Restrictions For Configuring Authentication For Access Points; Information About Configuring Authentication For Access Points; How To Configure Authentication For Access Points; Configuring Global Credentials For Access Points (Cli) - Cisco IOS XE Release 3SE Configuration Manual

Lightweight access point configuration guide, cisco ios xe release 3se (catalyst 3650 switches)
Table of Contents

Advertisement

Restrictions for Configuring Authentication for Access Points

• You can configure global authentication settings for all access points that are currently joined to the
• This feature is supported on the following hardware:
Restrictions for Configuring Authentication for Access Points
• The switch name in the AP configuration is case sensitive. Therefore, make sure to configure the exact

Information about Configuring Authentication for Access Points

Cisco IOS access points are shipped from the factory with Cisco as the default enable password. This password
allows users to log into the nonprivileged mode and enter the show and debug commands that pose a security
threat to your network. You must change the default enable password to prevent unauthorized access and to
enable users to enter configuration commands from the access point's console port.
You can configure 802.1X authentication between a lightweight access point and a Cisco switch. The access
point acts as an 802.1X supplicant and is authenticated by the switch where it uses EAP-FAST with anonymous
PAC provisioning.

How to Configure Authentication for Access Points

Configuring Global Credentials for Access Points (CLI)

SUMMARY STEPS
1. enable
2. configure terminal
3. ap mgmtuser username user_name password 0 passsword secret 0 secret_value
4. end
5. ap name Cisco_AP mgmtuser username user_name password password secret secret
6. show ap summary
7. show ap name Cisco_AP config general
Lightweight Access Point Configuration Guide, Cisco IOS XE Release 3SE (Catalyst 3650 Switches)
44
Cisco_AP mgmtuser username Cisco password Cisco command. Entering the command does not clear
the static IP address of the access point. Once the access point rejoins a switch, it adopts the default
Cisco/Cisco username and password.
switch and any that join in the future. If desired, you can override the global authentication settings and
assign unique authentication settings for a specific access point.
◦ All Cisco switches that support authentication.
◦ Cisco Aironet 1140, 1260, 1310, 1520, 1600, 2600, 3500, and 3600 access points
system name on the AP configuration. Failure to do this results in the AP fallback not working.
Configuring Authentication for Access Points
OL-28697-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 3650 series

Table of Contents