WESM zl Management and Configuration Guide WT.01.28 and greater
11-9
RADIUS Server
RADIUS Authentication
3. If you have selected EAP-TLS, choose a trustpoint from the CA Cert Trustpoint
drop-down menu.
Select the trustpoint in which you loaded the CA certificate for the CA that signs
users’ digital certificates. This trustpoint should typically match the one you
selected for the Cert Trustpoint.
Again, you can select <Create a New Certificate> to open the Certificates
Wizard.
4. Next choose the source for authentication data (explained in the section below).
Or click the Apply button and, when the screen is displayed asking you to restart
the server, click the Yes button.
Choosing the Source for User Credentials
The RADIUS server can draw on one of two potential databases for authenticating
users:
■ its local database
In addition to checking a user’s credentials against user accounts its local
database, the RADIUS server verifies that the user is connecting at an allowed
time (specified in the user’s assigned group).
After authenticating a user, the Wireless Edge Services zl Module can place that
user in a dynamic VLAN (also specified in the user’s assigned group).
■ an LDAP-compliant directory server
The module’s RADIUS server binds to the directory server and looks up users’
credentials.
To select the database, complete these steps:
1. Select Network Setup > Local RADIUS Server and click the Authentication tab.