Cisco Systems OL-6217-01 manual AAA-apconfig#radius-server local

Page 18

Cisco Structured Wireless-Aware Network (SWAN) Implementation Guide

Implementing the Cisco SWAN Framework

To configure the local RADIUS server on an access point, follow these steps:

Step 1 Access the access point command-line interface and go into configuration mode.

Step 2 Enter the following IOS command:

AAA-ap(config)# aaa new-model

Step 3 Enter the following IOS command:

AAA-ap(config)#radius-server local

You are now in the local RADIUS server configuration mode.

Step 4 Enter the following command for each WDS-host device while in the local RADIUS server configuration mode:

AAA-ap(config-radsrv)nas <wds-host ip address> key <shared secret>

Step 5 Each infrastructure access point presents a username and password to the WDS when it authenticates. These credentials must be defined on the local RADIUS server and do not have to be unique per infrastructure access point. Most implementations use a single username and password credential pair for all of the infrastructure access points. To add the username and password credentials into the local RADIUS server, enter the following command while in local RADIUS configuration mode for each username and password credential pair:

AAA-ap(config-radsrv)user <username> password <password>

Step 6 Exit configuration mode and save the configuration to NVRAM.

Configuring the AAA Server to Support WLAN Client Authentication

The configuration steps required to configure client authentication depending on authentication requirements for the WLAN client. A discussion of WLAN client authentication and configuration is beyond the scope of this document. Consult product documentation and other resources available from http://www.cisco.com for the details of WLAN client authentication configuration.

Preparing the CiscoWorks WLSE for Managing WLAN Devices

The CiscoWorks WLSE uses three methods to communicate with WLAN devices in the network:

WLCCP-Control transactions with the WDS-hosts

SNMP-Interrogation of all WLAN devices and some configuration tasks

Telnet or SSH-Configuration of access points via remote command-line interface

The CiscoWorks WLSE requires the following credentials to successfully communicate with WLAN devices in the network:

WLCCP credentials for initial authentication of the WLSE by the WDS-hosts

SNMP read-only and read-write communities

Telnet or SSH credentials

Cisco Structured Wireless-Aware Network (SWAN) Implementation Guide

18

OL-6217-01

 

 

Image 18
Contents Corporate Headquarters Cisco Aironet 1400 Series Wireless Bridge Deployment Guide N T E N T S Contents Book Title Xxxxx-xx Audience Acroymns and Terms Cisco Swan Framework Overview Cisco Swan Layers Cisco Swan Logical View Shows the access point-based WDS solution Cisco Swan Framework Components WDS WlccpSoftware Components Hardware ComponentsImplementing the Cisco Swan Framework Common Tasks CiscoSecure ACS NAS Setup Adding Username and Password Credentials CiscoSecure ACS User Setup AAA-apconfig#radius-server local AAA-apconfig-radsrvuser username password passwordCiscoWorks Wlse Snmp Community Entry Screen CiscoWorks Wlse Telnet/SSH Credentials Entry Access Point-Based WDS Solution Configuration Configuring the WDS Access PointWds-apconfig#hostname hostname Wds-apconfig#username username password passwordConfiguring the Infrastructure Access Point Wds-apconfig#wlccp wds priority priority numberWds-apconfig#wlccp wnm ip address wlse ip address Infra-apconfig#username username password password Managing the Access Points with the CiscoWorks WlseInfra-apconfig#hostname hostname Infra-apconfig-line#access-class access-list numberConfiguring the Catalyst 6500 Supervisor Switch-Based WDS Solution ConfigurationValidating the Configuration Wds-ap#show wlccp wds apConfiguring the WDS on the Wlsm Create the Vlan between the supervisor and WlsmWlsmconfig#snmp-server view iso iso included Wlsmconfig#hostname hostnameConfiguring the Infrastructure Access Points Wlsmconfig# wlccp wnm ip address wlse ip addressInfra-apconfig#wlccp ap wds ip address wlsm ip address Validating the Setup Wlsm# show wlccp wds apWlsm# show wlccp wnm status Sup720# show mobility status Mobility apFast Secure Roaming with Cckm Infra-apconfig-if#encryption mode ciphers cipher-type When Using Multiple Encryption Types or VLANsInfra-apconfig#interface dot11Radio Infra-apconfig-if-ssid#authentication network-eap eap-groupConfiguring ACU to use Cckm Click Profile ManagementCisco Swan Radio Management Features Cisco Swan Framework Radio ManagementPreparing to Use Cisco Swan Radio Management Building Tool Pop-Up WindowCisco Swan Radio Management Features Page OL-6217-01