11-06-2008 06:06 AM - edited 07-03-2021 04:44 PM
I have 1250 LAP and I want to install my own Sertificate on LAP because I want to have secure LWAPP communication between LAP 1252 and WLC 4400. How to install may own certificate from MS CA to LAP?
I have already installed certificate from my MS CA to WLC in .pem format without any problem
Please help,
Nenad
Solved! Go to Solution.
11-07-2008 05:27 AM
Once you LAP has registered with a wlc. That LAP will have the information it need to find the primary, secondary and or tertiary wlc. This info is from the mobility group configuration and ap configuration. This will not prevent any fat ap's from connecting to your network. Wired security is what you need for that. IDS, port security, shut down of ports, etc.
11-06-2008 07:34 AM
Don't think that is possible since the ap has a manufacturer installed certificate and uses that to join with the wlc.
11-07-2008 12:49 AM
Then what is the most secure solution for LAP authorization, with minimum risk for my wireless network? I dont have problem with registering LAP to WLC (Authorize AP against AAA or MIC certificate), but I dont understand how to achieve full mutual authorization?What is the most recommended solution?
11-07-2008 04:55 AM
Not too many organizations will authorize ap against a AAA since it becomes another device they have to manage. Both the ap and wlc has a manufacture installed certificate which is an x509 certificate. This is the mutual authentication method used by the LAP and WLC. You can't change this. The only way you can prevent an LAP to not join a WLC is to use the following methods posted earlier. If someone connects a LAP to your network, but the LAP has no way of joining because you removed dhcp, dhcp option 43, dns, etc, the LAP will not be an issue. Even if the LAP joins your network, you then have full control of that LAP. What you worry about more is when someone connects a fat ap to you network... now this becomes a rouge and you have to find it.
11-07-2008 05:20 AM
1. Ok, you recommended to me to register all my LAP through LWAPP (dhcp, dhcp option 43, dns), and then after I have registered all my LAP to WLC, to remove dhcp option 43, dns, dhcp, etc.
2. If for some reason my LAP lose network connection I must add all parametars (dhcp option 43, dns, dhcp, etc..) again? Yes?
3. If I remove dhcp option 43, dns, dhcp, etc.., does that mean that even the fat ap would not be able to register to my network?
11-07-2008 05:27 AM
Once you LAP has registered with a wlc. That LAP will have the information it need to find the primary, secondary and or tertiary wlc. This info is from the mobility group configuration and ap configuration. This will not prevent any fat ap's from connecting to your network. Wired security is what you need for that. IDS, port security, shut down of ports, etc.
11-07-2008 05:32 AM
Thank you very much for your answers
Regards, Nenad
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide