Users Guide

Field Default Description
Primary Server Port (1-65535) 49 Enter the port for the primary TACACS+ server.
Primary Server Secret N/A Specify and confirm the primary shared secret for the primary
TACACS+ server.
Confirm Primary Server
Secret
N/A Re-enter the primary server secret.
Secondary Server
Hostname/IP Address
N/A Enter the IP address or hostname of the secondary TACACS+
server.
Secondary Server Port (1-
65535)
49 Enter the port for the secondary TACACS+ server.
Secondary Server Secret N/A Enter the shared secret for the secondary TACACS+ server.
Confirm Secondary Server
Secret
N/A Re-enter the secondary server secret.
Table 22: AMP Setup > Authentication Fields and Default Values for TACACS+ Authentication (Continued)
3. Select Save and continue with additional steps.
Configuring Cisco ACS to Work with W-AirWave
To configure Cisco ACS to work with W-AirWave, you must define a new service named AMP that uses HTTPS on
the ACS server.
1. The AMP HTTPS service is added to the TACACS+ (Cisco) interface under the Interface Configuration tab.
2. Select a checkbox for a new service.
3. Enter AMP in the service column and https in the protocol column.
4. Select Save.
5. Edit the existing groups or users in TACACS to use the AMP service and define a role for the group or user.
l The role defined on the Group Setup page in ACS must match the exact name of the role defined on the
AMP Setup > Roles page.
n The defined role should use the format: role=<name_of_AMP_role>. For example role=DormMonitoring.
As with routers and switches, W-AirWave does not need to know user names.
6. W-AirWave also needs to be configured as an AAA client.
l On the Network Configuration page, select Add Entry.
l Enter the IP address of W-AirWave as the AAA Client IP Address.
l The secret should be the same value that was entered on the AMP Setup > TACACS+ page.
7. Select TACACS+ (Cisco IOS) in the Authenticate Using drop down menu and select submit + restart.
W-AirWave checks the local user name and password store before checking with the TACACS+ server. If the user is
found locally, the local password and local role apply. When using TACACS+, it is not necessary or recommended to
define users on the W-AirWave server. The only recommended user is the backup administrator, in the event that the
TACACS+ server goes down.
Configuring LDAP Authentication and Authorization
LDAP (Lightweight Directory Access Protocol) provides users with a way of accessing and maintaining distributed
directory information services over a network. When LDAP is enabled, a client can begin a session by
Dell Networking W-AirWave 8.2.4 | User Guide Configuring W-AirWave | 50