
724-746-5500 | blackbox.com
Page 136
724-746-5500 | blackbox.com
Chapter 9: Common Configuration Examples
Private PSK Users to Create per Rotation: Set the number of private PSK users to generate in each set. You can generate from
1 to 9999 users in each set. The default is 10, which means that each set will contain 10 private PSK users. (1–9999)
Example: To create a user group that generates 10 private PSK users at 8:00 A.M. every day for a year starting on 06/14/2011
and make each user valid for two days, enter the following:
Figure 9-19. PSK validity period.
SmartPath EMS VMA generates a set of 20 private PSK users, consisting of two subsets:
• The first subset of 10 users is valid from 8:00 AM 2011-06-14 to 7:59 AM 2011-06-16.
• The second subset of 10 users is valid from 8:00 AM 2011-06-15 to 7:59 AM 2011-06-17.
The SmartPath AP calculates the validity periods for subsequent private PSK user sets by adding the private PSK interval to the
private PSK start time. In this example, the generation of 10 more users occurs two days later after the first 10 users expire.
Because the first 10 users are no longer valid, the new users are assigned the same key prefixes that the first 10 users had.
Similarly, when the second set of 10 users expires, the next set of users gets their prefixes. After that, new sets of 10 users are
generated every day for the rest of the year.
Automatically Binding a Private PSK to a Client MAC Address
When configuring a private PSK SSID, you have the option to bind a private PSK to the MAC address of the first client that uses it.
This provides tighter control over which devices can use the private PSK to access the network. For example, there might be a
policy permitting network connections for corporate-owned devices only, and you want to ensure that employees do not reuse
their private PSKs to go on-line with other devices that they own privately. Enabling the binding of the private PSK to a single
MAC address blocks access to all devices other than that of the first client that uses it. If an employee makes a network
connection with a corporate device first, he cannot make another connection with a different device later. On the other hand, if
he goes on-line with a privately owned device first, he will be unable to connect the company-issued device later, which will
expose the policy breach when he has to report his inability to make a network connection.
To create an SSID with the automatic private PSK-to-client MAC address binding enabled, do the following:
Click “Configuration > SSIDs, New, type a name for the SSID profile,” choose the broadcast band, enter the following, and then
click “Save:”
Private PSK: (select)
Private PSK User Groups: Select an entry in the Available Private PSK User Groups column, and then click the right arrow ( > ) to
move it to the Selected Private PSK User Groups column.
Automatically bind a private PSK to a MAC address:
Comentarios a estos manuales