Controllerless Networks

last person joined: yesterday 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

IAP auth with external radius ?

This thread has been viewed 3 times
  • 1.  IAP auth with external radius ?

    Posted Dec 15, 2014 09:15 AM

    how do i authenticate inistant with external radius ?

     

    what is DRP IP ?

     

    thanks ,

    Ehab



  • 2.  RE: IAP auth with external radius ?



  • 3.  RE: IAP auth with external radius ?

    Posted Dec 15, 2014 09:26 AM
    What type of server are you trying to use ?

    Here's some good training :
    http://cloud.arubanetworks.com/instant-training


  • 4.  RE: IAP auth with external radius ?

    Posted Dec 15, 2014 09:35 AM

    Hi Friend,

     

    Here are the steps to configure IAP with external RADIUS,

     

    Click on "System" and fill the below details.





    Give an IP to the Virtual Controller and enable Dynamic radius Proxy. This will forward all the radius packets ( from any IAP in the cluster) to RADIUS server with the VC's IP.

    Click on "Authentication" and add a new radius Server.





    Navigate to Security - Role page and add two new roles.

    Employee : allowed to all destination.
    Contractor : limited access
    These roles can be customized based on user's requirements.






    Sample Contractor Role.




    Create a new SSID.

    Click on "New" and give a name to the SSID.





    On next page, select the Client IP assignment.

    We can have it either VC assigned or Network Assigned based on our requirements.





    On the Next page,



    Select the security as "Enterprise"
    Key Management as "WPA-2-Enterprise"
    Authentication server as < Server Name>


    On the next page,

    here we have to select the proper method to assign a role to the authenticated clients ( users).



    Please don't forget to configure the RADIUS client and other details in the server :)

     

    Hope you got some idea, please go ahead and try.

     

    Please feel free if you need any furhter help on this.



  • 5.  RE: IAP auth with external radius ?

    Posted Dec 15, 2014 09:57 AM

    thanks all for your fast responce .

    it works well but after cliend succesufull login via external radius server he can not access network shared folder that he already has access to them in active directory .

     

    please find attchement for system config and radius config that worked with me but with out access with shared folder .

     

    thanks

    Ehab



  • 6.  RE: IAP auth with external radius ?

    Posted Dec 15, 2014 10:21 AM

    Hi,

     

    What is the authenticated role assigned to the user and the policy mapped to that role, check whether you are allowing required traffic.



  • 7.  RE: IAP auth with external radius ?

    Posted Dec 15, 2014 10:33 AM

    on Active directory , user  has full control on shared folder , but when login via radius server  the user cant access this shard folder

     

    thanks ,

    Ehab



  • 8.  RE: IAP auth with external radius ?

    Posted Dec 15, 2014 10:57 AM

    Hi friend,

     

    I'm talking about the role assigned to the wireless user. always a policy will be tagged with the role.

     

    AD credentials will be used for authentication purpose. after successfull authentication user traffic will allowed asper the role and policy assigned to that user. here role can be assigned by the VC or by the RADIUS server, depends on the configuration.

     

    Please feel free still if you need help on this.

     

     

     



  • 9.  RE: IAP auth with external radius ?
    Best Answer

    Posted Dec 15, 2014 11:13 AM

    Verify which role is the user getting after passing authentication and see what ACLs do you have apply

     

     

    2014-12-15 11_13_55-Instant.png