User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
143
8021X 192.168.1.22 active thirdParty
ADMIN 0.0.0.0 inactive
USER_DEVICE 192.168.1.22 active thirdParty
No authentication servers are configured by default.
The Mesh Point can actively use up to three authentication
servers at a time. You can configure the same authentication
server to provide more than one supported authentication type.
Only the active server for the applicable authentication type will
determine the success or failure of a given authentication
attempt. Failed credentials are not forwarded to any other
server.
NOTE: Only
fortressRadius
servers support all three
types of authentication
(see the Fortress Mesh
Point Software GUI Guide
for more detail).
For redundancy, multiple authentication servers can be
configured on the Mesh Point. The additional servers will
become active only if the server with the earliest priority
number for a given authentication type becomes unavailable.
In this case the server next in the priority sequence for that
authentication type, if one is configured and available, will be
used.
Add an external authentication server to the Mesh Point
configuration interactively with
add auth:
# add auth
Name (Name of the server): radSrv1
Type (fortressRadius|thirdParty): fortressRadius
AuthType (userdev|8021x|admin): userdev
Priority (Priority [0..999] of the server): 4
Sharedkey (Authentication Key [1-31 characters in length]): sharedkey4
IPaddr (IP address of the external server): 192.168.1.9
PortNumber (Port number [1..65535] to communicate with the server): 1812
MaxRetries (Maximum number of retries (userdev and admin auth types only)): 3
AdminState (active|inactive to set admin state (default is active)):
Description (Description of the server):
You must name the server (Name), identify its Type, and specify
what type of authentication the server will perform (
AuthType).
You can also specify the
Priority number, from
1
–
999
, at
which the server will be used for the specified authentication
type. Lower priority numbers are used first. A value of
0 (zero)
assigns a priority of last. By default, servers are assigned
consecutive priority numbers, beginning with
1
, in the order in
which they are added to the Mesh Point’s configuration.
You should then specify the external server’s
IPaddress and
SharedKey (1–64 printable characters), and the PortNumber
to use for authentication transactions with the server.
In addition, you can specify how many times the Mesh Point
will attempt to connect to the server before determining that the
server is unavailable and going on to the next configured