Users Guide

Table Of Contents
10.For PEAP, select the “inner authentication method. The authentication method shown is MS-CHAPv2.
(Because password authentication is being used on this network, this is the only EAP authentication type
that should be selected.)
You can also enable fast reconnect in this screen. If you enable fast reconnect here and also on client
devices, additional time can be saved when multiple authentications take place (such as when clients are
roaming between APs frequently) because the server will keep the PEAP encrypted tunnel alive.
11.Click OK.
Configuring RADIUS Attributes
In the configuration example for 802.1x, the controller restricts network access privileges based on the group
membership of the computer or user. In order for this to work, the controller must be told to which group the
user belongs. This is accomplished using RADIUS attributes returned by the authentication server.
To configure RADIUS attributes:
1. In the Internet Authentication Service window, select Remote Access Policies.
1. Open the remote access policy you want to configure, and select the Advanced tab.
2. Click Add to configure an attribute.
3. Select the Class attribute.
4. Enter the value for this attribute. For example, for the Wireless-Computers policy, the Class attribute
returned to the controller should contain the value “computer”.
5. Click OK.
6. Click OK.
Another example of a Class attribute configuration is shown below for the Wireless-Student policy. This policy
returns the RADIUS attribute Class with the value student” upon successful completion.
Configuring Management Authentication using IAS
Before you can configure the controller for management authentication using Windows IAS, you must perform
the following steps to configure a Windows IAS RADIUS server on your Windows client.
The steps to perform this task may very depending on the version of Windows currently running on your server. For
complete details on configuring Windows IAS, refer to the Windows documentation available at
microsoft.com/downloads).
1. From your windows server, navigate to Start > Settings > Control Panel > Administrative
Tools>Internet Authentication Service. The Internet Authentication Service window opens.
2. Verify that the Internet Authentication Service is running. If it is running, a green arrow icon will appear at
the top of this window. If it has stopped, a red stop icon will appear. If the service is not active, click the
green arrow icon to restart the service.
3. From the Internet Authentication Service window, right click the Radius Clients folder and select New
Radius Client. The New RADIUS Client window opens.
4. Define a friendly name for the RADIUS client and enter the controller’s IP address or DNS name. Click Next.
5. Enter and confirm the Shared Secret key for the controller then click Finish.
Next, create a remote policy for your new RADIUS client.
Dell Networking W-Series ArubaOS 6.4.x | User Guide 802.1X Configuration for IAS and Windows Clients |
1155