Cisco Systems DL-2159-05 manual Security Setup Setting Up MAC-Based Authentication

Models: DL-2159-05

1 332
Download 332 pages 33.19 Kb
Page 185
Image 185

Chapter 8 Security Setup

Setting Up MAC-Based Authentication

You can configure up to four servers for authentication services, so you can set up backup authenticators. If you set up more than one server for the same service, the server first in the list is the primary server for that service, and the others are used in list order when the previous server times out.

Step 7 Enter the name or IP address of the authentication server in the Server Name/IP entry field.

Step 8 Enter the port number the server uses for authentication. The default setting, 1812, is the port setting for Cisco’s RADIUS server, the Cisco Secure Access Control Server (ACS), and for many other RADIUS servers. Check your server’s product documentation to find the correct port setting.

Step 9 Enter the shared secret used by the server in the Shared Secret entry field. The shared secret on the access point must match the shared secret on the server.

Step 10 Enter the number of seconds the the access point should wait before authentication fails.

Step 11 Enter the number of seconds the access point should wait before giving up contacting the server.

Step 12 Select MAC Address Authentication under the server. If you set up a backup authentication server, select MAC Address Authentication under the backup server, also.

Step 13 Click OK. You return automatically to the Setup page.

Step 14 Create a list of allowed MAC addresses for your authentication server. Enter the MAC addresses of all allowed clients as users in the server’s database. The “Enabling MAC-Based Authentication in Cisco Secure ACS” section on page 8-26describes how to create a list of MAC addresses for your RADIUS server.

Note Be sure to include your own MAC address in the authentication server’s list to avoid losing your connection to the access point.

Step 15 You can enable MAC authentication on one or both of the access point radios on the AP Radio Advanced pages. Click Advanced for the internal radio or the radio module in the AP Radio row of the Network Ports section at the bottom of the Setup page. The radio’s AP Radio Advanced page appears. Figure 8-12shows the AP Radio Advanced page for the internal radio.

Cisco Aironet 1200 Series Access Point Software Configuration Guide

 

OL-2159-05

8-23

 

 

 

Page 185
Image 185
Cisco Systems DL-2159-05 manual Security Setup Setting Up MAC-Based Authentication