5-8
Cisco Wireless LAN Controller Configuration Guide
OL-17037-01
Chapter 5 Configuring Security Solutions
Configuring RADIUS
Figure 5-3
RADIUS Authentication Servers > New Page
Step 7
If you are adding a new server, choose a number from the Server Index (Priority) drop-down box to
specify the priority order of this server in relation to any other configured RADIUS servers providing
the same service. You can configure up to 17 servers. If the controller cannot reach the first server, it
tries the second one in the list, then the third one if necessary, and so on.
Step 8
If you are adding a new server, enter the IP address of the RADIUS server in the Server IP Address field.
Step 9
From the Shared Secret Format drop-down box, choose
ASCII
or
Hex
to specify the format of the shared
secret key to be used between the controller and the RADIUS server. The default value is ASCII.
Step 10
In the Shared Secret and Confirm Shared Secret fields, enter the shared secret key to be used for
authentication between the controller and the server.
Note
The shared secret key must be the same on both the server and the controller.
Step 11
If you are configuring a new RADIUS authentication server and want to enable AES key wrap, which
makes the shared secret between the controller and the RADIUS server more secure, follow these steps.
AES key wrap is designed for Federal Information Processing Standards (FIPS) customers and requires
a key-wrap compliant RADIUS authentication server.
a.
Check the
Key Wrap
check box.Choose
ASCII
or
Hex
from the Key Wrap Format drop-down box
to specify the format of the AES key wrap keys: Key Encryption Key (KEK) and Message
Authentication Code Key (MACK).
b.
In the Key Encryption Key (KEK) field, enter the 16-byte KEK.
c.
In the Message Authentication Code Key (MACK) field, enter the 20-byte KEK.
Step 12
If you are adding a new server, enter the RADIUS server’s UDP port number for the interface protocols
in the Port Number field. The valid range is 1 to 65535, and the default value is 1812 for authentication
and 1813 for accounting.