Cisco Cisco Access Registrar 4.2 Especificaciones Pagina 281

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 636
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 280
6-17
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 6 Configuring WLANsWireless Device Access
Configuring WLANs
Dynamic 802.1X Keys and Authorization
Controllers can control 802.1X dynamic WEP keys using Extensible Authentication Protocol (EAP)
across access points and support 802.1X dynamic key settings for WLANs.
Note To use LEAP with lightweight access points and wireless clients, make sure to choose Cisco-Airespace
or Cisco-Aironet as the RADIUS server type when configuring the CiscoSecure Access Control Server
(ACS).
Enter show wlan wlan-id to check the security settings of each WLAN. The default security setting
for new WLANs is 802.1X with dynamic keys enabled. To maintain robust Layer 2 security, leave
802.1X configured on your WLANs.
To disable or enable the 802.1X authentication, use this command:
config wlan security 802.1X {enable | disable} wlan-id
After you enable 802.1X authentication, the controller sends EAP authentication packets between
the wireless client and the authentication server. This command allows all EAP-type packets to be
sent to and from the controller.
If you want to change the 802.1X encryption level for a WLAN, use this command:
config wlan security 802.1X encryption wlan-id [40 | 104 | 128]
Use the 40 option to specify 40/64-bit encryption.
Use the 104 option to specify 104/128-bit encryption. (This is the default encryption setting.)
Use the 128 option to specify 128/152-bit encryption.
If you want to configure Cisco Aironet 802.11a/b/g Wireless LAN Client Adapters (CB21AG and
PI21AG) running PEAP-GTC to authenticate to a controller through a one-time password to a token
server, use these commands:
config advanced eap identity-request-timeout—Configures the EAP identity request timeout
value in seconds. The default setting is 1 second.
config advanced eap identity-request-retries—Configures the EAP identity request
maximum retries value. The default setting is 20.
config advanced eap request-timeout—Configures the EAP request timeout value in seconds.
The default setting is 1 second.
config advanced eap request-retries—Configures the EAP request maximum retries value.
The default setting is 2.
show advanced eap—Shows the values that are currently configured for the config advanced
eap commands. Information similar to the following appears:
EAP-Identity-Request Timeout (seconds)........... 1
EAP-Identity-Request Max Retries................. 20
EAP-Request Timeout (seconds).................... 1
EAP-Request Max Retries.......................... 2
Vista de pagina 280
1 2 ... 276 277 278 279 280 281 282 283 284 285 286 ... 635 636

Comentarios a estos manuales

Sin comentarios