Steps for configuring WPA2-Enterprise on firewall acting as the AP Controller with a RADIUS server

Options
Zyxel_JoyLee
Zyxel_JoyLee Posts: 148 image  Zyxel Employee
Friend Collector First Anniversary

This guide explains the process for configuring WPA2-Enterprise on Zyxel’s USG FLEX H-Series acting as the AP Controller (APC) with a RADIUS server using Windows NPS. Below are the steps:

  1. Create AAA server on USG FLEX firewall

Go to User & Authentication > User Authentication > AAA Server > Radius Server

image.png

2. Configure SSID with wpa2 enterprise and WPA Enterprise with internal authentication

server.

a. wireless-wlan settings > ssid settings > advanced mode enabled

b. Edit SSID

Authentication Server is the AAA server you configured on step 1

image.png

3. On radius server (Windows NPS)

a. Configure the IP address of the firewall interface as a RADIUS client on the RADIUS server, and configure the same shared secret as the AAA server on the firewall.

image.png

b. Policies > Network Polices > Constraints > Authentication Methods > Microsoft:Protected EAP(PEAP)

image.png

c. Create a radius user on AD server

d. NB connects the SSID and use radius user name/password for 1x auth