Account@Adapter+ Authentication Integration Setup Examples
This document outlines the configuration examples for integrating the Account@Adapter+ authentication appliance with Buffalo wireless access points (WAPM-2133TR, WAPM-AX8R, WAPM-1266R, WAPS-1266) using IEEE802.1X EAP-TLS and EAP-PEAP environments.
The setup examples assume that the basic Wi-Fi functionality of the Buffalo wireless access points has already been configured. This document focuses on the necessary settings for IEEE802.1X EAP-TLS and EAP-PEAP.
This document is based on the specifications of the latest version at the time of writing (Ver. 6.18.00). Please note that the displayed screens may vary slightly depending on your environment.
This document describes the operational procedures for the Account@Adapter+ authentication appliance and Buffalo wireless access points (WAPM-2133TR, WAPM-AX8R, WAPM-1266R, WAPS-1266) based on our verification. We do not guarantee operation in all environments.
Table of Contents
- Configuration
- Account@Adapter+ Configuration
- RADIUS Client Configuration
- Client Configuration for EAP-TLS Authentication
- Client Configuration for EAP-PEAP Authentication
1. Configuration
1-1 Configuration Diagram
The following environment will be configured:
- Account@Adapter+ (RADIUS CA/DHCP Server): 192.168.10.2/24
- PoE Switch
- Buffalo Wireless Access Points (WAPM-2133TR, WAPM-AX8R, WAPM-1266R, WAPS-1266) as RADIUS Clients with respective IP addresses.
- Client Devices (Windows, macOS, iOS, Android)
1-2 Environment
1-2-1 Devices
Product Name | Manufacturer | Role | Version |
---|---|---|---|
Account@Adapter+ | HC Networks | RADIUS Server, DHCP Server, CA | 6.18.00 |
WAPM-2133TR | Buffalo | RADIUS Client | 1.27 |
WAPM-AX8R | Buffalo | RADIUS Client | 1.27 |
WAPM-1266R | Buffalo | RADIUS Client | 1.28 |
WAPS-1266 | Buffalo | RADIUS Client | 1.27 |
ThinkPad X13 Yoga Gen 1 | Lenovo | 802.1X Client Device | Windows 11 Pro 22H2 |
MacBook Air | Apple | 802.1X Client Device | macOS Ventura 13.2.1 |
iPad | Apple | 802.1X Client Device | 16.3.1 |
Lenovo Tab K10 | Lenovo | 802.1X Client Device | Android11 |
Note: The product and OS versions listed are based on the verification conducted at the time of this document's creation. Please select versions that address vulnerabilities when using the products and OS.
1-2-2 Authentication Methods
The following authentication methods were verified:
- IEEE802.1X EAP-TLS
- IEEE802.1X EAP-PEAP
1-2-3 Network Settings
Product Name | IP Address | RADIUS Port | Secret Key |
---|---|---|---|
Account@Adapter+ | 192.168.10.2/24 | 1812 | buffalo |
WAPM-2133TR | 192.168.10.11/24 | 1812 | buffalo |
WAPM-AX8R | 192.168.10.12/24 | 1812 | buffalo |
WAPM-1266R | 192.168.10.13/24 | 1812 | buffalo |
WAPS-1266 | 192.168.10.14/24 | 1812 | buffalo |
ThinkPad X13 Yoga Gen 1 | DHCP | - | - |
MacBook Air | DHCP | - | - |
iPad | DHCP | - | - |
Lenovo Tab K10 | DHCP | - | - |
2. Account@Adapter+ Configuration
The setup will proceed as follows:
- Access to Management Screen
- Network Settings
- CA Settings
- RADIUS Settings
- Account Registration
- DHCP Settings
- Certificate Issuance/Download
2-1 Access to Management Screen
To configure Account@Adapter+, access the management screen.
The initial IP address of Account@Adapter+ is 192.168.0.1/24. When performing settings, please set the IP address of the client device to the same segment.
Connect the client device and Account@Adapter+ LAN1 (left side) directly with a LAN cable.
Launch Microsoft Edge and access the following URL: http://192.168.0.1:8080/manager/
Enter the administrator ID and password to log in to the management screen.
- Login ID: naadmin
- Password: naadmin
2-2 Network Settings
Configure IP address settings.
Navigate to Management Tool [Environment Settings] - [Network Settings] - [Maintenance Menu].
After setting, click [Register] at the bottom of the screen.
Network Settings
Setting Item | Setting Value |
---|---|
IP Address | 192.168.10.2 |
Subnet Mask | 255.255.255.0 |
Default Gateway | 192.168.10.1 |
2-3 CA Settings
Open Management Tool [CA] - [CA Settings] and click [Settings] for CA.
After setting, click [Register] at the bottom of the screen. After clicking [Register], click [Reflect RADIUS Settings] at the top left of the screen.
Self-Signed Certificate Information Settings
Setting Item | Setting Value |
---|---|
Certificate Authority | Self-Signed Certificate |
Name (cn) | ca_buffalo |
Country (c) | Japan (JP) |
State/Province (st) | Tokyo |
CRL Distribution Point | Do not use |
OCSP URI | Do not use |
2-4 RADIUS Settings
2-4-1 RADIUS Settings
Open Management Tool [RADIUS] - [RADIUS Settings].
After setting, click [Register] at the bottom of the screen. After clicking [Register], click [Reflect RADIUS Settings] at the top left of the screen.
RADIUS Settings
Setting Item | Setting Value |
---|---|
RADIUS Port Number | 1812 |
RADIUS Accounting | Use |
Connection Status | Record |
Authentication Server Certificate | Internal Server Certificate |
Internal Authentication Authority | Internal Authentication Authority |
IEEE 802.1X Authentication | EAP-TLS/PEAP |
2-4-2 RADIUS Client Registration
Open Management Tool [RADIUS] - [RADIUS Client].
Click [New Registration] at the top of the screen.
RADIUS Client Registration
Setting Item | Setting Value 1 | Setting Value 2 | Setting Value 3 | Setting Value 4 |
---|---|---|---|---|
Client ID | WAPM-2133TR | WAPM-AX8R | WAPM-1266R | WAPS-1266 |
IP Address | 192.168.10.11 | 192.168.10.12 | 192.168.10.13 | 192.168.10.14 |
Secret Key | buffalo | buffalo | buffalo | buffalo |
After setting, click [Register] at the bottom of the screen. After clicking [Register], click [Reflect RADIUS Settings] at the top left of the screen.
2-5 Account Registration
2-5-1 Certificate Account Registration for EAP-TLS Authentication
Open the [Certificates] tab in the desired directory of the certificate account creation.
Click [New Registration].
Certificate Account Registration
Setting Item | Setting Value |
---|---|
cn | cert01 |
After setting, click [Register] at the bottom of the screen.
2-5-2 User Account Registration for EAP-PEAP Authentication
Open the [User] tab in the desired directory of the certificate account creation.
Click [New Registration].
User Account Registration
Setting Item | Setting Value |
---|---|
User ID | user01 |
Password | buffalo |
Account Expiration Date | No expiration |
After setting, click [Register] at the bottom of the screen.
2-6 DHCP Settings
2-6-1 Server Group Settings
Open Management Tool [DHCP] - [Server Group].
Click [Server Group Registration].
Server Group Registration
Setting Item | Setting Value |
---|---|
Group Name | servergroup_buffalo |
Primary Server Number | 01 |
Primary IP Address | 192.168.10.2 |
Primary Network Mask | 255.255.255.0[/24] |
After setting, click [Register] at the bottom of the screen. After clicking [Register], click [Reflect DHCP Settings] at the top left of the screen.
2-6-2 Scope Settings
Open Management Tool [DHCP] - [Scope Settings] - [Scope Settings] tab.
Click [New Registration] at the top of the screen.
Scope Settings Registration
Setting Item | Setting Value |
---|---|
Group Name | servergroup buffalo |
Scope Name | scope_buffalo |
Network Address | 192.168.10.0 |
Netmask | 255.255.255.0[/24] |
Default Router | 192.168.10.1 |
Address Range 001 | Issuance |
Address Range | 192.168.10.101 |
Address Range | 192.168.10.200 |
After setting, click [Register] at the bottom of the screen. After clicking [Register], click [Reflect DHCP Settings] at the top left of the screen.
2-7 Certificate Issuance/Download
2-7-1 Client Certificate Issuance/Download for EAP-TLS Authentication
Open the [Certificates] tab in the directory where the certificate account was created in 2-5-1.
Click [Issue] in the "Certificate 1" column.
Click [OK].
Click [DL Not Yet] in the "Certificate 1" column.
Enter any desired value in [Import Password] and click [Execute].
Confirm that the certificate file has been downloaded.
2-7-2 CA Certificate Download for EAP-PEAP Authentication
Open Management Tool [CA] - [CA Settings] and click [p12] for CA.
Confirm that the certificate file has been downloaded.
3. RADIUS Client Configuration
The setup will proceed as follows:
- Access to Management Screen
- IP Address Settings
- RADIUS Settings
- SSID Settings
3-1 Access to Management Screen
The Buffalo wireless access points WAPM-2133TR, WAPM-AX4R, WAPM-1266R, and WAPS-1266 can be configured using the same method. Therefore, this document uses WAPM-2133TR as a representative example for configuration.
To configure the wireless access point, access the management screen.
The initial IP address of the Buffalo wireless access point is automatically obtained via DHCP. If there is no DHCP server environment, the IP address will be 192.168.11.100/24. Therefore, when setting up, please set the IP address of the client device to the same segment.
Connect the client device and the wireless access point's LAN1 (left side) directly with a LAN cable.
Launch Microsoft Edge and access the following URL: 192.168.11.100
Enter the administrator ID and password to log in to the management screen.
- Login ID: admin
- Password: password
3-2 IP Address Settings
Configure IP address settings.
Navigate to Advanced Settings [LAN Settings] - [IP Address].
After the above settings, click [Register] at the bottom of the screen.
After changing the IP address, restart Microsoft Edge and access the following URL: 192.168.10.11
Network Settings
Setting Item | Setting Value |
---|---|
IP Address Acquisition Method | Manual Settings |
IP Address | 192.168.10.11 |
Subnet Mask | 255.255.255.0 |
3-3 RADIUS Settings
Open Advanced Settings [Network Settings] - [RADIUS Settings] tab.
Click [Settings] at the bottom of the above settings.
Scope Settings Registration
Setting Item | Setting Value |
---|---|
Server | External |
Server Name | 192.168.10.2 |
Authentication Port | 1812 |
Shared Secret | buffalo |
3-4 SSID Settings
Open SSID Settings. Click [New Creation] in the center of the screen.
Scope Settings Registration
Setting Item | Setting Value |
---|---|
Wi-Fi | Enabled |
SSID | 2133TR |
Usable Devices | 2.4GHz, 5GHz Low, 5GHz High (For devices other than WAPM-2133TR, 2.4GHz and 5GHz) |
Wi-Fi Authentication | WPA2 Enterprise |
RADIUS | Use RADIUS server settings in Network Settings |
After setting, click [Save Changes] at the bottom of the screen.
4. Client Configuration for EAP-TLS Authentication
The EAP-TLS authentication procedure for the following OSs is described below:
- Windows 11 EAP-TLS Authentication
- macOS EAP-TLS Authentication
- iOS EAP-TLS Authentication
- Android EAP-TLS Authentication
Note: The following describes EAP-TLS authentication via the RADIUS client "WAPM-2133TR". The procedure is the same for other RADIUS clients (WAPM-AX8R/WAPM-1266R/WAPS-1266).
4-1 Windows 11 EAP-TLS Authentication
Preparation: Import the client certificate to your PC.
EAP-TLS Authentication Procedure:
- Click SSID "2133TR".
- Click [Connect].
- Click [Connect using certificate].
- Click [Connect].
4-2 macOS EAP-TLS Authentication
Preparation: Import the client certificate to your PC.
EAP-TLS Authentication Procedure:
- Click SSID "2133TR".
- Select [cert01] from the dropdown.
- Click [OK].
- Click [Continue].
4-3 iOS EAP-TLS Authentication
Preparation: Import the client certificate to your PC.
EAP-TLS Authentication Procedure:
- Click SSID "2133TR".
- Click [Mode] and select [EAP-TLS].
- Click [ID] and select [cert01].
- Click [Connect].
- Click [Trust].
4-4 Android EAP-TLS Authentication
Preparation: Import the client certificate to your PC.
EAP-TLS Authentication Procedure:
- Click SSID "2133TR".
- Enter/select the values described in the table for items ② to ⑦.
- Click [Connect].
Authentication Settings
Setting Item | Setting Value |
---|---|
EAP Method | TLS |
CA Certificate | ca_buffalo |
Online Certificate Status | Do not verify |
Domain | ca_buffalo |
User Certificate | (Select client certificate) |
ID | cert01 |
5. Client Configuration for EAP-PEAP Authentication
The EAP-PEAP authentication procedure for the following OSs is described below:
- Windows 11 EAP-PEAP Authentication
- macOS EAP-PEAP Authentication
- iOS EAP-PEAP Authentication
- Android EAP-PEAP Authentication
Note: The following describes EAP-PEAP authentication via the RADIUS client "WAPM-2133TR". The procedure is the same for other RADIUS clients (WAPM-AX8R/WAPM-1266R/WAPS-1266).
5-1 Windows 11 EAP-PEAP Authentication
Preparation: Import the CA certificate to your PC.
EAP-PEAP Authentication Procedure:
- Click SSID "2133TR".
- Click [Connect].
- Enter Username:user01 Password:buffalo.
- Click [OK].
- Click [Connect].
5-2 macOS EAP-PEAP Authentication
Preparation: Import the CA certificate to your PC.
EAP-PEAP Authentication Procedure:
- Click SSID "2133TR".
- Enter Account Name:user01 Password:buffalo.
- Click [OK].
- Click [Continue].
5-3 iOS EAP-PEAP Authentication
Preparation: Import the CA certificate to your PC.
EAP-PEAP Authentication Procedure:
- Click SSID "2133TR".
- Enter Username:user01 Password:buffalo.
- Click [Connect].
- Click [Trust].
5-4 Android EAP-PEAP Authentication
Preparation: Import the CA certificate to your PC.
EAP-PEAP Authentication Procedure:
- Click SSID "2133TR".
- Enter/select the values described in the table for items ② to ⑧.
- Click [Connect].
Authentication Settings
Setting Item | Setting Value |
---|---|
EAP Method | PEAP |
Phase 2 Authentication | MSCHAPV2 |
CA Certificate | ca_buffalo |
Online Certificate Status | Do not verify |
Domain | ca_buffalo |
ID | user01 |
Password | buffalo |
Contact Information
For inquiries, please contact:
HC Networks, Ltd.
Address: 1-22-16 Asakusabashi, Taito-ku, Tokyo 111-0053, Japan
Website: https://www.hcnet.co.jp/
Buffalo Inc.
Address: Akamon-dori Building, 3-30-20 Osu, Naka-ku, Nagoya, Aichi 460-8315, Japan
Website: https://www.buffalo.jp/
HC NET and its logo are registered trademarks of HC Networks, Ltd. Company and product names mentioned are trademarks or registered trademarks of their respective companies. Some product photos are for illustrative purposes only.
When exporting products, please confirm and complete the necessary procedures in accordance with foreign export-related laws and regulations, such as the Foreign Exchange and Foreign Trade Act and the US Export Administration Regulations. If you have any questions, please contact our sales representative.