Cisco Systems DL-2159-05 manual Firmware Version Draft 802.1x-2001

Models: DL-2159-05

1 332
Download 332 pages 33.19 Kb
Page 178
Image 178

Chapter 8 Security Setup

Setting Up EAP Authentication

Note You can use the same server for both EAP authentication and MAC-address authentication.

Step 2 Use the 802.1X Protocol Version (for EAP authentication) pull-down menu to select the draft of the 802.1X protocol the access point’s radio will use. EAP operates only when the radio firmware on client devices complies with the same 802.1X Protocol draft as the management firmware on the access point. If the radio firmware on the client devices that will associate with the access point is 4.16, for example, you should select Draft 8. Menu options include:

Draft 7—No radio firmware versions compliant with Draft 7 have LEAP capability, so do not select this setting.

Draft 8—Select this option if LEAP-enabled client devices that associate with this access point use radio firmware versions 4.13, 4.16, or 4.23.

802.1x-2001 (formerly Draft 10)—Select this option if client devices that associate with this access point use Microsoft Windows XP authentication or if LEAP-enabled client devices that associate with this access point use radio firmware version 4.25 or later.

Table 8-3lists radio firmware versions for Cisco Aironet products and the drafts with which they comply.

Table 8-3 802.1x Protocol Drafts and Compliant Client Firmware

Firmware Version

Draft 7

Draft 8

802.1x-2001

 

 

 

 

PC/PCI cards 4.13

x

 

 

 

 

PC/PCI cards 4.16

x

 

 

 

 

PC/PCI cards 4.23

x

 

 

 

 

PC/PCI cards 4.25 and later

x

 

 

 

 

WGB34x/352 8.58

x

 

 

 

 

WGB34x/352 8.61 or later

x

 

 

 

 

AP34x/35x 11.05 and earlier

x

 

 

 

 

AP34x/35x 11.06 and later

x

x

 

 

 

 

BR352 11.06 and later1

x

x

1. The default draft setting in access point and bridge firmware version 11.06 and later is 802.1x-2001.

Note Draft standard 8 is the default setting in firmware version 11.05 and earlier, and it might remain in effect when you upgrade the firmware to version 11.06 or later. Check the setting on the Authenticator Configuration page in the management system to make sure the best draft standard for your network is selected.

Step 3 Enter the name or IP address of the RADIUS server in the Server Name/IP entry field.

Step 4 Select the server type (RADIUS or TACAS) in the Server Type field.

Step 5 Enter the port number your RADIUS server uses for authentication. The default setting, 1812, is the port setting for Cisco’s RADIUS server, the Cisco Secure Access Control Server (ACS), and for many other RADIUS servers. Check your server’s product documentation to find the correct port setting.

Cisco Aironet 1200 Series Access Point Software Configuration Guide

8-16

OL-2159-05

 

 

Page 178
Image 178
Cisco Systems DL-2159-05 manual Firmware Version Draft 802.1x-2001