
7-41
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 7 Controlling Lightweight Access Points
Autonomous Access Points Converted to Lightweight Mode
Note To remove an access point from the authorization list, hover your cursor over the blue drop-down
arrow for the access point and choose Remove.
Note To search for a specific access point in the authorization list, enter the MAC address of the access
point in the Search by MAC field and click Search.
Using the CLI to Authorize Access Points
Using the controller CLI, follow these steps to authorize access points.
Step 1 To configure an access point authorization policy, enter this command:
config auth-list ap-policy {authorize-ap {enable | disable} | ssc {enable | disable}}
Step 2 To add an access point to the authorization list, enter this command:
config auth-list add {mic | ssc} ap_mac [ap_key]
where ap_key is an optional key hash value equal to 20 bytes or 40 digits.
Note To delete an access point from the authorization list, enter this command:
config auth-list delete ap_mac.
Step 3 To view the access point authorization list, enter this command:
show auth-list
Information similar to the following appears:
Authorize APs against AAA ....................... enabled
Allow APs with Self-Signed Certificate (SSC) .... enabled
Mac Addr Cert Type Key Hash
----------------------- ---------- ------------------------------------------
00:0b:85:57:c9:f0 MIC
00:13:80:60:48:3e SSC ecefbb0622ef76c997ac7d73e413ee499e24769e
Using DHCP Option 43
Cisco 1000 series access points use a string format for DHCP option 43, whereas Cisco Aironet access
points use the type-length-value (TLV) format for DHCP option 43. DHCP servers must be programmed
to return the option based on the access point’s DHCP Vendor Class Identifier (VCI) string (DHCP
Option 60). Table 7-3 lists the VCI strings for Cisco access points capable of operating in lightweight
mode.
Komentáře k této Příručce