5-70
Cisco Wireless LAN Controller Configuration Guide
OL-17037-01
Chapter 5 Configuring Security Solutions
Configuring Management Frame Protection
Figure 5-39
Management Frame Protection Settings Page
On this page, you can see the following MFP settings:
•
The Management Frame Protection field shows if infrastructure MFP is enabled globally for the
controller.
•
The Controller Time Source Valid field indicates whether the controller time is set locally (by
manually entering the time) or through an external source (such as NTP server). If the time is set by
an external source, the value of this field is “True.” If the time is set locally, the value is “False.” The
time source is used for validating the timestamp on management frames between access points of
different controllers within a mobility group.
•
The Infrastructure Protection field shows if infrastructure MFP is enabled for individual WLANs.
•
The Client Protection field shows if client MFP is enabled for individual WLANs and whether it is
optional or required.
•
The Infrastructure Validation field shows if infrastructure MFP is enabled for individual access
points.
Using the CLI to Configure MFP
Use these commands to configure MFP using the controller CLI.
1.
To enable or disable infrastructure MFP globally for the controller, enter this command:
config wps mfp infrastructure
{
enable
|
disable
}
2.
To enable or disable infrastructure MFP signature generation on a WLAN, enter this command:
config wlan mfp infrastructure protection
{
enable
|
disable}
wlan_id
Note
Signature generation is activated only if infrastructure MFP is globally enabled.
3.
To enable or disable infrastructure MFP validation on an access point, enter this command:
config ap mfp infrastructure validation
{
enable
|
disable
}
Cisco_AP
Note
MFP validation is activated only if infrastructure MFP is globally enabled.