Cisco Cisco Access Registrar 4.2 Spécifications Page 242

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 636
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 241
5-58
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 5 Configuring Security Solutions
Configuring Identity Networking
Identity Networking Overview
In most wireless LAN systems, each WLAN has a static policy that applies to all clients associated with
an SSID. Although powerful, this method has limitations since it requires clients to associate with
different SSIDs to inherit different QoS and security policies.
However, the Cisco Wireless LAN Solution supports identity networking, which allows the network to
advertise a single SSID but allows specific users to inherit different QoS or security policies based on
their user profiles. The specific policies that you can control using identity networking include:
Quality of Service. When present in a RADIUS Access Accept, the QoS-Level value overrides the
QoS value specified in the WLAN profile.
ACL. When the ACL attribute is present in the RADIUS Access Accept, the system applies the
ACL-Name to the client station after it authenticates. This overrides any ACLs that are assigned to
the interface.
VLAN. When a VLAN Interface-Name or VLAN-Tag is present in a RADIUS Access Accept, the
system places the client on a specific interface.
Note The VLAN feature only supports MAC filtering, 802.1X, and WPA. The VLAN feature does
not support web authentication or IPSec.
Tunnel Attributes.
Note When any of the other RADIUS attributes (QoS-Level, ACL-Name, Interface-Name, or
VLAN-Tag), which are described later in this section, are returned, the Tunnel Attributes
must also be returned.
The operating system’s local MAC filter database has been extended to include the interface name,
allowing local MAC filters to specify to which interface the client should be assigned. A separate
RADIUS server can also be used, but the RADIUS server must be defined using the Security menus.
RADIUS Attributes Used in Identity Networking
This section explains the RADIUS attributes used in identity networking.
QoS-Level
This attribute indicates the Quality of Service level to be applied to the mobile client's traffic within the
switching fabric, as well as over the air. This example shows a summary of the QoS-Level Attribute
format. The fields are transmitted from left to right.
0123
01234567890123456789012345678901
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Type | Length | Vendor-Id
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
Vendor-Id (cont.) | Vendor type | Vendor length |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| QoS Level |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
Vue de la page 241
1 2 ... 237 238 239 240 241 242 243 244 245 246 247 ... 635 636

Commentaires sur ces manuels

Pas de commentaire