config mesh security eap
config macfilter mac-delimiter colon
config mesh security rad-mac-filter enable
config mesh radius-server index enable
config mesh security force-ext-auth enable
d) To provide external authentication on a RADIUS server using a MAC username (such as c1520-123456) on the
RADIUS server, enter these commands:
config macfilter mac-delimiter colon
config mesh security rad-mac-filter enable
config mesh radius-server index enable
config mesh security force-ext-auth enable
Step 7
To save your changes, enter this command:
save config
Viewing Global Mesh Parameter Settings (CLI)
Use these commands to obtain information on global mesh settings:
•
show mesh client-access
—When Universal Client Access is enabled, it allows wireless client association
over the backhaul radio. Generally, backhaul radio is a 5-GHz radio for most of the mesh access points
except for 1522 where backhaul can be 2.4 GHz. This means that a backhaul radio can carry both backhaul
traffic and client traffic.
When Universal Client Access is disabled, only backhaul traffic is sent over the backhaul radio and
client association is only over the second radio(s).
(Cisco Controller)>
show mesh client-access
Backhaul with client access status: enabled
•
show mesh ids-state
—Shows the status of the IDS reports on the backhaul as either enabled or disabled.
(Cisco Controller)>
show mesh ids-state
Outdoor Mesh IDS(Rogue/Signature Detect): .... Disabled
•
show mesh config
—Displays global configuration settings.
(Cisco Controller)>
show mesh config
Mesh Range....................................... 12000
Mesh Statistics update period.................... 3 minutes
Backhaul with client access status............... disabled
Background Scanning State........................ enabled
Backhaul Amsdu State............................. disabled
Mesh Security
Security Mode................................. EAP
External-Auth................................. disabled
Use MAC Filter in External AAA server......... disabled
Force External Authentication................. disabled
Cisco Mesh Access Points, Design and Deployment Guide, Release 7.3
OL-27593-01
117
Connecting the Cisco 1500 Series Mesh Access Points to the Network
Configuring Global Mesh Parameters