13-16
Cisco Wireless LAN Controller Configuration Guide
OL-17037-01
Chapter 13 Configuring Hybrid REAPWireless Device Access
Configuring Hybrid-REAP Groups
Figure 13-9
Hybrid-REAP Group Deployment
Hybrid-REAP Groups and Backup RADIUS Servers
You can configure the controller to allow a hybrid-REAP access point in standalone mode to perform
full 802.1X authentication to a backup RADIUS server. You can configure a primary backup RADIUS
server or both a primary and secondary backup RADIUS server. These servers are used only when the
hybrid-REAP access point is not connected to the controller.
Hybrid-REAP Groups and CCKM
Hybrid-REAP groups are required for CCKM fast roaming to work with hybrid-REAP access points.
CCKM fast roaming is achieved by caching a derivative of the master key from a full EAP authentication
so that a simple and secure key exchange can occur when a wireless client roams to a different access
point. This feature prevents the need to perform a full RADIUS EAP authentication as the client roams
from one access point to another. The hybrid-REAP access points need to obtain the CCKM cache
information for all the clients that might associate so they can process it quickly instead of sending it
back to the controller. If, for example, you have a controller with 300 access points and 100 clients that
might associate, sending the CCKM cache for all 100 clients is not practical. If you create a
hybrid-REAP group comprising a limited number of access points (for example, you create a group for
four access points in a remote office), the clients roam only among those four access points, and the
CCKM cache is distributed among those four access points only when the clients associate to one of
them.
Note
CCKM fast roaming among hybrid-REAP and non-hybrid-REAP access points is not supported. Refer
to the
“WPA1 and WPA2” section on page 6-22
for information on configuring CCKM.
Backup RADIUS
server
WAN link
Branch
802.1x
DHCP server
VLAN 101
Local VLAN
Local switch
231941
Trunk port
native VLAN 100
Trunk port
native VLAN 100
Hybrid-REAP Access Points