• Add the mesh access point configured for external authorization and authentication to the user list of
the RADIUS server.
◦ For additional details, see the Adding a Username to a RADIUS Server section.
• Configure EAP-FAST on the RADIUS server and install the certificates. EAP-FAST authentication is
required if mesh access points are connected to the controller using an 802.11a interface; the external
RADIUS servers need to trust Cisco Root CA 2048. For information about installing and trusting the
CA certificates, see the Configuring RADIUS Servers section.
If mesh access points connect to a controller using a Fast Ethernet or Gigabit Ethernet
interface, only MAC authorization is required.
Note
This feature also supports local EAP and PSK authentication on the controller.
Note
Configuring RADIUS Servers
To install and trust the CA certificates on the RADIUS server, follow these steps:
Step 1
Download the CA certificates for Cisco Root CA 2048 from the following locations:
•
http://www.cisco.com/security/pki/certs/crca2048.cer
•
http://www.cisco.com/security/pki/certs/cmca.cer
Step 2
Install the certificates as follows:
a) From the CiscoSecure ACS main menu, click
System Configuration
>
ACS Certificate Setup
>
ACS Certification
Authority Setup
.
b) In the
CA certificate file
box, type the CA certificate location (path and name). For example: C:\Certs\crca2048.cer.
c) Click
Submit
.
Step 3
Configure the external RADIUS servers to trust the CA certificate as follows:
a) From the CiscoSecure ACS main menu, choose
System Configuration
>
ACS Certificate Setup
>
Edit Certificate
Trust List
. The Edit Certificate Trust List appears.
b) Select the check box next to the
Cisco Root CA 2048 (Cisco Systems)
certificate name.
c) Click
Submit
.
d) To restart ACS, choose
System Configuration
>
Service Control
, and then click
Restart
.
For additional configuration details on Cisco ACS servers, see the following:
•
http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_installation_and_configuration_
guides_list.html
(Windows)
•
http://www.cisco.com/en/US/products/sw/secursw/ps4911/
(UNIX)
Cisco Mesh Access Points, Design and Deployment Guide, Release 7.3
110
OL-27593-01
Connecting the Cisco 1500 Series Mesh Access Points to the Network
Configuring External Authentication and Authorization Using a RADIUS Server