Allied Telesis AT-TQ2403 Network Card User Manual


 
AT-TQ2403 Management Software User's Guide 177
proced
ures will vary depending on the RADIUS server you use and how you configure it. For this
example, we use the Internet Authentication Service that comes with Microsoft Windows 2003 server.
Note: This document does not describe how to set up Administrative users on the
RADIUS server. In
this example, we assume you already have RADIUS server user
accounts configured. You will need a RADIUS server user name and password for both this
procedure and the following one that describes how to obtain and install a certificate on
the wireless client. Please consult the documentation for your RADIUS server for
information on setting up user accounts.
The purpose of this procedure is to identify your AT-TQ2403 Wireless Access Point as a "client" to the
RADIUS server. The RADIUS server can then handle authentication and authorization of wireless clients
for the AP. This procedure is required per access point. If you have more than one access point with
which you plan to use an external RADIUS server, you need to follow these steps for each of those APs.
Keep in mind that the information you need to provide to the RADIUS server about the access point
corresponds to settings on the access point (Security) and vice versa. You should have already provided
the RADIUS server IP Address to the AP; in the steps that follow you will provide the access point IP
address to the RADIUS server. The RADIUS Key provided on the AP is the "shared secret" you will
provide to the RADIUS server.
Note: The RADIUS server is identified by its IP address and UDP port numbers for the
differ
ent services it provides. On the current release of the AT-TQ2403 Wireless Access
Point, the RADIUS server User Datagram Protocol (UDP) ports used by the access point are
not configurable. (The AT-TQ2403 Wireless Access Point is hard-coded to use RADIUS
server UDP port 1812 for authentication and port 1813 for accounting.)
1. Log on to the system hosting your RADIUS server and bring up the Internet Authentication
Service.