Converged Wired and Wireless Access
Provisioning a Small Branch WLAN
94
Best Practice User Guide for the Catalyst 3850 and Catalyst 3650 Switch Series
Step 1
Enable the AAA RADIUS server.
You must match the following configuration with an equivalent configuration on the RADIUS server.
Configure the WLAN with IEEE 802.1x Authentication
Step 2
Create a WLAN with WPA2 and IEEE 802.1x enabled.
Although the controller and access points support WLAN with SSID using WPA and WPA2
simultaneously, some wireless client drivers cannot support complex SSID settings.
Whenever possible, we recommend only WPA2 be configured with Advanced Encryption Standard
(AES).
Note
WPA2 with AES encryption and IEEE 802.1x key management are enabled by default on the WLAN for
the switch so you do not need to explicitly configure these security settings.
aaa authentication dot1x default group RADIUS
aaa authorization network default group RADIUS
aaa accounting dot1x default start-stop group RADIUS
! Enable 802.1X authentication globally on the switch