Using External DPSK with RADIUS Authentication

Using an external AAA server for managing Dynamic Pre-Shared Keys provides several advantages to internal DPSKs stored on the AP or controller.

The external DPSK feature allows customers to exceed the maximum number of DPSKs that can be stored on the controller, and provides the option to store and manage DPSKs on the AAA server for distribution to multiple controllers.

To enable external DPSK using an external authentication server:

  1. Select Wi-Fi > Wi-Fi Networks > Wi-Fi Network List > Create/Edit WLAN > Advanced Options > Zero-IT & DPSK.
  2. For Dynamic PSK, select External.
  3. For Authentication Server, select an AAA server entry from the drop-down list or click to create a new AAA server entry (refer to Adding and Managing AAA Servers).
  4. Click Apply to save the changes.

    External DPSK

    The controller will send Access-Request messages to the RADIUS server with following attributes: Ruckus-SSID, Ruckus-BSSID, User-Name, Ruckus-Dpsk-Params.

    The AAA server sends back a RADIUS Access-Accept or Access-Reject message with the following attributes: Access-Accept: Calling-station-id, Tunnel-Type, Tunnel-Medium-Type, Tunnel-Private-Group-Id, MS-MPPE-Recv-Key,Session-Timeout, Ruckus-User-Groups, User-Name. The MS-MPPE-Recv-Key is mandatory.

    Note: If the User-Name attribute is empty in the Access-Accept packet of external Radius server, the column User in the web UI uses the User-name attribute from the Access-Request packet of Unleashed.

    The AAA server generates a DPSK key (PMK) for each wireless station. This key is encrypted and entered in the attribute MS-MPPE-Recv-Key: PMK = PBKDF2_SHA1(PassPhrase, Wlan-SSID, Wlan-SSID-Len, 4096, 32). Refer to RFC2548 Chapter 2.4.3.

    Note: The WLAN-SSID attribute will exist in the authentication request. The AAA server can use this value to generate the PSK or the AAA server can be pre-configured with WLAN-SSID value.

    The AAA server calculates the wireless station’s Pairwise Transient Key (PTK) from the Ruckus-Dpsk-Params attribute (AKM Suite, Cipher, Anonce, EAPOL-Key-Frame) in the Access-Request message and generates the PMK key, and finally verifies the Key MIC of the station. If it matches, the RADIUS server will send back an Access-Accept message with the MS-MPPE-Recv-Key attribute.

    With the DPSK keys generated managed by the AAA server, the controller's internal max DPSK limits are avoided and an unlimited number of DPSKs can be generated.