Description:

This article describes how access management via RADIUS (802.1x) can be implemented on a LANCOM router or access point with LCOS. This makes it possible to centrally manage user access data.


Requirements:


Procedure:

1) Configuring RADIUS authentication on the router or access point:

1.1) Use LANconfig to connect to the router / access point for which the central access management is to be set up, switch to the menu Management → Authentication and modify the following parameters:

1.2) Go to the menu RADIUS servers.

1.3) Create a new entry and adjust the following parameters:

1.4) This concludes the configuration of the LANCOM router / access point. You can now write the configuration back to the device.



2) Configuring the RADIUS server on a LANCOM router or access point:

2.1) In LANconfig, open the configuration of the router / access point that acts as a RADIUS server. Go to the menu RADIUS → Server and set a checkmark for RADIUS authentication active.

2.2) Navigate to the menu RADIUS services ports.

2.3) Make sure that the authentication port is set to the port 1812.

2.4) Go to the menu IPv4 clients.

2.5) Create a new entry and adjust the following parameters:

2.6) Go to the menu User table.

2.7) Create a new entry and adjust the following parameters:

The LCOS supports 7 different authorizations, which are set as the Shell privilege level.

AttributeAccess rightsRemarks
1User, read-onlyAccess only to the status tree from the command line and WEBconfig
3User, write-onlyAccess only to the status tree from the command line and WEBconfig, and status tables can be reset
5Admin, read-only, no trace rightsRead-only access from the command line and WEBconfig (including configuration / setup tree)
7Admin, read and write, no trace rightsRead and write access via the command line and WEBconfig (including configuration / setup tree)
9Admin, read.onlyRead-only access from the command line and WEBconfig (including configuration / setup tree)
11Admin, read and writeRead and write access via the command line and WEBconfig (including configuration / setup tree)
15SupervisorAll access rights including access via LANconfig

2.8) This concludes the configuration of the LANCOM router / access point that acts as the RADIUS server. You can now write the configuration back to the device.