Cisco AIR-LAP1252AG-A-K9 Software Configuration Guide - Page 158

Setting Up Backup Authentication Servers

Page 158 highlights

Setting Up Backup Authentication Servers Chapter 4 Security Setup Setting Up Backup Authentication Servers You can configure up to four servers for authentication services on the Authenticator Configuration page, so you can set up backup authenticators. If you set up more than one server for the same service, the server first in the list is the primary server for that service, and the other servers are used in list order when the previous server times out. If a backup server responds after the primary server fails, the access point continues to use the backup server for new transactions. Follow these steps to set up a backup authentication server: Step 1 Step 2 Step 3 Complete the steps in the "Setting Up EAP Authentication" section on page 4-20 or the "Setting Up MAC-Based Authentication" section on page 4-29 to set up your primary authentication server. On the Authenticator Configuration page, enter information about your backup server in one of the entry field groups under the completed entry fields for your primary server: a. Enter the name or IP address of the backup server in the Server Name/IP entry field. b. Enter the port number the server uses for authentication. The default setting, 1812, is the port setting for Cisco's RADIUS server, the Cisco Secure Access Control Server (ACS), and for many other RADIUS servers. Check your server's product documentation to find the correct port setting. c. Enter the shared secret used by the server in the Shared Secret entry field. The shared secret on the bridge must match the shared secret on the server. d. Enter the number of seconds the access point should try contacting the backup server in the Timeout entry field. If this backup server does not respond within this time, the access point tries to contact the next backup server on the list. If you don't have another backup server configured, the access point tries to contact the original primary authentication server. e. Select the same authentication methods as those selected on the primary server. Click OK. You return automatically to the Setup page. Figure 4-13 shows a primary authentication server and a backup server configured on the Authenticator Configuration page. 4-40 Cisco Aironet 1200 Series Access Point Software Configuration Guide OL-2159-03

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284

Chapter 4
Security Setup
Setting Up Backup Authentication Servers
4-40
Cisco Aironet 1200 Series Access Point Software Configuration Guide
OL-2159-03
Setting Up Backup Authentication Servers
You can configure up to four servers for authentication services on the
Authenticator Configuration page, so you can set up backup authenticators. If you
set up more than one server for the same service, the server first in the list is the
primary server for that service, and the other servers are used in list order when
the previous server times out. If a backup server responds after the primary server
fails, the access point continues to use the backup server for new transactions.
Follow these steps to set up a backup authentication server:
Step 1
Complete the steps in the
Setting Up EAP Authentication
section on page 4-20
or the
Setting Up MAC-Based Authentication
section on page 4-29
to set up
your primary authentication server.
Step 2
On the Authenticator Configuration page, enter information about your backup
server in one of the entry field groups under the completed entry fields for your
primary server:
a.
Enter the name or IP address of the backup server in the Server Name/IP entry
field.
b.
Enter the port number the server uses for authentication. The default setting,
1812
, is the port setting for Cisco
s RADIUS server, the Cisco Secure Access
Control Server (ACS), and for many other RADIUS servers. Check your
server
s product documentation to find the correct port setting.
c.
Enter the shared secret used by the server in the Shared Secret entry field. The
shared secret on the bridge must match the shared secret on the server.
d.
Enter the number of seconds the access point should try contacting the
backup server in the Timeout entry field. If this backup server does not
respond within this time, the access point tries to contact the next backup
server on the list. If you don
t have another backup server configured, the
access point tries to contact the original primary authentication server.
e.
Select the same authentication methods as those selected on the primary
server.
Step 3
Click
OK
. You return automatically to the Setup page.
Figure 4-13
shows a
primary authentication server and a backup server configured on the
Authenticator Configuration page.