Previous Page Go Index Next Page

IEEE802.1X Authentication


This page explains how to configure the settings to use IEEE802.1X authentication.


1. Supported 802.1X Authentication Methods

2. Standard and Saving Format for Certificate

3. IEEE 802.1X Settings


1. Supported 802.1X Authentication Methods

DS-520AN supports the following IEEE802.1X authentication methods.

PEAP(PEAPv0)
EAP-TLS
EAP-TTLS
LEAP
EAP-FAST


2. Standard and Saving Format for Certificate

Standard for Certificate

DS-520AN supports the standard of certificate as follows:

Key exchange method RSA
Key size 512bit, 1024bit, 2048bit
Signature algorithm SHA1withRSA
SHA224withRSA
SHA256withRSA
SHA384withRSA
SHA512withRSA
MD5withRSA

Saving Format for Certificate

DS-520AN supports the saving format of certificate as follows:

Client certificate PKCS#12
PFX
CA certificate for server authentication DER (Binary encoded X509)
PEM (BASE64-encoded text format of DER)


3. IEEE 802.1X Settings

Access the Web page of DS-520AN.


The login page is displayed.
Enter the password for DS-520AN and click Login.

  • By default, no password is configured to DS-520AN.

The Web page of DS-520AN is displayed.
From the left menu on the Web page, click Security - IEEE 802.1X.


The Wireless LAN Configuration page is displayed.
Click Detailed Configuration tab.

The detailed wireless configuration page is displayed.
Configure each setting and click Submit.

Authentication Method Set the EAP authentication method (EAP-TLS/EAP-TTLS/PEAP/EAP-FAST/LEAP).
EAP-TLS
EAP User Name Set an EAP user name for the EAP authentication. This name is used by the server to identify a client.
None
EAP Password Set an EAP password for the EAP authentication.
This password is used to check client reliability when EAP-TTLS or PEAP or EAP-FAST or LEAP is used as authentication method.
None
Inner Authentication Method Set the inner authentication method (PAP/CHAP/MSCHAP/MSCHAPv2) to perform in TLS tunneling of the EAP authentication.
When PEAP is used as authentication method, this is fixed to MS-CHAPv2.
None
Client Certificate Password Set a client certificate password to use for client authentication on the EAP authentication.
This setting is necessary when a password is set to the client certificate.
None
Client Certification Select a client certificate to use for client authentication on the EAP authentication.
This is used when EAP-TLS is used as authentication method.
None
Server Authentication Specify whether to check reliability of the server on EAP authentication.
When ON is selected, CA certificate for server authentication is required.
None
CA Certification Select a CA certificate to use for server authentication on the EAP authentication.
This setting is necessary when ON is selected for server authentication.
None
Auto PAC Provisioning Enable/Disable auto-distribution of PAC (Protected Access Credential) when using EAP-FAST authentication (ON/OFF).
When auto-distribution is disabled, you need to register the PAC file issued from the server.
OFF
PAC File
Register the PAC file issued from the server to use for manual distribution of PAC (Protected Access Credential) when using EAP-FAST authentication.
None

EAP User Name Necessary Necessary Necessary Necessary Necessary
EAP Password Necessary -- Necessary Necessary Necessary
Inner Authentication Method -- -- Necessary -- --
Client Certification -- Necessary -- -- --
Client Certificate Password -- Optional -- -- --
Server Authentication Optional Optional Optional -- --
CA Certification Optional Optional Optional -- --
Auto PAC Provisioning -- -- -- -- Optional
PAC File -- -- -- -- Optional

The Restart page is displayed. Click Restart to restart DS-520AN.
The changes will take effect after restart.

When the login page is displayed, the reboot is completed.
Finish the Web browser.


Go PageTop Previous Page Go Index Next Page