Configuring Radius Servers - Cisco Mesh Access Points Deployment Manual

Cisco mesh access points, design and deployment guide, release 7.3
Table of Contents

Advertisement

Configuring External Authentication and Authorization Using a RADIUS Server
• Add the mesh access point configured for external authorization and authentication to the user list of
• Configure EAP-FAST on the RADIUS server and install the certificates. EAP-FAST authentication is

Configuring RADIUS Servers

To install and trust the CA certificates on the RADIUS server, follow these steps:
Step 1
Download the CA certificates for Cisco Root CA 2048 from the following locations:
http://www.cisco.com/security/pki/certs/crca2048.cer
http://www.cisco.com/security/pki/certs/cmca.cer
Step 2
Install the certificates as follows:
a) From the CiscoSecure ACS main menu, click System Configuration > ACS Certificate Setup > ACS Certification
Authority Setup.
b) In the CA certificate file box, type the CA certificate location (path and name). For example: C:\Certs\crca2048.cer.
c) Click Submit.
Step 3
Configure the external RADIUS servers to trust the CA certificate as follows:
a) From the CiscoSecure ACS main menu, choose System Configuration > ACS Certificate Setup > Edit Certificate
Trust List. The Edit Certificate Trust List appears.
b) Select the check box next to the Cisco Root CA 2048 (Cisco Systems) certificate name.
c) Click Submit.
d) To restart ACS, choose System Configuration > Service Control, and then click Restart.
For additional configuration details on Cisco ACS servers, see the following:
• http://www.cisco.com/en/US/products/sw/secursw/ps4911/(UNIX)
Cisco Mesh Access Points, Design and Deployment Guide, Release 7.3
110
the RADIUS server.
◦ For additional details, see the Adding a Username to a RADIUS Server section.
required if mesh access points are connected to the controller using an 802.11a interface; the external
RADIUS servers need to trust Cisco Root CA 2048. For information about installing and trusting the
CA certificates, see the Configuring RADIUS Servers section.
If mesh access points connect to a controller using a Fast Ethernet or Gigabit Ethernet
Note
interface, only MAC authorization is required.
This feature also supports local EAP and PSK authentication on the controller.
Note
http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_installation_and_configuration_
guides_list.html(Windows)
Connecting the Cisco 1500 Series Mesh Access Points to the Network
OL-27593-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents