01-19-2005 08:03 PM - edited 07-04-2021 10:22 AM
We just purchased several 1310's to connect buildings together. The users will connect thru lan interface on each AP. There will not be any wireless users. The only wireless access should be the AP's. Our question is what is the best way to configue security and authentication? We want to authenticate each AP against Windows IAS server, using EAP if this is this possible. We are setting each end point with a 1721 router to do GRE tunneling to protect user traffic, so I don't know if this is overkill in wanting to implement authentication. We will still use radius authentication for ssh connection to AP's and routers. Any help would be greatly appreciated in pointing us in the right direction.
01-26-2005 07:20 AM
Before a wireless client device can communicate on your network through the access point, it must authenticate to the access point using open or shared-key authentication. For maximum security, client devices should also authenticate to your network using MAC-address or EAP authentication, authentication types that rely on an authentication server on your network.For more information please refer ther folllowing link :
02-01-2005 03:51 PM
I assume that you use the 1310s as either point to point bridges or point to multipoint bridges. If this is the case, the best you can do is AES+WPA+LEAP. There is a radius server coming with 12.3(2)JA software. You can use that for authentication. Microsoft IAS does not support LEAP.
The next best solution is to use AES+WPA-PSK. Please remember to disable concentenation when enable AES.
02-01-2005 05:47 PM
Thanks for replying. Do you know links to set your recomendations up?
02-07-2005 04:21 PM
As we recently add AES support, we do not have any link yet. It is very similar to setting up TKIP:
Select AES+CCMP instead of TKIP in Encryption Manager.
You also need to configure EAP user name in the non-root bridge (i.e. SSID Manager).
Finally, you need to set up local radius server:
02-08-2005 11:12 AM
Thank you for the information; however I'm unable to view the webpages. It promts for my CCO username and password and when I enter my information, it goes to the Message #401: Authorization Required/Forgotten Password page. Can you send me the info via email? My email is jfoote@vctx.org. Thank you very much.
02-08-2005 12:37 PM
Just change the word "partner" in the link to "customer" and you should be good.
02-08-2005 02:58 PM
Could you please clarify the EAP username. I'm assuming it will also need to be set up in the local radius server on the root bridge. Looking at the show run on the root bridge, I see it created several usernames with the mac address of the non-root bridges as the name. Can I use the same scheme and just create new users with mac address as name and new password?
02-11-2005 05:47 PM
You do not configure EAP username on SSID Manager. You create the same username on the root under "radius-server local". If you access the link "LEAP Authentication with Local RADIUS Server", it is step # 5.
02-14-2005 08:46 AM
I'm sorry, but it's not working when I follow the steps. When I get to LEAP authentication and select WEP encryption, a message appears telling me to set the 'Authenticated Key Management' to 'None' before changing Ciper. It seems that if you configure WPA on the radios, you cannot configure LEAP authentication as outlined on the web site.
Still scatching my head
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide