RADIUS Servers
When using enterprise encryption for SSIDs, you must provide an external RADIUS server or identity provider (IdP) for authentication. On the RADIUS Servers page, you can create and manage RADIUS servers and IdPs to use with your AP6 SSIDs.
The RADIUS servers and IdP configured on the RADIUS Servers page can only be used with AP6 SSIDs. For APX SSIDs, you must enter the IP address of the RADIUS server you want to use when creating the SSID. For more information, see Settings.
You can see the following information about your RADIUS servers and IdP:
- Name: The name assigned to the RADIUS server or IdP.
- Type: Whether the server is a RADIUS server or an IdP.
- Domain/IP address: The domain name for the IdP or the IP addresses of the primary and secondary RADIUS servers.
- SSID count: The number of SSIDs assigned to the RADIUS server or IdP.
Click the Edit button
to edit a RADIUS server or IdP.
Click the Delete button
to delete a RADIUS server or IdP.
Add a RADIUS server or identity provider
You can add external RADIUS servers and IdPs by clicking Add.
Click the appropriate tab below for instructions.
Configure a primary and secondary RADIUS server as follows:
- Click Add and select Add external RADIUS server.
-
Enter a unique Name.
This name is used to identify the RADIUS server on the RADIUS Servers page and the RADIUS server drop-down list when creating an AP6 SSID.
-
Enter the IP address of the primary RADIUS server for Server address.
- Enter the Port used to communicate with the server or leave it as the default RADIUS port,
1812. - Enter the Password used to connect to the server.
-
(Optional) Select Enable secondary RADIUS server to enter the Server address, Port, and Password for the secondary RADIUS server.
Devices use the secondary RADIUS server for authentication if the connection to the primary RADIUS server fails.
-
Click Save.
Configure Microsoft Entra ID as an external IdP as follows:
You'll need the values for the Client ID, Client secret, Domain name, and Tenant ID from Entra ID. To find out how to get these values and configure Entra ID for Sophos Central wireless, see Configure Entra ID for AP6 authentication.
- Click Add and select Add external identity provider.
-
Enter a unique Name.
This name is used to identify the IdP on the RADIUS Servers page and the RADIUS server drop-down list when creating an AP6 SSID.
-
Enter your Application ID from Entra ID as the Client ID.
- Enter the Client secret.
- Enter your verified Entra ID custom domain name as the Domain name.
- Enter the Directory ID from Entra ID as the Tenant ID.
-
Click Test connection.
A message indicates whether the external IdP connection test succeeded.
-
Click Save.