Configuring AAA for network users 481Nortel WLAN—Security Switch 2300 Series Configuration GuideWays a WSS can use EAPNetwork users with 802.1X support cannot access the network unless they are authenticated. You canconfigure a WSS to authenticate users with EAP on a group of RADIUS servers and/or in a local user databaseon the WSS, or to offload some authentication tasks from the server group. Table 2 details these three basicWSS authentication approaches.(For information about digital certificates, see “Managing keys and certificates” (page 443).)Table 2: Three basic WSS approaches to EAP authenticationApproach DescriptionPass-through An EAP session is established directly between the client and RADIUSserver, passing through the WSS. User information resides on theserver. All authentication information and certificate exchanges passthrough the switch or use client certificates issued by a certificateauthority (CA). In this case, the switch does not need a digitalcertificate, although the client might.Local The WSS performs all authentication using information in a local userdatabase configured on the switch, or using a client-suppliedcertificate. No RADIUS servers are required. In this case, the switchneeds a digital certificate. If you plan to use the EAP with TransportLayer Security (EAP-TLS) authentication protocol, the clients alsoneed certificates.Offload The WSS offloads all EAP processing from a RADIUS server byestablishing a TLS session between the switch and the client. In thiscase, the switch needs a digital certificate. When you use offload,RADIUS can still be used for non-EAP authentication andauthorization. EAP-TLS cannot be used with offload.