Description: The following document describes how to configure LEPS (LANCOM Enhanced Passphrase Security) on a LANCOM access point and in a WLAN Controller scenario. Requirements:- LCOS as of version 7 (download latest version)
- LANtools as of version 7 (download latest version)
- The MAC check has to be activated in the logical WLAN network:
- Standalone acccess point: Wireless LAN → General → Logical WLAN settings → WLAN interface x - Network x → MAC filter enabled
- WLAN Controller: WLAN Controller → Profiles → Logical WLAN networks (SSIDs) → MAC check activated
Procedure 1) Configuring LEPS-MAC on a standalone access point: 1.1) Configuring LEPS-MAC on a standalone access point via the station rules: 1.1.1) Go to the menu item Wireless LAN → Stations/LEPS → LEPS MAC, select the option transfer data from the listed stations... and open the menu Station rules.
1.1.2) Modify the following parameters:- MAC address pattern: Enter the MAC address of a WiFi end device.
- SSID pattern: Enter the wildcard * so that the WiFi end device has access to all SSIDs.
- Name: Enter a descriptive name for the WiFi end device.
- Passphrase: Enter the WiFi password, which should be used for this WiFi end device.
1.2) Configuring LEPS-MAC on a standalone access point with an external RADIUS server: 1.2.1) Connect to the access point via LANconfig, go to the menu item Wireless LAN → Stations/LEPS → LEPS MAC and select the option transfer data from the listed stations.... 
1.2.2) Go to the menu RADIUS server settings. 
1.2.3) Erstellen Sie einen neuen Eintrag und passen die folgenden Parameter an:
- Server address: Enter the IP address of the RADIUS server.
- Secret: Enter a password, which the access point uses for authentication with the RADIUS server.

1.2.4) Go to the menu Wireless LAN → Stations/LEPS and select the option MAC address for the RADIUS server password source. 
2) Configuring LEPS-MAC on a WLAN Controller: 2.1) Configuring LEPS-MAC on a WLAN Controller via the station rules: 2.1.1) Go to the menu RADIUS → Server and activate the option RADIUS authentication active to activate the RADIUS server. 2.1.2) Go to the menu WLAN Controller → Stations/LEPS → Station rules. 2.1.3) Modify the following parameters:- MAC address pattern: Enter the MAC address of a WiFi end device.
- SSID pattern: Enter the wildcard * so that the WiFi end device has access to all SSIDs.
- Name: Enter a descriptive name for the WiFi end device.
- Passphrase: Enter the WiFi password, which should be used for this specific WiFi end device.
2.2) Configuring LEPS-MAC on a WLAN Controller via an external RADIUS server: 2.2.1) Connect to the WLAN Controller via LANconfig and go to the menu WLAN Controller → Profiles → RADIUS profiles. 2.2.2) Click Add, to create a new RADIUS profile. 2.2.3) Modify the following parameters: - Name: Enter a descriptive name for the profile (in this example RADIUS-EXT).
- IP address: Enter the IP address of the RADIUS server.
- Secret: Enter a password, which the access points use for authentication with the RADIUS server.

2.2.4) Go to the menu WLAN Controller → Profiles → Logical WLAN networks (SSIDs). 2.2.5) Edit the logical WLAN network to be used with LEPS-MAC and modify the following parameters: - In the dropdown menu for the RADIUS profile select the profile created in step 2.2.3.
- Activate the option MAC check activated.
|