
724-746-5500 | blackbox.com
724-746-5500 | blackbox.com
Page 135
Chapter 9: Common Configuration Examples
Recurring Automatic Generation of Private PSKs
For private PSK generation, the recurring option refreshes keys every day. This option satisfies the needs of guest access for daily
visitors, but is less suitable for temporary users for longer stays, such as contractors who might need to access the wireless net-
work for several days or several weeks. For such users, it is more convenient to have one key that they can use for longer periods
of time rather than having to obtain a new key every day.
NOTE: Because the generation of private PSK users is time sensitive, make sure that the system clocks on both SmartPath EMS
VMA and the SmartPath APs are accurate and synchronized.
To configure private PSK users for longer periods, click Configuration > Advanced Configuration > Authentication > Local User
Groups > New, enter the following, leave the other settings with their default values, and then click Save:
User Group Name: Enter a name for the user group. Consider indicating how long the private PSK users are valid as part of the
name, such as "3-day-keys", "1-week-keys", "2-week-keys". Also, consider including the attribute number in the user group name.
By including this information in the user group name, you can make sure an SSID references the correct user group for a corre-
sponding user profile.
Automatically generated private PSK users:
User Profile Attribute: Type the attribute number for the user group. The SmartPath AP uses this to assign a user profile with
the same number to members of this group.
VLAN ID: Type the VLAN ID that you want SmartPath APs to assign to traffic from users in this group. If you leave this empty,
SmartPath APs assign traffic to the VLAN ID set in the user profile. If you specify a VLAN ID here, it supersedes the one defined in
the user profile.
Reauthorization Time: Use the default setting of 1800 seconds (30 minutes) or set a new one from 600 to 86400 seconds (10
minutes to 24 hours).
User Name Prefix: Type a text string to be added to the beginning of to all automatically generated private PSK users. You can
also include the private PSK user validity period here, by entering a text string such as "2-day", "1-week", "3-week", and so on. If
you include numbers and special characters, be sure to include them in the Character types used in generated PSKs and manually
created passwords option in the Private PSK Advanced Options section.
Private PSK Secret: Type a random string of up to 64 characters to be used as part of the PSK generation process.
Expand the Private PSK Advanced Generation Options section, and enter the following:
PSK Validity Period: Recurring
Enable the automatic creation and rotation of private PSK users and their keys: This enables the creation of private PSK users and
exposes the following controls to determine how many sets to generate, how many private PSK users to include in each set, and
the amount of time between the generation of each new set.
NOTE: The validity period for subsequent private PSK user sets is calculated by adding the bulk interval to the starting and ending
times. To see how the PSK validity period settings work with the bulk private PSK feature, refer to the following example.
Private PSK Start Time: Enter a start date and time for the generation of the first set of private PSK users. This is also the start-
ing point when they become valid.
Private PSK Lifetime: Enter the length of time during which private PSK users are valid. You can set their lifetime to be as short
as a few hours (set days as 0, and define the lifetime in just hours and minutes) or as long as a full year (set days as 365).
Private PSK Rotation Interval: Set the amount of time between the generation of each set of private PSK users. Enter the num-
ber of days (0-365), hours, and minutes. For example, if you want to generate a new set of private PSK users every day, set the
number of days as 1.
Private PSK Rotations: Set the number of times to generate a set of private PSK users. Enter a number from 1 to 500. The
default is 1, which means that SmartPath EMS VMA only generates one set of users.
Komentarze do niniejszej Instrukcji