneled TLS (TTLS)
PEAP with Microsoft CHAP version 2 (MS-CHAP v2)
EAP-Subscriber Identity Module (SIM)
EAP-Generic Token Card (GTC)
Note In 802.1X, the supplicant and the authentication server, not the authenticator,
agree on the EAP method. Because the module simply passes EAP messages
between the wireless station and the external server, rather than generating
the messages itself, it should support any standard EAP method. The module
has been certified those EAP method listed above.
For more information about EAP methods, see “EAP Methods” on page 1-30.
Internal RADIUS Server. The Wireless Edge Services xl Module’s internal
RADIUS server can authenticate stations that connect to the module’s WLANs.
The server can also respond to authentication requests from clients such as
switches that enforce port authentication in the Ethernet network.