Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
11-24
RADIUS Server
RADIUS Authentication
The RADIUS server replaces <group attribute> with the string that you
enter in the Group Attribute field. (See step 11). The server replaces <local
group name> with the name of the group configured in the local RADIUS
database.
10. In the Group Membership Attribute field, specify the attribute that stores a
user’s group memberships.
The internal RADIUS server requests this attribute in the search for the
user accounts. The attribute is commonly named “memberOf” or “radius-
GroupName.”
11. In the Group Attribute field, specify the attribute that your LDAP server
uses to store the name of a group object.
The internal RADIUS server uses this attribute as part of the search with
the group filter. See step 9 for more information about this search.
12. In the Net Timeout field, enter a time from 1 through 10 seconds.
If the Wireless Edge Services xl Module does not receive a response within
this time, it considers the LDAP server unreachable. If you have config-
ured a secondary LDAP server, the module contacts it. Otherwise, authen-
tication fails.
13. Optionally, click the Secondary tab in the LDAP Server Details section.
Repeat steps 4 through 12 to configure the secondary LDAP server.
14. Click the Apply button.
15. Click the Save link to save your configuration to the startup-config.
You can edit LDAP setting by changing the appropriate fields and clicking the
Apply button. Whenever you change a setting, you must re-enter the bind
password.
You can also remove all settings for a particular LDAP server at once:
1. Click the servers tab (Primary or Secondary).
2. Check the Delete Primary Ldap server or Delete Secondary Ldap server box.
3. Click the Apply button and save your configuration to the startup-config.
Configuring Groups for Use with an LDAP Server. To authenticate
users, the Wireless Edge Services xl Module’s internal RADIUS server requires
at least one group policy. If you are using an LDAP server as the data source,
the group name must match the name of wireless users’ group as stored on
the LDAP server.