
5-78
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 5 Configuring Security Solutions
Configuring Maximum Local Database Entries
c. Choose ASCII or Hex from the Key Wrap Format drop-down box to specify the format of the AES
key wrap keys: Key Encryption Key (KEK) and Message Authentication Code Key (MACK).
d. Enter the 16-byte KEK in the Key Encryption Key (KEK) field.
e. Enter the 20-byte KEK in the Message Authentication Code Key (MACK) field.
f. Click Apply to commit your changes.
Step 5 Click Save Configuration to save your changes.
Using the CLI to Configure AES Key Wrap
Follow these steps to configure a controller to use AES key wrap using the CLI.
Step 1 To enable or disable the use of AES key wrap attributes, enter this command:
config radius auth keywrap {enable | disable}
Step 2 To configure AES key wrap attributes, enter this command:
config radius auth keywrap add {ascii | hex} index
The index attribute specifies the index of the RADIUS authentication server on which to configure the
AES key wrap.
Configuring Maximum Local Database Entries
You can use the controller GUI or CLI to specify the maximum local database entries used for storing
user authentication information. The information in the database is used in conjunction with the
controller’s web authentication feature.
Using the GUI to Configure Maximum Local Database Entries
Follow these steps to configure a controller to use the maximum local database entries using the GUI.
Step 1 Click Security > AAA > General to open the General page (see Figure 5-46).
Figure 5-46 General Page
Komentáře k této Příručce