Cisco AIR-LAP1252AG-A-K9 Software Configuration Guide - Page 141

EAP Authentication, Radio Data Encryption WEP, Network-EAP, Require EAP

Page 141 highlights

Chapter 4 Security Setup Setting Up EAP Authentication 1. Functionality in Draft 10 is equivalent to the functionality in Draft 11, the ratified draft of the 802.1X standard. 2. The default draft setting in access point and bridge firmware version 11.06 and later is Draft 10. Note Draft standard 8 is the default setting in firmware version 11.05 and earlier, and it might remain in effect when you upgrade the firmware to version 11.06 or later. Check the setting on the Authenticator Configuration page in the management system to make sure the best draft standard for your network is selected. Step 3 Step 4 Step 5 Step 6 Step 7 Step 8 Step 9 Step 10 Enter the name or IP address of the RADIUS server in the Server Name/IP entry field. Enter the port number your RADIUS server uses for authentication. The default setting, 1812, is the port setting for Cisco's RADIUS server, the Cisco Secure Access Control Server (ACS), and for many other RADIUS servers. Check your server's product documentation to find the correct port setting. Enter the shared secret used by your RADIUS server in the Shared Secret entry field. The shared secret on the access point must match the shared secret on the RADIUS server. The shared secret can contain up to 64 alphanumeric characters. Enter the number of seconds the access point should wait before authentication fails. If the server does not respond within this time, the access point tries to contact the next authentication server in the list if one is specified. Other backup servers are used in list order when the previous server times out. Select EAP Authentication under the server. The EAP Authentication checkbox designates the server as an authenticator for any EAP type, including LEAP, EAP-TLS, and EAP-MD5. Click OK. You return automatically to the Security Setup page. On the Security Setup page, click Radio Data Encryption (WEP) for the internal radio or the radio module to browse to the radio's AP Radio Data Encryption page. Select Network-EAP for the Authentication Type setting to allow EAP-enabled client devices to authenticate through the access point. Select Require EAP under Open or Shared Key to allow client devices with EAP-TLS or EAP-MD5 enabled through Windows XP to authenticate through the access point. If you do not select Require EAP, client devices with EAP enabled through Windows XP authenticate to the access point but might not perform OL-2159-03 Cisco Aironet 1200 Series Access Point Software Configuration Guide 4-23

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284

4-23
Cisco Aironet 1200 Series Access Point Software Configuration Guide
OL-2159-03
Chapter 4
Security Setup
Setting Up EAP Authentication
Note
Draft standard 8 is the default setting in firmware version 11.05 and
earlier, and it might remain in effect when you upgrade the firmware to
version 11.06 or later. Check the setting on the Authenticator
Configuration page in the management system to make sure the best draft
standard for your network is selected.
Step 3
Enter the name or IP address of the RADIUS server in the Server Name/IP entry
field.
Step 4
Enter the port number your RADIUS server uses for authentication. The default
setting,
1812
, is the port setting for Cisco
s RADIUS server, the Cisco Secure
Access Control Server (ACS), and for many other RADIUS servers. Check your
server
s product documentation to find the correct port setting.
Step 5
Enter the shared secret used by your RADIUS server in the Shared Secret entry
field. The shared secret on the access point must match the shared secret on the
RADIUS server. The shared secret can contain up to 64 alphanumeric characters.
Step 6
Enter the number of seconds the access point should wait before authentication
fails. If the server does not respond within this time, the access point tries to
contact the next authentication server in the list if one is specified. Other backup
servers are used in list order when the previous server times out.
Step 7
Select
EAP Authentication
under the server. The EAP Authentication checkbox
designates the server as an authenticator for any EAP type, including LEAP,
EAP-TLS, and EAP-MD5.
Step 8
Click
OK
. You return automatically to the Security Setup page.
Step 9
On the Security Setup page, click
Radio Data Encryption (WEP)
for the internal
radio or the radio module to browse to the radio
s AP Radio Data Encryption page.
Step 10
Select
Network-EAP
for the Authentication Type setting to allow EAP-enabled
client devices to authenticate through the access point.
Select
Require EAP
under Open or Shared Key to allow client devices with
EAP-TLS or EAP-MD5 enabled through Windows XP to authenticate through the
access point. If you do not select Require EAP, client devices with EAP enabled
through Windows XP authenticate to the access point but might not perform
1.
Functionality in Draft 10 is equivalent to the functionality in Draft 11, the ratified draft of the
802.1X standard.
2.
The default draft setting in access point and bridge firmware version 11.06 and later is Draft 10.