User Guide

Table Of Contents
Bridge GUI Guide: Security Configuration
134
NOTE: If you are
using an external
RADIUS server, config-
ure user timeouts in that
service.
Authentication is enabled on the Bridge when at least one
authentication server is configured and enabled on the Bridge.
You can configure two types of authentication server for the
network, depending on the network configuration:
Fortress Auth. - identifies an authentication service running
internally on a Fortress Bridge (either on the local Bridge or
on a Fortress Bridge external to the current Bridge). A
Bridge’s internal authentication server is always available.
Availability of external Fortress authentication servers
depends on whether other Bridges configured for
authentication are present on the network.
3rd Party RADIUS - identifies a non-Fortress RADIUS server.
The Bridge can be used with most standard RADIUS
servers likely to be present on the network, including:
Microsoft® Internet Authentication Service (IAS)
included in Windows® Server 2003
the open source freeRADIUS version 2.1
CAUTION: Only
the
Fortress Auth.
authentication server
type supports both RA-
DIUS user authentica-
tion and Fortress device
authentication.
3rd Par-
ty RADIUS
servers do
not support device au-
thentication.
For each of the three possible authentication types (Auth
Types) that you want the Bridge to support, you must specify at
least one authentication server that supports that
authentication type.
Auth Types include:
User/Device Authentication - 1) the user name and
password, as supplied by the user logging in and
configured locally or on an authentication server
providing user authentication to the network, and 2) the
unique, hexadecimal Device ID generated for each
Secure Client device and used to authenticate it on a
Fortress-secured network
NOTE: Enabling
802.1X on any
Ethernet port or using
WPA or WPA2 BSS Wi-Fi
Security
options that do
not use PSK (Section
3.3.4.14) all require
that
you configure an 802.1X
authentication service on
or for the
Bridge
.
802.1X - supplicant credentials
Admin - the user name and password of an
administrator on the Bridge, as supplied by the
administrator logging in and configured locally or on an
authentication server providing administrative
authentication over the network
Only Fortress RADIUS servers fully support all three types of
authentication. Table 4.3 shows the authentication types
supported by the two possible server types.
In order to use a 3rd -party RADIUS server to authenticate
Bridge administrators, the server must be configured to use
Fortress’s Vendor-Specific Attributes (
Fortress-Administrative-
Table 4.3. Supported
Auth. Types
by Configurable Server
Type
Authentication
Fortress Auth. 3rd Party RADIUS
User/Device
yes user only
802.1X
yes yes
Admin
yes yes