WESM zl Management and Configuration Guide WT.01.28 and greater
11-27
RADIUS Server
RADIUS Authentication
You should be careful when using dynamic VLANs with Web-Auth. The user’s
station receives an IP address in the static VLAN before the user can login and
receive the dynamic VLAN assignment. So you must set the lease for the DHCP
address in the static VLAN very low. Then the station will automatically renew
its address soon after it receives the dynamic assignment.
Note You must enable dynamic VLANs in the WLAN to which users connect for this
setting to take effect. See “Enabling Authentication to the Internal Server on
a WLAN” on page 11-33.
5. Specify the times of day when users in this group can connect to the wireless
network.
a. In the Time of Access Start field, enter the earliest time that users can
connect.
b. In the Time Access End field, enter the latest time users can connect.
Always enter times in four digits, the first two digits being the hour in the 24-hour
clock and the second two digits being the minutes.
If a user is already logged in, and the end access time passes, the user remains
logged in. However, the next time the user’s station re-authenticates, the re-
authentication fails. You can require period re-authentication in the WLAN’s
RADIUS settings. See “Enabling Authentication to the Internal Server on
a WLAN” on page 11-33.
As shown in Figure 11-5, by default, users can connect at any time of the day or
night.
6. In the Time of access in days section, check the boxes to specify the days of the
week when users in this group can connect to the wireless network. By default,
network access is available every day.
7. Click the OK button.
For more information about managing groups, see “Creating a Group” on page 11-12.
Specifying a Domain Proxy RADIUS Server
The Wireless Edge Services zl Module’s internal RADIUS server can query external
RADIUS servers to authenticate users in a different domain.