
7-40
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 7 Controlling Lightweight Access Points
Autonomous Access Points Converted to Lightweight Mode
Authorizing Access Points Using MICs
You can configure controllers to use RADIUS servers to authorize access points using MICs. The
controller uses an access point’s MAC address as both the username and password when sending the
information to a RADIUS server. For example, if the MAC address of the access point is 000b85229a70,
both the username and password used by the controller to authorize the access point are 000b85229a70.
Note The lack of a strong password by the use of the access point’s MAC address should not be an issue
because the controller uses MIC to authenticate the access point prior to authorizing the access point
through the RADIUS server. Using MIC provides strong authentication.
Note If you use the MAC address as the username and password for access point authentication on a RADIUS
AAA server, do not use the same AAA server for client authentication.
Using the GUI to Authorize Access Points
Using the controller GUI, follow these steps to authorize access points.
Step 1 Click Security > AAA > AP Policies to open the AP Policies page (see Figure 7-21).
Figure 7-21 AP Policies Page
Step 2
If you want the access points to be authorized using a AAA RADIUS server, check the Authorize APs
Against AAA check box.
Step 3 If you want the access points to be authorized using an SSC, check the Authorize Self Signed
Certificate (SSC) check box.
Step 4 Click Apply to commit your changes.
Step 5 Follow these steps to add an access point to the controller’s authorization list:
a. Click Add to access the Add AP to Authorization List area.
b. In the MAC Address field, enter the MAC address of the access point.
c. From the Certificate Type drop-down box, choose MIC or SSC.
d. Click Add. The access point appears in the access point authorization list.
Komentáře k této Příručce