> For the complete documentation index, see [llms.txt](https://docs.lan.kokomocloud.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lan.kokomocloud.com/application-note/application-note/radius-authentication/use-kokomo-cloud-radius.md).

# KOKOMO Cloud RADIUSを使用する

KOKOMO Cloud RADIUSではKOKOMO Cloud上のRADIUSサーバーを利用できるため、ユーザー側でRADIUSサーバーを準備する必要はありません。\
また、RADIUSでの認証ではユーザーIDとパスワードを用いる「ユーザー認証」をサポートしています。そのため、KOKOMO Cloud上でKOKOMO Cloud RADIUSを有効化し、「クラウドユーザー」を作成する必要があります。

KOKOMO Cloud RADIUSは以下の２つの認証で設定できます。

* WPA2/3エンタープライズでの認証
* キャプティブポータルでの認証

それぞれの設定方法は、　以降の各項目を参照してください。

### WPA2/3エンタープライズでの認証 <a href="#enterprise" id="enterprise"></a>

#### 設定方法 <a href="#setup" id="setup"></a>

WPA2/3エンタープライズでKOKOMO Cloud RADIUSを有効にするには、SSIDのセキュリティタイプで「**WPA2エンタープライズ**」「**WPA3エンタープライズ**」のいずれかを設定してください。続いて、認証方法の設定で「**KOKOMO Cloud RADIUS**」を選択します。なお、SSIDでMLOまたは6GHzが有効になっている場合、WPAタイプはWPA3エンタープライズのみ選択可能です。

【設定場所】

「**設定**」＞「**アクセスポイント**」＞「**SSID**」＞「**SSIDの追加**」または作成済みSSIDを選択＞「**基本設定**」＞「**セキュリティタイプ**」＞「**WPA2エンタープライズ**」または「**WPA3エンタープライズ**」＞"認証方法で「**KOKOMO Cloud RADIUS**」を選択"

<figure><img src="/files/03uCDNzMxsHA94NdF3pg" alt=""><figcaption><p>セキュリティタイプから認証方法を設定</p></figcaption></figure>

<figure><img src="/files/eviD46RUCQrP8ETA6X0K" alt="" width="563"><figcaption><p>WPA2/3エンタープライズでのKOKOMO Cloud RADIUSの動作</p></figcaption></figure>

#### 証明書について <a href="#certificate" id="certificate"></a>

KOKOMO Cloud RADIUSでは、ユーザー認証情報を安全にやり取りするための認証プロトコルとしてPEAP（EAP-PEAP）を使用しています。PEAPの認証プロセスでは、ユーザー認証情報を保護するためにTLSトンネルを確立します。その際に、サーバーはクライアントに対しサーバー証明書を提示し、クライアントはそれが信頼できる認証局（CA）から発行されたものであるかを確認するためにCA証明書を使用します。

<figure><img src="/files/qIA53HfeMEfwTTuaxnzQ" alt=""><figcaption><p>証明書のダウンロード</p></figcaption></figure>

### キャプティブポータルでの認証 <a href="#captive-portal-auth" id="captive-portal-auth"></a>

#### セキュリティタイプの設定 <a href="#security-type-settings" id="security-type-settings"></a>

キャプティブポータルでKOKOMO Cloud RADIUSを有効にするには、SSIDのセキュリティタイプで「**Open**」「**Enhanced Open**」「**パスワード**」のいずれかを設定してください。なお、SSIDでMLOまたは6GHzが有効になっている場合、「**Enhanced Open**」と「**パスワード**」のWPA3パーソナルのみ選択可能です。

【設定場所】

「**設定**」＞「**アクセスポイント**」＞「**SSID**」＞「**SSIDの追加**」または作成済みSSIDを選択＞「**基本設定**」＞「**セキュリティタイプ**」

<figure><img src="/files/yB5sVe5fUtaJptonQ7Dl" alt=""><figcaption><p>セキュリティタイプの設定</p></figcaption></figure>

#### キャプティブポータルの設定 <a href="#captive-portal-settings" id="captive-portal-settings"></a>

SSIDのセキュリティタイプを設定した後は、キャプティブポータルの設定を行います。キャプティブポータルを有効化し、認証タイプを「**KOKOMO Cloud RADIUS**」に設定します。

{% hint style="warning" %}
セキュリティタイプでWPA2エンタープライズもしくはWPA3エンタープライズを設定している場合、これらは802.1X認証を使用しているため、キャプティブポータルの認証タイプでKOKOMO Cloud RADIUSを使用することはできません。
{% endhint %}

【設定場所】

「**設定**」＞「**アクセスポイント**」＞「**SSID**」＞（設定するSSIDをクリック）＞「**キャプティブポータル**」

<figure><img src="/files/EUH3ynCioRsUvvQDkS8T" alt="" width="563"><figcaption><p>キャプティブポータルの設定</p></figcaption></figure>

<figure><img src="/files/48VAC4clpvKj4GsMgYue" alt=""><figcaption><p>WPA2/3エンタープライズとキャプティブポータル認証タイプの組み合わせ</p></figcaption></figure>

<figure><img src="/files/WaWZiiygp5b8sr52cwIl" alt="" width="563"><figcaption><p>キャプティブポータルでのKOKOMO Cloud RADIUSの動作</p></figcaption></figure>

### クライアントの登録 <a href="#client-registration" id="client-registration"></a>

KOKOMO Cloud RADIUSを使用するには、KOKOMO Cloud上でクラウドユーザーの登録が必要です。

設定方法は、クラウドユーザー設定画面にて、「**ユーザーの追加**」をクリックします。表示された「**認証ユーザーを追加する**」ウィンドウにて、接続を許可するユーザーの以下の情報を入力します。ここで入力した情報は、Cloud上のRADIUSサーバーに登録されます。

* **メールアドレス** ：クライアントのメールアドレス
* **パスワード** ：任意のパスワード
* **説明文** ：クライアントに関する説明文（任意）
* **認証** ：接続を許可するSSID

【設定場所】

「**設定**」＞「**ユーザー**」＞「**クラウドユーザー**」＞「**ユーザーの追加**」

<figure><img src="/files/FbCcCZ3bObHuBaQhkty5" alt=""><figcaption><p>クラウドユーザーの追加</p></figcaption></figure>

<figure><img src="/files/L5bof8hjNA2evakiOziO" alt="" width="563"><figcaption><p>認証ユーザーを追加する</p></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lan.kokomocloud.com/application-note/application-note/radius-authentication/use-kokomo-cloud-radius.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
