User Manual

Table Of Contents
Advanced Configuration AP-4000/4000M/4900M User Guide
SSID/VLAN/Security
133
Enable: MAC addresses in the MAC Access Control List stored on the RADIUS server are blocked or allowed,
based on the MAC ACL settings. If a higher priority authentication protocol is also enabled, the higher-priority
settings will override the MAC ACL settings. See Authentication Protocol Hierarchy.
Disable: RADIUS MAC ACL settings are disabled.
Strict: RADIUS MAC ACL settings are enabled. If a higher-priority authentication protocol is also enabled,
RADIUS MAC ACL settings will be applied in addition to the higher priority authentication protocol settings. See
Authentication Protocol Hierarchy.
4. Control the functionality of the MAC Access Control List on the VLAN/SSID by selecting one of the following from the
MAC ACL Status drop-down menu:
Enable: MAC addresses in the MAC Access Control List are blocked or allowed, based on the MAC ACL settings.
If a higher priority authentication protocol is also enabled, the higher-priority settings will override the MAC ACL
settings. See Authentication Protocol Hierarchy.
Disable: MAC ACL settings are disabled.
Strict: MAC ACL settings are enabled. If a higher-priority authentication protocol is also enabled, MAC ACL
settings will be applied in addition to the higher priority authentication protocol settings. See Authentication
Protocol Hierarchy. When MAC ACL Status is set to Strict, changes to the MAC ACL table (configured on the MAC
Access page) will take effect without a device reboot.
5. Enter Rekeying Interval in seconds (between 300 and 65525). When set to 0, this parameter is disabled. The default
is 900 seconds.
6. Enter the Security Profile used by the VLAN in the Security Profile field. See the Security Profile section for more
information.
7. Define the RADIUS Server Profile Configuration for the VLAN/SSID:
RADIUS MAC Authentication Profile
RADIUS EAP Authentication Profile
RADIUS Accounting Profile
If 802.1x, WPA, or 802.11i security mode is used, the RADIUS EAP Authentication Profile must have a value.
A RADIUS Server Profile for authentication for each VLAN shall be configured as part of the configuration options
for that VLAN. RADIUS profiles are independent of VLANs. The user can define any profile to be the default and
associate all VLANs to that profile. Four profiles are created by default, “MAC Authentication”, “EAP
Authentication”, Accounting”, and “Management”
8. If desired, scroll down to the scroll down to the SSID and VLAN Table and click Edit to modify the Network Name,
VLAN ID, or QoS profile of the SSID/VLAN.
NOTE: Because VLAN tagging is disabled, attempting to add a new SSID/VLAN will produce an error message.
The Edit Entries screen will be displayed. See Figure 4-55.