Cisco CISCO1401 Software Guide - Page 127

Configuring Authentication Holdoffs, Timeouts, and Intervals, con terminal, dot11 holdoff-time

Page 127 highlights

Chapter 10 Configuring Authentication Types Configuring Authentication Types This example sets the authentication type for the SSID bridget to network-EAP with a static WEP key. EAP-enabled bridges using the bridget SSID attempt EAP authentication using a server named eve, and bridges using static WEP rely on the static WEP key. bridge# configure terminal bridge(config)# configure interface dot11radio 0 bridge(config-if)# encryption key 2 size 128 12345678901234567890123456 bridge(config-if)# ssid bridget bridge(config-ssid)# authentication network-eap eve bridge(config-ssid)# end The configuration on non-root bridges associated to this bridge would also contain these commands: bridge(config)# configure interface dot11radio 0 bridge(config-if)# ssid bridget bridge(config-ssid)# authentication client username bridge11 password 99bottles Configuring Authentication Holdoffs, Timeouts, and Intervals Beginning in privileged EXEC mode, follow these steps to configure holdoff times, reauthentication periods, and authentication timeouts for non-root bridges authenticating through your root bridge: Step 1 Step 2 Step 3 Step 4 Step 5 Step 6 Step 7 Command Purpose configure terminal Enter global configuration mode. dot11 holdoff-time seconds Enter the number of seconds a non-root bridge must wait before it can reattempt to authenticate following a failed authentication. Enter a value from 1 to 65555 seconds. interface dot11radio 0 Enter interface configuration mode for the radio interface. dot1x client-timeout seconds Enter the number of seconds the bridge should wait for a reply from a non-root bridge attempting to authenticate before the authentication fails. Enter a value from 1 to 65555 seconds. dot1x reauth-period seconds [server] Enter the interval in seconds that the bridge waits before forcing an authenticated non-root bridge to reauthenticate. • (Optional) Enter the server keyword to configure the bridge to use the rauthentication period specified by the authentication server. If you use this option, configure your authentication server with RADIUS attribute 27, Session-Timeout. This attribute sets the maximum number of seconds of service to be provided to the non-root bridge before termination of the session or prompt. The server sends this attribute to the root bridge when a non-root bridge performs EAP authentication. end Return to privileged EXEC mode. copy running-config startup-config (Optional) Save your entries in the configuration file. Use the no form of these commands to reset the values to default settings. OL-4059-01 Cisco Aironet 1400 Series Wireless Bridges Software Configuration Guide 10-7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286

10-7
Cisco Aironet 1400 Series Wireless Bridges Software Configuration Guide
OL-4059-01
Chapter 10
Configuring Authentication Types
Configuring Authentication Types
This example sets the authentication type for the SSID bridget to network-EAP with a static WEP key.
EAP-enabled bridges using the bridget SSID attempt EAP authentication using a server named
eve
,
and bridges using static WEP rely on the static WEP key
.
bridge#
configure terminal
bridge(config)#
configure interface dot11radio 0
bridge(config-if)#
encryption key 2 size 128 12345678901234567890123456
bridge(config-if)#
ssid bridget
bridge(config-ssid)#
authentication network-eap eve
bridge(config-ssid)#
end
The configuration on non-root bridges associated to this bridge would also contain these commands:
bridge(config)#
configure interface dot11radio 0
bridge(config-if)#
ssid bridget
bridge(config-ssid)#
authentication client username bridge11 password 99bottles
Configuring Authentication Holdoffs, Timeouts, and Intervals
Beginning in privileged EXEC mode, follow these steps to configure holdoff times, reauthentication
periods, and authentication timeouts for non-root bridges authenticating through your root bridge:
Use the no form of these commands to reset the values to default settings.
Command
Purpose
Step 1
configure terminal
Enter global configuration mode.
Step 2
dot11 holdoff-time
seconds
Enter the number of seconds a non-root bridge must wait before
it can reattempt to authenticate following a failed
authentication. Enter a value from 1 to 65555 seconds.
Step 3
interface dot11radio 0
Enter interface configuration mode for the radio interface.
Step 4
dot1x client-timeout
seconds
Enter the number of seconds the bridge should wait for a reply
from a non-root bridge attempting to authenticate before the
authentication fails. Enter a value from 1 to 65555 seconds.
Step 5
dot1x reauth-period
seconds
[
server
]
Enter the interval in seconds that the bridge waits before
forcing an authenticated non-root bridge to reauthenticate.
(Optional) Enter the
server
keyword to configure the
bridge to use the rauthentication period specified by the
authentication server. If you use this option, configure your
authentication server with RADIUS attribute 27,
Session-Timeout. This attribute sets the maximum number
of seconds of service to be provided to the non-root bridge
before termination of the session or prompt. The server
sends this attribute to the root bridge when a non-root
bridge performs EAP authentication.
Step 6
end
Return to privileged EXEC mode.
Step 7
copy running-config startup-config
(Optional) Save your entries in the configuration file.