RADIUS settings
You can configure the device’s RADIUS server settings. A RADIUS server provides user-based authentication to improve security and control wireless device access. The access point authenticates users before they can access the network.
Restrictions
When you configure an access point with a mesh network, the following restrictions apply:
- You can only configure a primary RADIUS server for each wireless band.
- You can't use the internal RADIUS server.
RADIUS server
You can configure a primary and secondary RADIUS server for each frequency band and SSID on the access point.
Select the Band and SSID for the RADIUS settings, then configure the following options:
-
You can choose one of the following for RADIUS type:
- Internal: Use the access point's built-in RADIUS server. See Internal server.
-
External: Use an external RADIUS server. If you choose External, you must configure the following options:
- RADIUS server: Sets the IP address of the external RADIUS server.
- Authentication port: Set the UDP port you want to use for RADIUS authentication. You must choose a port from 1 to 65535. The default is 1812.
- Shared secret: Enter a shared secret from 1 to 99 characters in length.
- Session timeout: Set a session timeout duration from 0 to 86400 seconds. The default is 3600.
- Accounting: Turns RADIUS accounting on or off.
- Accounting port: Set the UDP port you want to use for RADIUS accounting. You must choose a port from 1 to 65535. The default is 1813.
-
Central: A Sophos Central RADIUS server is configured on the selected SSID. See RADIUS Servers.