How to Configure
Devices


In Policy Manager, you can configure devices for authentication, whereby users identify themselves to the network and are given customized access capabilities based on what role they serve in the organization. Policy Manager uses a RADIUS server and an authentication-enabled switch to allow the active role on a port to be dynamically assigned, based on the user's login.

You can configure authentication for a single device or for multiple devices. You can also configure authentication parameters on individual ports (see How to Configure Ports), but you need to configure and enable authentication on the device before any port authentication settings will take effect.

You can configure devices in two ways:

Instructions on:

Using the Device Configuration Wizard

The Device Configuration Wizard is a series of windows enabling you to define an authentication configuration, then apply it to the devices of your choosing. You can elect to configure authentication settings only, RADIUS client/server communication settings, or both. You can also configure MAC Locking, Rule Accounting, and CEP (Convergence End Point) for the devices, and a device-level role for Matrix C1 devices only.

  1. From the menu bar, select Tools > Device Configuration Wizard.

Select Options to Configure

  1. In the Device Configuration window, select the components you wish to configure.

Configure Settings

  1. The sequence of windows you see next depends on the selections you made in the Device Configuration window.
      NOTE: Each window provides the option to use the current configuration on the device(s), or set a new configuration. If you select Use Current Configuration on Device(s), the default settings in the window are visible, but are unavailable for entry or editing. Keep in mind that these values do not necessarily reflect the current settings on the device.

    If you have selected to configure Authentication
    All the windows you could see are listed below, but only those related to the Authentication type(s) you selected will actually appear:

    If you have selected to configure RADIUS
    All the windows you could see are listed below, but only those related to the RADIUS options you selected will actually appear:

    If you have selected General:
    All the windows you could see are listed below, but only those related to the options you selected will actually appear:

Select Devices

  1. In the Device Selection window, select the device(s) to which you want this configuration to apply.
  2. Click Finish.

  NOTE: If you elected to enable authentication as part of the device configuration, and chose the "Select Ports to set to Inactive/Default Role" option, the Set Authentication State to Inactive/Default Role window now appears. Make your selections and click OK to complete the wizard.

Using the Device Tabs

Configuring a device using the device tabs enables you to set up or modify the same options found in the Device Configuration Wizard, but for a selected device, using the right-panel device tabs.

  NOTE: When you create or import a device, Policy Manager determines whether or not authentication is enabled on the device. If so, the appropriate Authentication Type is displayed in the device's Authentication tab, with the Authentication Status set to Enabled.  If no authentication is enabled on the device, Policy Manager displays the previous Authentication Type setting for the device if there was one, or Authentication Type: Web-Based if not.

To configure a device using the device tabs:

  1. In the left-panel Network Elements tab, select the device you want to configure. Use the right-panel tabs to configure the device.
  2. Select the Authentication tab and fill out the tab as required. Be sure to click Apply in any part of the tab you change.
  3. Select the RADIUS tab and fill out the tab as required.
  4. To enable MAC Locking, select the MAC Locking tab and configure the options as desired.
  5. In the right panel, select the Role/Rule tab and configure a device-level role (Matrix C1 devices only) or enable Rule Accounting as desired.
  6. To enable CEP (Convergence End Point), select the CEP tab and configure the options as desired.
  7. Select the General tab and choose your Class of Service mode.

Turning Off Device Contact on Startup

When Policy Manager is launched, it automatically contacts the devices. However, this can take some time when you have many devices. If it is not required that Policy Manager and the devices be synchronized each time you launch Policy Manager, you can turn off the device contact at launch by deselecting the Contact Devices on Startup option in the Options Startup view (Tools > Options).

Top


Related Information

For information on related concepts: For information on related tasks: For information on related windows: top