Controllerless Networks

last person joined: 19 hours ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

IAP and external RADIUS

This thread has been viewed 0 times
  • 1.  IAP and external RADIUS

    Posted Jan 21, 2014 04:46 AM

    Hi all,

    I have a question about the configuration of my IAPs with an external RADIUS Server. If I don't enable Dynamic RADIUS Proxy in the System tab and if I don't write nothing in the NAS IP address in the Authentication Server parameters, which IP addresses will comunicatewith the radius server? All the IP addresses of my 4 IAPs? So I have to insert in the NPS service of my Windows 2008 server all my IAPs and not only the VC?

     

    Thanks,

     

    Massimo



  • 2.  RE: IAP and external RADIUS

    EMPLOYEE
    Posted Jan 21, 2014 04:55 AM

    It will be the ip of the IAP.  You'll need to add the four addresses to your NPS.

     

     



  • 3.  RE: IAP and external RADIUS

    Posted Jan 21, 2014 05:03 AM

    Ok, thank you for the good explanation Michael!

     

    And is better to enable or not the Termination flag in the SSID tab? That is better to terminate the EAP protocol on the RADIUS or on the IAP?



  • 4.  RE: IAP and external RADIUS

    EMPLOYEE
    Posted Jan 21, 2014 05:08 AM

    That depends on the circumstances.  Personally I prefer to not enable termination and let the Radius do the EAP exchange, and then you don't need to worry about certificates.

     

     



  • 5.  RE: IAP and external RADIUS

    Posted Jan 31, 2014 10:20 AM

    Termination or not will depend on your setup, do you have CA setup, self cert or external cert on the radius server. If it is for someone not familiar with such cert then I would use termination instead. Or if you need to do machine auth etc then you have no choice but to go ahead with no termination.