Administrator Guide

Table Of Contents
Parameter Action/Description
Authentication
Methods
Select authentication methods using the Select to Add field used for this service depend on the
802.1X supplicants and the type of authentication methods you choose to deploy.
W-Policy Manager automatically selects the appropriate method for authentication, when a user
attempts to connect. The common types, which are automatically selected include the following
examples:
l EAP PEAP
l EAP FAST
l EAP TLS
l EAP TTLS
l EAP MSCHAPV2
The EAP-MD5 authentication type is not supported if you use W-ClearPass Policy Manager in
FIPS mode.
The order of authentication is significant, when a client tries to perform an 802.1X authentication.
W-Policy Manager proposes the first authentication method configured. However, the client can
accept the authentication method proposed by W-Policy Manager and continue authentication or
send a Negative-Acknowledgment (NAK) and propose a different authentication method. If the
newly proposed authentication method is also configured, then the authentication proceeds,
otherwise authentication fails.
If most of the clients in the network use a specific authentication method, that authentication
method should be configured first in the list. This would reduce the number of RADIUS packets
exchanged.
For more information, see the following:
l Adding and Modifying Authentication Methods on page 169
l Adding and Modifying Authentication Sources on page 193.
Authentication
Sources
Specify the authentication sources using the Select to Add field.
This can be one or more instances of the following list of authentication sources:
l Active Directory
l Admin User Repository
l Blacklist User Repository
l Endpoints Repository
l Guest Device Repository
l Guest User Repository
l Insight Repository
l Local User Repository
l Onboard Devices Repository
l Social Login Repository
l Time Sources
NOTE: When you attempt to specify more than 23 Services authentication sources, the following
error message is displayed: No. of Authentication Sources cannot exceed 23.
Strip
Username
Rules
Select the check box to preprocess the user name (to remove prefixes and suffixes) before
authenticating and authorizing against the authentication source.
Table 22: Dell 802.1X Wireless Service > Authentication Parameters
Authorization Tab
Use the Authorization tab to select the authorization sources for this service. The Authorization tab is not
displayed by default.
To access this tab, select the Authorization check box from More Options on the Services tab.
Dell Networking W-ClearPass Policy Manager 6.6 | User Guide Services | 75