Skip to content

RADIUS settings

You can configure the device’s RADIUS server settings. A RADIUS server provides user-based authentication to improve security and control wireless device access. The access point authenticates users before they can access the network.

Restrictions

When you configure an access point with a mesh network, the following restrictions apply:

  • You can only configure a primary RADIUS server for each wireless band.
  • You can't use the internal RADIUS server.

RADIUS server

You can configure a primary and secondary RADIUS server for each frequency band and SSID on the access point.

Select the Band and SSID for the RADIUS settings, then configure the following options:

  • You can choose one of the following for RADIUS type:

    • Internal: Use the access point's built-in RADIUS server. See Internal server.
    • External: Use an external RADIUS server. If you choose External, you must configure the following options:

      • RADIUS server: Sets the IP address of the external RADIUS server.
      • Authentication port: Set the UDP port you want to use for RADIUS authentication. You must choose a port from 1 to 65535. The default is 1812.
      • Shared secret: Enter a shared secret from 1 to 99 characters in length.
      • Session timeout: Set a session timeout duration from 0 to 86400 seconds. The default is 3600.
      • Accounting: Turns RADIUS accounting on or off.
      • Accounting port: Set the UDP port you want to use for RADIUS accounting. You must choose a port from 1 to 65535. The default is 1813.
    • Central: A Sophos Central RADIUS server is configured on the selected SSID. See RADIUS Servers.