68
Cisco Aironet 1520, 1130, 1240 Series Wireless Mesh Access Points, Design and Deployment Guide, Release 6.0
OL-20213-01
Connecting the Cisco 1520 Series Mesh Access Point to Your Network
Configuring External Authentication and Authorization Using a RADIUS Server
External authorization and authentication of mesh access points using a RADIUS server such as Cisco
ACS (4.1 and later) is supported in release 5.2 and later. The RADIUS server must support the client
authentication type of EAP-FAST with certificates.
Before you employ external authentication within the mesh network, you must make these changes:
•
Configure the RADIUS server to be used as an AAA server must be configured on the controller.
•
The controller must also be configured on the RADIUS server.
•
Add the mesh access point configured for external authorization and authentication to the user list
of the RADIUS server.
–
For additional details, refer to the
“Adding a Username to a RADIUS Server” section on
•
Configure EAP-FAST on the RADIUS server and install the certificates. EAP-FAST authentication
is required if mesh access points are connected to the controller using an 802.11a interface; the
external RADIUS servers need to trust Cisco Root CA 2048. For information on installing and
trusting the CA certificates, see the
“Configuring RADIUS Servers” section on page 68
.
Note
If mesh access points connect to a the controller using a Fast Ethernet or Gigabit Ethernet
interface, only MAC authorization is required.
Note
This feature also supports local EAP and PSK authentication on the controller.
Configuring RADIUS Servers
Follow these steps to install and trust the CA certificates on the RADIUS server:
Step 1
Using Internet Explorer, download the CA certificates for Cisco Root CA 2048:
http://www.cisco.com/security/pki/certs/crca2048.cer
http://www.cisco.com/security/pki/certs/cmca.cer
Step 2
Install the certificates:
a.
From the CiscoSecure ACS main menu, click, click
System Configuration
>
ACS Certificate
Setup
>
ACS Certification Authority Setup
.
b.
In the
CA certificate file
box, type the CA certificate location (path and name). For example:
c:\Certs\crca2048.cer.
c.
Click
Submit
.
Step 3
Configure the external RADIUS servers to trust the CA certificate.
a.
From the CiscoSecure ACS main menu, choose
System Configuration
>
ACS Certificate Setup
>
Edit Certificate Trust List
. The Edit Certificate Trust List appears.
b.
Check the check box next to the
Cisco Root CA 2048 (Cisco Systems)
certificate name.
c.
Click
Submit
.
d.
To restart ACS, choose
System Configuration
>
Service Control
, and then click
Restart
.