Administrator Guide

Table Of Contents
WAN Failure (Authentication) Survivability
This section contains the following information about the authentication survivability feature. This feature is
supported on W-7000 Seriescontrollers.
l Supported Client and Authentication Types
l Administrative Functions
l About the Survival Server
l Trigger Conditions for Critical Actions
l Authentication for Captive Portal Clients
l Authentication for 802.1X Clients
l Authentication for MAC Address-Based Clients
l Authentication for WISPr Clients
Authentication survivability allows controllers to provide client authentication and authorization survivability
when remote authentication servers are not accessible. It stores user access credentials, as well as key reply
attributes, whenever clients are authenticated with external RADIUS servers or LDAP authentication servers.
When external authentication servers are not accessible, the controller uses its local Survival Server to continue
providing authentication and authorization functions by using the user access credentials and key reply
attributes that were stored earlier.
Authentication survivability is critical to WLANs managed by branch controllers since most branch controllers
use geographically remote authentication servers to provide authentication and authorization services. When
those authentication servers are not accessible, clients can't access the WLAN because the branch controller
can't authenticate them.
This feature can be configured for branch controllers using the Smart Config WebUI, or for master and local
controllers using the aaa auth-survivability commands in the command-line interface. For details on configuring
this feature using the Smart Config WebUI, see WAN Configuration on page 317.
Supported Client and Authentication Types
The the following combination of clients and authentication types are supported with the authentication
survivability feature (see Table 54):
Table 54: Clients and Supported Authentication Types
Clients Authentication Methods
Captive Portal clients Password Authentication Protocol (PAP)
802.1X clients l Termination disabled: Extensible Authentication Protocol-Transport
Layer Security (EAP-TLS) with an external RADIUS server
l Termination enabled: EAP-TLS with Common Name (CN) lookup with
an external authentication server
External Captive Portal clients using
the XML-API
PAP
MAC-based Authentication clients PAP
Dell Networking W-Series ArubaOS 6.4.x | User Guide BranchController Config for Controllers | 284