WDS, Fast Secure Roaming, and Radio Management
Understanding Fast Secure Roaming
3
Cisco 3200 Series Wireless MIC Software Configuration Guide
Figure 1
Client Authentication Using a RADIUS Server
When you configure your wireless LAN for fast, secure roaming, however, LEAP-enabled client devices
roam from one access point to another without involving the main server. Using Cisco Centralized Key
Management (CCKM), an access point configured to provide WDS takes the place of the RADIUS
server and authenticates the client so quickly that there is no perceptible delay in voice or other
time-sensitive applications.
Figure 2
shows client reassociation using CCKM.
Figure 2
Client Reassociation Using CCKM and a WDS Access Point
Access point
or bridge
Wired LAN
Client
device
RADIUS Server
1. Authentication request
2. Identity request
3. Username
(relay to client)
(relay to server)
4. Authentication challenge
5. Authentication response
(relay to client)
(relay to server)
6. Authentication success
7. Authentication challenge
(relay to client)
(relay to server)
8. Authentication response
9. Successful authentication
(relay to server)
65583
88964
Reassociation request
Reassociation response
Pre-registration request
Pre-registration reply
Roaming client
device
Access point
WDS Device - Router/
Switch/AP
Authentication server
Wired LAN