SINGLE CONNECT
...
2 Single Connect Portal GUI
2.15 802.1x Authentication
5 min
802 1x authentication https //archbee io/docs/1s a8r9fnbldt7zdyf13d/pajdtgalutnivxukikuxa#802 1x authentication this configuration have two phases and first phase of the configuration requires higher level of modification please ask consultation from kron technical support for these steps https //sc support\@kron com epdestek\@kron com tr single connect gui configurations single connect admins should follow the steps below log in to the single connect web gui create user and user group (see also create device group and add new device to device group (see also create device group realm with the user group and device group defined at step 2 (see note ) define the authenticator secret key as navigate to administration> radius 802 1x config choose an eap type (only peap is available for now as eap type) fill in the “certificate authority pem”, “certificate private key pem” (which has certificate and private key) and “certificate private key password” fields note the device that is added at step 3 must be the last destination ip that sends an authentication request to single connect for example, wireless lan controller, firewall etc 1\ if dynamic vlan and mac filtering are to be activated, the check box should be selected (see also mac filtering configuration) note vlans can be dynamically assigned by a radius server to supplicants requesting 802 1x authentication through that server if dynamic vlan is assigned to supplicants, the following 2 settings must be set in single connect 1 choose dynamic vlan check box in the 802 1x config screen 2\ radius attribute policy should be defined on related user group as vlan interval see also “adding radius/tacacs+ attribute” at tacacsthe tacacs access manager section in the admin guide 2\ select the “add sc server to active directory” option and fill the necessary fields mac filtering configurations if mac addresses are defined for a user, that user can use only those mac addresses the same mac address can be defined to different users users cannot use undefined mac addresses for radius authentication to activate mac filtering while using 802 1x authentication, follow the steps below the "mac filtering" option in the "administration / radius 802 1x config" screen must be selected allowed mac addresses must be defined log in to the single connect web gui navigate to administration > mac filtering enter user mac address and username save