Yes, neither the ASG nor the AP perform RADIUS authentication as every other AP as well. That's the job of an authentication server. The AP itself only relays frames from the wireless clients to the RADIUS server as the wireless client is not yet authorized to access the according network.
The AP firmware previously had a bug that refused EAP authentication on bridge-to-LAN wifi networks. That's fixed in 7.507+.
Maybe this is interesting for you as well:
https://community.sophos.com/products/unified-threat-management/astaroorg/f/107/t/69986
Regards,
Helmut
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
So, Helmut, do I need to define any packet filters for RADIUS access for the APs or connected clients? I saw a bunch of drops for the RADIUS port when I tried this -- so I added some packet filters to take care of it.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
Dos Anyone know if the astaro PEAP-Offload og PEAP-Passthroug mode?