Authentications

Authentications are used to authenticate users using a device during 802.1X or Captive portal web authentication. They are also used to authenticate user you can allow guests on the network.

Providers

Each provider has a name that will be used in the ELAN Center. It also has a description that you can use at your wish.

The following providers are available:

Internal:

User are manage via this web UI. User management can be done form the list of authentication providers.

Mainly for testing or some special accounts like Guest.

Active Directory:

This will register one or several Agents to an active directory domain for user authentication.

The Domain controller must be accessible from the Agent and the DNS configured for the agent should be able to lookup the domain.

Registration is done by an administrator of the domain, whose credentials will be used.

LDAP

One or several agents will be used to perform LDAP authentication of users.

Warning

LDAP must contain a clear text password in UserPassword attribute or NT hash password in ntPassword or sambaNTPassword attribute for some PEAP or EAP-MSCHAPv2 802.1X authentications to work.

G Suite

Authentication against Google apps suite for a domain.

This will require you to enable IMAP access for the domain.

Warning

Using this authentication provider will limit authentication methods available during 802.1X to EAP-TTLS/PAP (Extensible Authentication Protocol with Tunneled Transport Layer Security / Password Authentication Protocol).

The following operating systems are shipped with supplicants that support EAP-TTLS/PAP:

  • Microsoft Windows v8+
  • Apple Mac OS X, iOS 3.1.3+
  • Android v2.1+
  • Google Chrome OS
  • All recent Linux distributions

Groups

Groups can be used to group provider together.

Order in group is significant as this is the order that will be used to try to authenticate users.

Nested groups are supported and a provider will only be checked once per authentication. Circular groups are also supported.