Case Study - Configuration between NXC2500 and LDAP Server 1
1. Scenario:... 3 2. Topology:... 4 3. Step-by-step Configurations:...4 a. Configure NXC2500:...4 b. Configure LDAP setting on NXC2500:...10 c. Windows wireless connection setting:...13 4. Verification:......22 5. Reference:..23 2
1. Scenario A customer may have an NXC2500 controller to manage applications on the network and wants to use an LDAP server for wireless authentication instead of a pre-shared key. In this kind of an application, wireless clients do not need to remember pre-shared keys, which are not easy to remember because MIS needs to make the key complicated or change pre-share key every day in order to reduce the security risk. MIS could use a staff s working account as a username and password in the LDAP database so that wireless clients will not easily forget the authentication information. Otherwise, MIS does not need to require all the staff to remember new passwords, if someone does not work in the company anymore. MIS can just delete the user from the LDAP server to prevent users who are not working company from connecting to the wireless network. Customer Background Info and Requirements: 1. Customer has a NXC controller and LDAP server in the network. 2. Customer can centralize managing the wireless clients authentication information in LDAP database and APs. Proposal: 1. We will use one Wireless LAN Controller (NXC2500) to control the managed APs. 2. Customer can create a username and password for wireless authentication in LDAP database. 3
2. Topology 3. Step-by-step Configuration a. Configure NXC2500 Step 1. Go to Configuration > Interface > VLAN to remove ge1 from vlan0. 4
Step 2. Set ge1 interface type to External and get IP address automatically. 5
Step 3. Enable DHCP server in vlan 0, IP pool address starts from 192.168.1.200, pool size 20. Step 4. Configure policy route to allow the LAN to accesses the Internet. In Configuration > Network > Routing add a policy route. 6
7
Step 5. Configure AP Profile 5-1 In Configuration > Object > AP Profile > SSID 5-2 In Configuration > Object > AP Profile > SSID > Security List 8
5-3 In Configuration > Object > AP Profile > Radio > Edit to choose configured SSID Profile. 9
b. Configure LDAP setting on NXC2500 Please notice the user password in LDAP server is plain text in this example. Step 1. Configure AAA server In Configuration > Object > AAA Server > LDAP > Edit 10
Step 2. Test LDAP user 11
Step 3. Configure Auth. Method In Configuration > Object > Auth. Method > Edit to add group ldap 12
c. Windows wireless connection setting Step 1. Open Network and Sharing Center. 13
Step 2. Click on Manage wireless networks. Step 3. Click on Add to add a new wireless profile. 14
Step 4. Click on Manually create a network profile to create a new wireless manually. 15
Step 5. Key-in the SSID that you configured in NXC2500 in Network name field and select Security type and Encryption type that you configured in NXC2500 AP profile. Step 6. Click on Properties to continue to the detailed settings. Step 7. Click Security tab for more settings 16
Step 8. Uncheck the Validate server certificate and then click on Configure. 17
Step 9. Uncheck Automatically sue my Windows login name and password (and domain if any). Then, go back to Protected EAP Properties and click on the OK button. Step 10. Click on Advanced Settings. 18
Step 11. Place a check in the Specify authentication mode and select user or computer authentication. 19
Step 12. Return to the Wireless Network Connection and click on the SSID that you configured manually before. Note: if the Encryption type setting does not meet the setting in NXC2500, you will see a cross shown on the picture. 20
Step 13. Enter the username and password created in the LDAP server. The wireless authentication will be successful. 21
4. Verification from NXC2500. Go to Monitor > Log 22
5. Reference The LDAP encryption is supported on NXC2500. We provide the list of authentication methods, which can be supported. The following table shows the user authentication methods on NXC2500 to support with the password form stored in LDAP server DB. For example, if a customer wants to create a password with SHA1 encryption in the LDAP server for a user, the customer needs to choose network authentication method as EAP-TTLS and Authentication Protocol as PAP on wireless station. 23
24