
5-31
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 5 Configuring Security Solutions
Configuring Local EAP
Step 8 To configure EAP-FAST parameters if you created an EAP-FAST profile, enter this command:
config local-auth method fast ?
where ? is one of the following:
• anon-prov {enable | disable}—Configures the controller to allow anonymous provisioning, which
allows PACs to be sent automatically to clients that do not have one during PAC provisioning.
• authority-id auth_id—Specifies the authority identifier of the local EAP-FAST server.
• pac-ttl days—Specifies the number of days for the PAC to remain viable.
• server-key key—Specifies the server key used to encrypt and decrypt PACs.
Step 9 To configure certificate parameters per profile, enter these commands:
• config local-auth eap-profile method fast local-cert {enable | disable} profile_name—
Specifies whether the device certificate on the controller is required for authentication.
Note This command applies only to EAP-FAST because device certificates are not used with
LEAP and are mandatory for EAP-TLS and PEAP.
• config local-auth eap-profile method fast client-cert {enable | disable} profile_name—
Specifies whether wireless clients are required to send their device certificates to the controller in
order to authenticate.
Note This command applies only to EAP-FAST because client certificates are not used with
LEAP or PEAP and are mandatory for EAP-TLS.
• config local-auth eap-profile cert-issuer {cisco | vendor} profile_name—If you specified
EAP-FAST with certificates, EAP-TLS, or PEAP, specifies whether the certificates that will be sent
to the client are from Cisco or another vendor.
• config local-auth eap-profile cert-verify ca-issuer {enable | disable} profile_name—If you chose
EAP-FAST with certificates or EAP-TLS, specifies whether the incoming certificate from the client
is to be validated against the CA certificates on the controller.
• config local-auth eap-profile cert-verify cn-verify {enable | disable} profile_name—If you chose
EAP-FAST with certificates or EAP-TLS, specifies whether the common name (CN) in the
incoming certificate is to be validated against the CA certificates’ CN on the controller.
• config local-auth eap-profile cert-verify date-valid {enable | disable} profile_name—If you
chose EAP-FAST with certificates or EAP-TLS, specifies whether the controller is to verify that the
incoming device certificate is still valid and has not expired.
Step 10 To enable local EAP and attach an EAP profile to a WLAN, enter this command:
config wlan local-auth enable profile_name wlan_id
Note To disable local EAP for a WLAN, enter this command: config wlan local-auth disable
wlan_id.
Step 11 To save your changes, enter this command:
save config
Komentáře k této Příručce