Example for Configuring AD to Perform Authentication and Authorization
Networking Requirements
As shown in Figure 5-43, an enterprise AC connects to an AP and an AD server. The AC functions as the DHCP server to assign IP addresses on the network segment 10.23.101.0/24 to STAs.
The AC authenticates access STAs in MAC+AD mode.
# Set the IP address of an AD server to 10.23.200.1 and port number to 88.
Data Planning
Configuration Item |
Data |
---|---|
AD authentication parameters |
Authentication scheme name: wlan-net Authorization scheme name: wlan-net AD server template name: template1
|
MAC access profile |
|
Authentication profile |
|
DHCP server |
The AC functions as a DHCP server to assign IP addresses to APs and STAs. |
IP address pool for APs |
10.23.100.2-10.23.100.254/24 |
IP address pool for STAs |
10.23.101.2-10.23.101.254/24 |
IP address of the AC's source interface |
VLANIF 100: 10.23.100.1/24 |
AP group |
|
Regulatory domain profile |
|
SSID profile |
|
Security profile |
|
VAP profile |
|
Configuration Roadmap
The configuration roadmap is as follows:
- Configure network interworking of the AC, APs, and other network devices.
- Select Config Wizard to configure system parameters for the AC.
- Select Config Wizard to configure the APs to go online on the AC.
- Select Config Wizard to configure WLAN services on the AC. Configure MAC address authentication and AD authentication to authenticate users.
- Complete user service verification.
Procedure
- Configure AC system parameters.
- Configure APs to go online.
- Configure WLAN services.
# Click Create. The Basic Information page is displayed.
# Configure the SSID name, forwarding mode, and service VLAN ID.
# Click Next. The Security Authentication page is displayed.
# Set Security settings to Open (applicable to personal networks).
# Click Next. The Access Control page is displayed.
# Set Binding the AP group to ap-group1.
# Click Finish.
- Configure MAC address authentication and AD authentication.
- Verify the configuration.
- STAs automatically connect to the WLAN with the SSID wlan-net.
- Choose User List, set the search criteria to SSID, enter wlan-net, and click
. STAs go online successfully and obtain IP addresses. . In