Cisco Aironet 2700i manuel d'utilisation

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511

Aller à la page of

Un bon manuel d’utilisation

Les règles imposent au revendeur l'obligation de fournir à l'acheteur, avec des marchandises, le manuel d’utilisation Cisco Aironet 2700i. Le manque du manuel d’utilisation ou les informations incorrectes fournies au consommateur sont à la base d'une plainte pour non-conformité du dispositif avec le contrat. Conformément à la loi, l’inclusion du manuel d’utilisation sous une forme autre que le papier est autorisée, ce qui est souvent utilisé récemment, en incluant la forme graphique ou électronique du manuel Cisco Aironet 2700i ou les vidéos d'instruction pour les utilisateurs. La condition est son caractère lisible et compréhensible.

Qu'est ce que le manuel d’utilisation?

Le mot vient du latin "Instructio", à savoir organiser. Ainsi, le manuel d’utilisation Cisco Aironet 2700i décrit les étapes de la procédure. Le but du manuel d’utilisation est d’instruire, de faciliter le démarrage, l'utilisation de l'équipement ou l'exécution des actions spécifiques. Le manuel d’utilisation est une collection d'informations sur l'objet/service, une indice.

Malheureusement, peu d'utilisateurs prennent le temps de lire le manuel d’utilisation, et un bon manuel permet non seulement d’apprendre à connaître un certain nombre de fonctionnalités supplémentaires du dispositif acheté, mais aussi éviter la majorité des défaillances.

Donc, ce qui devrait contenir le manuel parfait?

Tout d'abord, le manuel d’utilisation Cisco Aironet 2700i devrait contenir:
- informations sur les caractéristiques techniques du dispositif Cisco Aironet 2700i
- nom du fabricant et année de fabrication Cisco Aironet 2700i
- instructions d'utilisation, de réglage et d’entretien de l'équipement Cisco Aironet 2700i
- signes de sécurité et attestations confirmant la conformité avec les normes pertinentes

Pourquoi nous ne lisons pas les manuels d’utilisation?

Habituellement, cela est dû au manque de temps et de certitude quant à la fonctionnalité spécifique de l'équipement acheté. Malheureusement, la connexion et le démarrage Cisco Aironet 2700i ne suffisent pas. Le manuel d’utilisation contient un certain nombre de lignes directrices concernant les fonctionnalités spécifiques, la sécurité, les méthodes d'entretien (même les moyens qui doivent être utilisés), les défauts possibles Cisco Aironet 2700i et les moyens de résoudre des problèmes communs lors de l'utilisation. Enfin, le manuel contient les coordonnées du service Cisco en l'absence de l'efficacité des solutions proposées. Actuellement, les manuels d’utilisation sous la forme d'animations intéressantes et de vidéos pédagogiques qui sont meilleurs que la brochure, sont très populaires. Ce type de manuel permet à l'utilisateur de voir toute la vidéo d'instruction sans sauter les spécifications et les descriptions techniques compliquées Cisco Aironet 2700i, comme c’est le cas pour la version papier.

Pourquoi lire le manuel d’utilisation?

Tout d'abord, il contient la réponse sur la structure, les possibilités du dispositif Cisco Aironet 2700i, l'utilisation de divers accessoires et une gamme d'informations pour profiter pleinement de toutes les fonctionnalités et commodités.

Après un achat réussi de l’équipement/dispositif, prenez un moment pour vous familiariser avec toutes les parties du manuel d'utilisation Cisco Aironet 2700i. À l'heure actuelle, ils sont soigneusement préparés et traduits pour qu'ils soient non seulement compréhensibles pour les utilisateurs, mais pour qu’ils remplissent leur fonction de base de l'information et d’aide.

Table des matières du manuel d’utilisation

  • Page 1

    Cisco Systems, Inc. www.cisco.com Cisco has more than 200 offices worldwide. Addresses, phone numbers, and fax numbers are listed on the Cisco we bsite at www.cisco.com/go/ offices. Cisco IOS Conf iguration Guide for A utonomous Cisco Air onet A ccess P oints Cisco IOS Release 15 .3(3)J AB Text Part Number: OL -31535-01[...]

  • Page 2

    THE SPECIFICATION S AND INFORMAT ION REGARDING THE PRODUCTS IN THIS MA NUAL ARE SUBJ ECT TO CHANGE WITHOUT NOT ICE. ALL STATEMENTS , INFORMATION , AND RECOMMEN DATIONS I N THIS MANUA L ARE BELIEVE D TO BE ACCURATE BUT ARE PRESENTED WI THOUT WARRANTY OF ANY KIND, EX PRESS OR IMPLIED. USERS MUST TAKE FUL L RESPONSIBILITY FOR THEIR APPLICAT ION OF ANY[...]

  • Page 3

    1 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-29225-01 CONTENTS 1 Preface xix Audience i-xix Purpose i-xix Configuration Procedures and Examples i-xx Organization i-xx Conventi ons i-xxii Related Publication s i-xxii Obtaining Documentation, Obtaining Support, and Security Guid elines i-xxiii CHAPTER 1 Overview of Acc[...]

  • Page 4

    Contents 2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01 Using the Management Pages in the Web-Browser Interfac e 2-2 Using Action Buttons 2-3 Character Restrictions in Entry Fields 2-4 Enabling HTTPS for Secure Brows ing 2-5 Deleting an HTTPS Certificate 2-7 Using Online User Guides 2-7 Disabling the Web-Brow[...]

  • Page 5

    Contents 3 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-29225-01 Connecting to the 155 0 Series Access Point Locally 4-5 Default Radio Settings 4-6 Assigning Basic Settings 4-6 Default Settings on the Easy Setu p Page 4-10 Understanding th e Security Settings 4-11 Using VLANs 4-12 Security Types for an SSID 4-12 Limita[...]

  • Page 6

    Contents 4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01 Prepare a Configuration Information File 4-34 Enable environmental variab les 4-35 Schedule the Configuration Information File Download 4-35 Enabling Autoconf ig via a Boot File 4-36 Checking the Au toconfig Status 4-36 Debugging Autoconfig 4-37 CHAPTER [...]

  • Page 7

    Contents 5 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-29225-01 Monitoring and Maintaining the DHCP Server Access Point 5-26 Show Commands 5-26 Clear Commands 5-26 Debug Command 5-27 Configuring the Access Point for Secure Shell 5-27 Understanding SSH 5-2 7 Configuring SSH 5-27 Support for Secure Copy Protocol 5-28 Co[...]

  • Page 8

    Contents 6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01 Configuring Dual-Radio Fallback 6-7 Radio Tracking 6-8 Fast Ethernet Tracking 6-8 MAC-Address Tracking 6-8 Configuring Radio Data Rates 6-9 Access Points Send Multicast and Ma nagement Frames at Highest Ba sic Rate 6-9 Configuring MCS Rates 6-12 Configur[...]

  • Page 9

    Contents 7 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-29225-01 802.11r Config uration 6-39 CHAPTER 7 Configuring Mu ltiple SSIDs 7-1 Understanding Multiple SSIDs 7-2 Configuring Multiple SSIDs 7-3 Creating an SSID Globally 7-3 Viewing SSIDs Configured Globally 7-5 Using a RADIUS Server to Restrict SSIDs 7-5 Configuri[...]

  • Page 10

    Contents 8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01 Non-Root Bridge Without VLANs 8-11 Root Bridge with VLANs 8-12 Non-Root Bridge with VLANs 8-14 Displaying Spannin g-Tree Status 8-16 CHAPTER 9 Configuring an Acc ess Poin t as a Local Authenticator 9-1 Understanding L ocal Authenticatio n 9-2 Configuring[...]

  • Page 11

    Contents 9 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-29225-01 Combining MAC-Based, EAP, and Open Authentication 11-6 Using CCKM for Authenticated Clients 11-6 Using WPA Key Management 11-7 Configuring Authentication Types 11-9 Assigning Authentication Types to an SSID 11-9 Configuring WPA Migration Mode for Legacy W[...]

  • Page 12

    Contents 10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01 Configuring Access Points to Support Fa st Secure Roaming 12-18 CLI Configuration Example 12 -20 Support for 802.11r 12-20 Configuring Management Frame Protec tion 12-21 Management Fram e Protection 12-21 Client MFP Overview 12-21 Client MFP For Access [...]

  • Page 13

    Contents 11 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-29225-01 TACACS+ Operation 13-24 Configuring TACACS+ 13-24 Default TAC ACS+ Config uration 13-25 Identifying the TACACS+ Server Host and Setting the Authenticatio n Key 13-25 Configuring TACACS+ Login Authentication 13-26 Configuring TACACS+ Authorization for Pr [...]

  • Page 14

    Contents 12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01 Optimized Voice Settings 15 -14 CHAPTER 16 Configuring Filters 16-1 Understanding F ilters 16-2 Configuring Filters Usin g the CLI 16-2 Configuring Filters Usin g the Web-Browser Interface 16-3 Configuring and Enabling MAC Address Filters 16-3 Creating [...]

  • Page 15

    Contents 13 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-29225-01 Enabling the SNMP Agent 18-6 Configuring Community Strings 18-6 Specifying SNMP-Server Group Names 18-8 Configuring SNMP-Server Hosts 18-8 Configuring SNMP-Server Users 18-8 Configuring Trap Managers and Enablin g Traps 18-8 Setting the Agent Contact an [...]

  • Page 16

    Contents 14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01 CHAPTER 20 Managing Firmware and Configurations 20-1 Working with the Flash File System 20-1 Displaying Available File Systems 20-2 Setting the De fault File System 20-3 Displaying Information Abou t Files on a File System 20-4 Changing Directories and [...]

  • Page 17

    Contents 15 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-29225-01 Copying Image Files by Using FTP 20-22 Preparing to Download or Upload an Image File by Using FTP 20 -23 Downloading an Image F ile by Using FTP 20-24 Uploading an Image File by Using FTP 20 -26 Copying Image Files by Using RCP 20-27 Preparing to Downloa[...]

  • Page 18

    Contents 16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01 CHAPTER 23 Troubleshooting 23-1 Checking the LED Indicators 23-2 Checking Power 23-2 Low Power Conditio n 23-2 Checking Basic Settings 23-3 SSID 23-3 WEP Keys 23-3 Security Settings 23-3 Resetting to the Default Configuration 23-4 Using the MODE Button [...]

  • Page 19

    Contents 17 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-29225-01 WDS Messages C-24 Mini IOS Messages C-25 Access Point/Bridge Messages C-26 Cisco Discovery Protocol Messages C-26 External Radius Server Error Messages C-26 LWAPP Error Messages C-27 Sensor Messages C-28 SNMP Error Messages C-29 SSH Error Messages C-3 0 [...]

  • Page 20

    Contents 18 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01[...]

  • Page 21

    -xix Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Preface Audience This guide i s for the ne tworking profe ssional who i nstalls an d manage s Cisco Aironet Access Point s in Autonomous mode. T o use this guide, you should ha ve experience w orking with the Cisco IOS so ftware and be familiar with th e conce[...]

  • Page 22

    -xx Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Configuration Procedur es and Examples P oints an d Bridges for this release. F or inform ation about the standard Ci sco IOS software commands, refer to the Cisco IOS software documentation set a v ailable from the Cisco.com ho me page at Support > Document[...]

  • Page 23

    -xxi Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Organization Chapter 9, “Configuring an Access Point as a Local Authenticator, ” describes how to conf igure the access point to act as a local RADIUS server for your wireless LAN. If the W AN connection to your main RADIUS server fails, the access point a[...]

  • Page 24

    -xxii Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Conventions Conventions This publica tion uses the se con ventions to co n v ey in structions an d informatio n: Command descriptions use these co n v entions: • Commands and ke yword s are in boldface text . • Argum ents for which yo u supply v alues are[...]

  • Page 25

    -xxiii Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Obtaining Do cumentation, Obta ining Support, and Security Guidelines Obtaining Documentation, Obtaining Support, and Security Guidelines For info rmation on obtaining documentatio n, obtaining support , providi ng documentation feedback, security g uideline[...]

  • Page 26

    -xxiv Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Obtaining Documentation, Obtaining Support, and Security G uidelines[...]

  • Page 27

    CH A P T E R 1-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 1 Overview of Access Point Features Cisco Aironet Access Poin ts (herea fter called ac cess points , or abbreviated as APs ) pro vide a secure, affo rdable, and easy-to-use wi reless LAN solution t hat combines mobility and fl exibilit y with the e[...]

  • Page 28

    1-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 1 Overvi ew of Acce ss Point Feature s New Features and Platforms in this Release New Features and Platforms in this Release For full inf ormation on the new fe atures and updates to e xisting feat ures in this release, see the Release Notes for Autonom[...]

  • Page 29

    1-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 1 Overview of Access Point Features New Features and Platforms in this Release – Non Root Bridge – W orkgroup Bridge – Scanner – Spectrum – Repeater Support for Cisco Aironet 1700 Series access point • This access point is b uilt on 3 x4:3(2[...]

  • Page 30

    1-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 1 Overvi ew of Acce ss Point Feature s New Features and Platforms in this Release Automatic Configuring of the Access Point The Autoconf ig feature of autonomou s access points allo ws the AP to do wnload i ts config uration, periodically , from a Secur[...]

  • Page 31

    1-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 1 Overview of Access Point Features Management Options Management Options Y ou can use the wireless de vice management system through the follo wing interfaces: • The Cisco IOS command-line interf ace (CLI), which you use th rough a console port or T [...]

  • Page 32

    1-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 1 Overvi ew of Acce ss Point Feature s Network Config uration Exam ples Figur e 1 -1 Access P oints as Ro ot Units on a Wir ed LAN Repeater Access Point An access point can be configured as a stand-alone rep eater to extend the range of your infrastruct[...]

  • Page 33

    1-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 1 Overview of Access Point Features Network Configuration Examp les Bridges Access points can be conf igured as root or non-root bridges. In th is role, an acc ess point esta blishes a wireless link with a non-root brid ge. T raf f ic is passed o v er t[...]

  • Page 34

    1-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 1 Overvi ew of Acce ss Point Feature s Network Config uration Exam ples you can connect th e printers to a h ub or to a switch, conn ect the hub o r switch to the access point Ethernet port, and configure the access point as a workgroup bridge. Th e wor[...]

  • Page 35

    CH A P T E R 2-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 2 Using the Web-Browser Interface This chapter describes the web-brow ser interface that you can use to conf igure the wireless de vice. This chapter contains the following sections: • Using the W eb-Bro wser Interface for the First T ime, page 2[...]

  • Page 36

    2-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 2 Using th e Web-Browser Interface Using the Web-Browser Inte rf ace for the First Time Using the Web-Browser Interface for the First Time Use the wireless device IP address to br owse to the management system. See t he “Logging into the Access Point?[...]

  • Page 37

    [...]

  • Page 38

    2-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 2 Using th e Web-Browser Interface Using the Management Pages in the Web-Browser Interface Character Restrictions in Entry Fields Y ou canno t use the fo llowing characte rs in the entry fi elds on the web-bro wser interf ace. This is true for all acces[...]

  • Page 39

    2-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 2 Using the W eb-Browser Interface Enabling HTTPS for Secure Browsing Enabling HTTPS for Secure Browsing Y ou can protect the communicatio n with the access point web-b row ser interf ace by enabling HTTPS. HTTPS protects HTTP bro wser sessions by us in[...]

  • Page 40

    2-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 2 Using th e Web-Browser Interface Enabling HTTPS for Sec ure Browsing Step 12 In the Domain Name field, enter a domain name, and then click Appl y . Note Enabling HTTPS automatically disables HTTP . T o maintain HTTP access with HTT PS enabled, check t[...]

  • Page 41

    2-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 2 Using the W eb-Browser Interface Using Online User Guides AP(config)# end In this example, the access point system name is ap3600 , the domain name is company .com , and the IP address of the DNS serv er is 10.91.107.18. For complete descriptio ns of [...]

  • Page 42

    2-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 2 Using th e Web-Browser Interface Disabling the Web-Brow ser Interface ap(config)# ip http server[...]

  • Page 43

    CH A P T E R 3-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 3 Using the Command-Line Interface This chapter describes the Cisco IOS command-line interface (CLI) that you can use to configure the wireless de vice. It contains th e follo wing sections: • Cisco IOS Command Modes, page 3-2 • Getting Help, p[...]

  • Page 44

    3-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 3 Using the Comman d-Line Interface Cisco IOS Command Mode s Cisco IOS Command Modes The Cisco IOS user interface is di vided i nto many dif ferent modes. The commands a v ailable to you depend on which mode y ou are currently in. Enter a quest ion mark[...]

  • Page 45

    3-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 3 Using th e Co mmand-Line Interface Getting Help Getting Help Y ou can enter a ques tion mark (?) at the system prompt to display a list of commands a v ailable for each command mo de. Y ou can also obta in a list of a sso ciated k eywo rds and argumen[...]

  • Page 46

    3-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 3 Using the Comman d-Line Interface Using the no and Default Forms of Com mands Using the no and Default Forms of Commands Most confi guration command s also ha ve a no form. In general, use the no form to disable a feature or function or re v erse the [...]

  • Page 47

    3-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 3 Using th e Co mmand-Line Interface Using Comman d History Changing the Command History Buffer Size By default, the wi reless de vice records ten command lines in i ts history b uf fer . Beginning in pri vile ged EXEC mode, enter this command to change[...]

  • Page 48

    3-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 3 Using the Comman d-Line Interface Using Editing Features Using Editing Features This section descri bes the editing features that can help you manipu late the command line. It contains these sections: • Enabling and Disabling Edit ing Features, page[...]

  • Page 49

    3-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 3 Using th e Co mmand-Line Interface Using Editing Features Editing Command Lines that Wrap Y ou can use a wraparound featu re for commands that e xtend be yond a single line on the screen . When the cursor reaches the right margin, the command line shi[...]

  • Page 50

    3-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 3 Using the Comman d-Line Interface Searching and Filteri ng Output of show and more Commands In this e xample, the access-list global co nfigu ration command entry e xtends be yond one line. When t he cursor first reaches the end of the line, the line [...]

  • Page 51

    3-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 3 Using th e Co mmand-Line Interface Accessing the CLI Accessing the CLI Y ou can open th e wireless device CLI using T elne t or Secure Shell (SSH). Opening the CLI with Telnet Follo w these steps to op en the CLI with T elnet. These steps are for a PC[...]

  • Page 52

    3-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 3 Using the Comman d-Line Interface Accessing the CLI[...]

  • Page 53

    CH A P T E R 4-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 4 Configuring the Access Point for the First Time This chapter describe s how to configure basic settin gs on the wireless de vice for the f irst time. The contents of this chapter are similar to the instru ct ions in the quick start gui de that sh[...]

  • Page 54

    4-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Before You Start • The case-sensitiv e wireless service set id entifier (SSID) for your radio netw ork • If not connected to a DH CP server , a unique IP address for the wireless de vice (such as 17[...]

  • Page 55

    4-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Logging into the Access Point Step 6 Click System Conf iguration and the System Conf iguration screen appears. Step 7 Click the Reset to Defaults b utton to reset all sett ings, including the IP address[...]

  • Page 56

    4-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Obtaining and Assign ing an IP Address • graphica l user interf ace (GUI) • T elnet (if the AP is configured with an IP address) • console port Note Not all mode ls of Cisco A ironet Acce ss Point[...]

  • Page 57

    4-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Connecting to the 1040, 1140, 1240, 1250, 1260, and 2600 Series Access Points Locally Default IP Address Behavior When you connect a 1040, 1130 A G, 1140, 1240, 1 250, 1260, 2600 access point, o r 1300 [...]

  • Page 58

    4-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Default Radio Settings Note Y ou do not need a special crosso ver ca ble to connec t your PC to the po wer injector; yo u can use either a straight-through cable or a crossov er cable. Follo w th ese st[...]

  • Page 59

    4-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Assigning Basic Setting s Step 2 Ente r the wireless device IP address in the bro wser address line and press Enter . An Enter Networ k Passw ord screen appears. Step 3 Press Ta b to bypass the Username[...]

  • Page 60

    4-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Assigning Basic Settings • IPv6 Address —En ter the IPv6 address • Username —Enter the username r equired to access the netw ork. • Password —Enter the password corresponding to t he usernam[...]

  • Page 61

    4-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Assigning Basic Setting s ciphers tkip, open authentication + EAP , n etwork EAP authenti cation, ke y management WP A mandatory , and RADIUS server authentication port 1645. Specify the RADIUS Server a[...]

  • Page 62

    4-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Assigning Basic Settings • Channel —The default chann el setting for the wireless de vi ce radios is least congested; at startup, the wireless device scans for and selects the leas t-congested chan[...]

  • Page 63

    4-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Assigning Basic Setting s Understanding the Security Settings Y ou can conf igure basic securi ty settings in the Easy Setup > Radio Conf iguration section. Y ou can use the options gi v en in this [...]

  • Page 64

    4-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Assigning Basic Settings Using VLANs If you use VLANs on your wi reless LAN and assign SSIDs to VLANs, y ou can create multiple SSIDs using an y of the four security settings on the Express Securi ty p[...]

  • Page 65

    4-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Assigning Basic Setting s EAP Authentication This option en ables 802.1X authentication (such as LEA P , PEAP , EAP-TLS, EAP-F AST , EAP-TTLS, EAP-GTC, EAP-SIM, and other 802.1X/EAP based pro ducts) Th[...]

  • Page 66

    4-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Assigning Basic Settings Limitations of Security Settings The security settings i n the Easy Setup Radio Conf iguration section are designed for simple confi guration of basic security . The options a [...]

  • Page 67

    4-15 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time CLI Configuration Examples CLI Configuration Examples The examples in this section sho w the CLI commands that are equi v alent to creating SSIDs using each security type. This section contai ns these [...]

  • Page 68

    4-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time CLI Configuration Examples no bridge-group 1 unicast-flooding ! Example: Static WEP for Radio 2.4 GHz This exampl e sho ws a part of the conf iguratio n that results from creating an SSID called static[...]

  • Page 69

    4-17 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time CLI Configuration Examples no ip route-cache bridge-group 1 bridge-group 1 subscriber-loop-control bridge-group 1 spanning-disabled bridge-group 1 block-unknown-source no bridge-group 1 source-learning[...]

  • Page 70

    4-18 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time CLI Configuration Examples ! antenna gain 0 station-role root bridge-group 1 bridge-group 1 subscriber-loop-control bridge-group 1 block-unknown-source no bridge-group 1 source-learning no bridge-group[...]

  • Page 71

    4-19 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time CLI Configuration Examples ipv6 address autoconfig ipv6 enable ! ip forward-protocol nd ip http server no ip http secure-server ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/h[...]

  • Page 72

    4-20 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time CLI Configuration Examples ! antenna gain 0 station-role root bridge-group 1 bridge-group 1 subscriber-loop-control bridge-group 1 block-unknown-source no bridge-group 1 source-learning no bridge-group[...]

  • Page 73

    4-21 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Configuring System Power Settings Access Points ipv6 address autoconfig ipv6 enable ! ip forward-protocol nd ip http server no ip http secure-server ip http help-path http://www.cisco.com/warp/public/7[...]

  • Page 74

    4-22 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Support for 802.11n Performance on 1250 Series Access Points with Standard 802.3af PoE Using a Switch That D oes Not Support IEEE 80 2.3af Power Negotiation If you use a switch to pro vide Po wer o ver[...]

  • Page 75

    4-23 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Support for 802.11ac 1. Maximum transmit power will vary by channel and accordin g to individual country regulations. Refer to the product documentation for specific details. 2. Tx—Transmitter. Suppo[...]

  • Page 76

    4-24 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Support for 802.11ac Of f channel scanning or transmissions ar e not suppor ted. The 802.11 ac radio depend s on 802.11n radio s for the of f channel scanning fu nctionality . For e xample, to conf igu[...]

  • Page 77

    4-25 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Assigning an IP Address Using th e CLI 802.11n and 802.11ac u se the po wer le ve ls config ured on 802.11n. Y ou cannot conf igure po wer levels independently for 80 2.11ac. Assigning an IP Address Us[...]

  • Page 78

    4-26 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Configuring the 802.1X Supp licant Configuring the 802.1X Supplicant T raditionally , the dot1x authenticator/client relationship has al ways been a n etwork de vice and a PC client re spectively , as [...]

  • Page 79

    4-27 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Configuring the 802.1X Supplicant ap1240AG> enable Password: xxxxxxx ap1240AG# config terminal Enter configuration commands, one per line. End with CTRL-Z. ap1240AG(config)# dot1x credentials test a[...]

  • Page 80

    4-28 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Configuring IPv6 The follo wing example applys the credentials profile test to the ssid testap1 on a repeater access point. repeater-ap> enable Password: xxxxxxx repeater-ap# config terminal Enter c[...]

  • Page 81

    4-29 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Configuring IPv6 Link-Local Addressses are auto matically configured on inte rf ace using link-local pref ix FE80::/10 (1111 111 0 10). The interface iden tifier i s in the modif ied EUI-64 format. •[...]

  • Page 82

    4-30 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Configuring IPv6 Beginni ng in pri vileged EXEC mode, use the follo win g command to assign a site-local or global add ress to the int erface: ap(config-i f)# ipv6 address i pv6-addr ess [eui-64] Note [...]

  • Page 83

    4-31 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Configuring IPv6 Command Purpose ipv6 nd ? Config ures neighbor disco ve ry protocol. ipv6 nd ns-interval va lue This command is a v ailable only on bridg e group virtual interf ace (BVI). Sets the int[...]

  • Page 84

    4-32 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Configuring IPv6 Configuring IPv6 Access Lists IPv6 access lists (ACL) are used to fi lter traf f ic and restrict ac cess to th e router . IPv6 prefix lists are used to fi lter routing pro tocol update[...]

  • Page 85

    4-33 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Configuring IPv6 IPv6 WDS AP registration The first acti ve IPv6 address is used to register the WDS. Ta b l e 4 - 8 sho ws dif ferent scenarios in the IPv6 WDS AP regi stration process. Note 11r roami[...]

  • Page 86

    4-34 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Automatic Configuring of the Access Point RA filtering RA filterin g increases the security of the IPv6 network by dropping RAs coming from wireless clients. RA filt ering pre v ents misconf igured or [...]

  • Page 87

    4-35 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Automatic Configuring of the Access Poin t </l2tp_cfg> The xml tags used in the conf iguration i nformation f ile are described belo w . Enable environmental variables After you ha ve t he conf i[...]

  • Page 88

    4-36 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Automatic Configuring of the Access Point Step 2 Y ou need to set the correct time zone for the AP to ha ve the correct time, This can be done using the command clock timezone TIMEZONE HH MM, where: ?[...]

  • Page 89

    4-37 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 4 Configuring th e Access Point for the First Time Automatic Configuring of the Access Poin t Debugging Autoconfig Y ou can use the following debugging com mands as requ ired: • Debug commands to see Autoconf ig state machi ne transition: Deb dot11 a[...]

  • Page 90

    4-38 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 4 Configuring the Access Point fo r the First Time Automatic Configuring of the Access Point[...]

  • Page 91

    CH A P T E R 5-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 5 Administrating the Access Point This chapter describes ho w to administrate th e wireless de vice. This chapter contains the follo wing sections: • Disabling the Mo de Button, page 5-2 • Pre venting Unauthorized Access to Y our Access Point, [...]

  • Page 92

    5-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Disabling the Mode Button Disabling the Mode Button Y ou can disable the mode bu tton on access points ha ving a console port by using the global conf iguration [no] boot mode-button co mmand. This command pre v ents p[...]

  • Page 93

    5-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Preventing Unauthorized Acc ess to Your Access Po int Preventing Unauthorized Access to Your Access Point Y ou can pre v ent unauthorized users from r econfigur ing the wireless de vice and vie wing conf iguration infor[...]

  • Page 94

    5-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Protecting Ac cess to Pr ivileged EXEC Commands Default Password and Privilege Level Configuration Ta b l e 5 - 1 show s the default passw ord and pri vile ge le v el conf iguration. Setting or Changing a Static Enable[...]

  • Page 95

    5-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Protecting A ccess to Privile ged EXEC Commands This example sho ws how to ch ange the enable password to l1u2c3k4y5 . The password is not encrypt ed and provides access to le vel 15 (tradi tional pri vileg ed EXEC mode[...]

  • Page 96

    5-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Protecting Ac cess to Pr ivileged EXEC Commands Protecting Enable and Enable Secret Passwords with Encryption T o pro vide an additional layer of security , particularly for p asswords that cr oss the network or t hat [...]

  • Page 97

    5-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Protecting A ccess to Privile ged EXEC Commands If both the enable and enable secret passwords are defined, users must enter the enable secret password. Use the level keyw ord to def ine a passw ord for a specif ic pri [...]

  • Page 98

    5-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Protecting Ac cess to Pr ivileged EXEC Commands T o disable username authenticatio n for a specific user , use the no username na me global configuratio n command. T o disable password checking and allo w connections w[...]

  • Page 99

    5-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Protecting A ccess to Privile ged EXEC Commands Setting the Privilege Level for a Command Beginni ng in priv ileged EXEC mod e, follo w these steps to set the pri vile ge le vel for a command mode: When you set a comman[...]

  • Page 100

    5-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Configuring Easy Setup Configuring Easy Setup Y ou can no w conf igure a network and radio in a single screen using the Easy Set up. Network Configuration T o conf igure an access point using the network config uratio[...]

  • Page 101

    5-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Configuring Spectrum Expert Mode – Spectrum—See Conf iguring Spectrum Expert Mode . • Optimize Radio Networ k—Y ou can either select preconf igured sett ings or customize th e settings for the wirele ss device [...]

  • Page 102

    5-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Controlling Access Point Access with RADIUS Your current security s ettings put c omputer at risk . Controlling Access Point Access with RADIUS This section descri bes ho w to control ad ministrator access to the wir [...]

  • Page 103

    5-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Controlling Access Point Access with RADIUS authentication method or until all def ined methods are exhausted. If auth entication fails at any poin t in this cycl e—meaning that the security server or lo cal username[...]

  • Page 104

    5-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Controlling Access Point Access with RADIUS Defining AAA Server Groups Y ou can conf igure the wireless de vice to use AAA server groups to group e xisting serv er hosts for authentication. Y ou select a subset of the[...]

  • Page 105

    5-15 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Controlling Access Point Access with RADIUS Step 3 radius-server host { hostname | ip-addr ess } [ auth-port port-number ] [ acct-port port-number ] [ timeout seconds ] [ retransmit re tr i es ] [ key string ] Specify [...]

  • Page 106

    5-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Controlling Access Point Access with RADIUS T o remov e the specified RADIUS server , use the no radius-server host hostna me | ip-addr ess global confi guration command. T o remove a serv er group from the conf igura[...]

  • Page 107

    5-17 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Controlling Access Poin t Access with TACACS+ T o disable authorization, use the no aaa author ization { network | exec } method1 global configuration command. Displaying the RADIUS Configuration T o display t he RADIU[...]

  • Page 108

    5-18 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Controlling Access Point Access with TACACS+ authentication met hods are performed. The onl y exceptio n is the default met hod list (which, b y coincidence, is named default ). The default metho d list is automatical[...]

  • Page 109

    5-19 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Controlling Access Poin t Access with TACACS+ T o disable AAA , use the no aaa new-model global confi guration command. T o disable AAA authentic ation, use the no aaa authentication login { default | list-name } metho[...]

  • Page 110

    5-20 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Configuring Ethernet Sp eed and Dupl ex Settings Configuring Ethernet Speed and Duplex Settings Y ou can assign the wir eless de vice Ethernet port speed and duple x settings. W e recommend that you use auto , the def[...]

  • Page 111

    5-21 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Configu ring the A ccess Poin t for L oca l Authentica tion and Authorization Configuring the Access Point for Local Authentication and Authorization Y ou can configure AAA to operate without a serv er by conf iguring [...]

  • Page 112

    5-22 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Configuring the Authen tication Cache and Profile T o disable AAA , use the no aaa new-model global conf iguration command. T o disable authorization, use the no aaa authorization { network | ex ec } method1 global co[...]

  • Page 113

    5-23 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Configuring the Auth enti cation Cache and Profile ! aaa group server tacacs+ tac_admin server 192.168.133.231 cache expiry 1 cache authorization profile admin_cache cache authentication profile admin_cache ! aaa group[...]

  • Page 114

    5-24 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Configuring the Access Poin t to Provide DHCP Service ! ip http server ip http authentication aaa no ip http secure-server ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag ip radius sou[...]

  • Page 115

    5-25 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Configuring the Access Point to Pr ovide DHCP Service http://www .cisco.com/uni vercd/cc/ td/doc/product/so f tware/ios12 2/122cgcr/f ipr_c/ip cprt1/1cfdhcp.htm Beginning in pri vile ged EXEC mode, follo w these steps [...]

  • Page 116

    5-26 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Configuring the Access Poin t to Provide DHCP Service AP(dhcp-config)# end Monitoring and Maintaining the DHCP Server Access Point These sections describe commands you can use to monitor and maintain the DHCP serv er [...]

  • Page 117

    5-27 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Configuring the Ac cess Point for Secure Shell Debug Command T o enable DHCP serv er deb ugging, use this command in pri vileged EXEC mode: debug ip dhcp serv er { even ts | packets | linkage } Use the no form of the c[...]

  • Page 118

    5-28 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Configuring Client ARP Caching Support for Secure Copy Protocol The Secure Copy Protocol (SCP) supports file transf ers between hosts on a network using Secure Shell (SSH) for security . Cisco IOS Release 15.2(2)JB su[...]

  • Page 119

    5-29 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Managing the System Time and Date Optional ARP Caching When a non-Cisco client de vice is associated to an access point and is not passing data, the wireless device might not know the client IP address. If th is situat[...]

  • Page 120

    5-30 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Managing the System Time and Date Understanding Simple Network Time Protocol Simple Network T ime Protocol (SNTP) is a simplif ied, client-only v ersion of NTP . SNTP can only recei ve the time from NTP ser vers; it c[...]

  • Page 121

    5-31 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Managing the System Time and Date • Config uring the T ime Zone, page 5-32 • Config uring Summer T ime (Daylight Saving T ime), page 5-33 Setting the System Clock If you ha ve an outside source on the n etwork that[...]

  • Page 122

    5-32 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Managing the System Time and Date Beginning in privileged EXEC mode, follow these steps to set th e system clock: This exampl e sho ws ho w to manually set the system cl ock to 1:32 p.m. on July 23, 2001: AP# clock se[...]

  • Page 123

    5-33 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Managing the System Time and Date The minutes-offset variable in the clock timezone global conf iguration command is a v ailable for those cases where a local time zone is a percentage of an hour dif ferent from UTC. F[...]

  • Page 124

    5-34 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Managing the System Time and Date The first part of the clock summer -time global conf iguration command specif ies when summer time begins, and t he second part specif ies when it ends. All ti mes are relati ve to th[...]

  • Page 125

    5-35 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Defining H TTP Access Defining HTTP Access By default, 80 is used fo r HTTP access, and port 443 is used for HTTPS access. These values can be customized by the user . Fo llo w these step s to define the HTTP access vi[...]

  • Page 126

    5-36 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Configuring a System N ame and Prompt Configuring a System Name Beginning in pri vileged EXEC mod e, follo w these steps to manually conf igure a system name: When you set the system name, it is also used as the syste[...]

  • Page 127

    5-37 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Configuring a System Name and Prompt Default DNS Configuration Ta b l e 5 - 5 show s the default DN S conf iguration. Setting Up DNS Beginning in pri vile ged EXEC mode, follo w these st eps to set up the wireless devi[...]

  • Page 128

    5-38 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Creating a Banne r default domain name is the v alue set by the ip domain -name global configuration command. If there is a period (.) in the host name, Cisco IOS software lo oks up the IP address without appending an[...]

  • Page 129

    5-39 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Creating a Banner Beginni ng in pri vile ged EXEC mode, follo w these steps to conf igure a MO TD login b anner: T o delete the MO TD banner , use the no banner motd global conf igurati on command. This exampl e sho ws[...]

  • Page 130

    5-40 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Creating a Banne r Configuring a Login Banner Y ou can conf igure a logi n banner to appear on al l c onnected terminals. This b anner appears after the MO TD banner and befo re the login pro mpt. Beginni ng in pri vi[...]

  • Page 131

    5-41 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 5 Administrating the Access Point Upgrading Autonomous Cisc o Aironet Access Points to Lightweig ht Mode Upgrading Autonomous Cisco Aironet Access Points to Lightweight Mode Note For inf ormation on only upgrading the Cisco IOS image on an autonomous a[...]

  • Page 132

    5-42 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 5 Administrating th e Access Point Upgrading Autonomous Cisco Aironet Access Points to Lightweight Mode[...]

  • Page 133

    CH A P T E R 6-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 6 Configuring Radio Settings This chapter describes h ow to config ure radio settings for the wireless device. Th is chapter includes the follo wing sections: • Enabling the Radio Inter face, page 6-2 • Config uring the Role in Radi o Network, [...]

  • Page 134

    6-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Enabling the Radio Interface Enabling the Radio Interface The wireless de vice radios are disabled by def ault. Note Beginni ng with Cisco IOS Release 12.3(8)J A there is no SSID. Y ou must create an SSID before you can enab[...]

  • Page 135

    6-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring the Ro le in Radio Netw ork Configuring the Role in Radio Network Ta b l e 6 - 1 show s the role in the radio netwo rk for each de vice. T able 6-1 Device Role in Radio Netw or k Configurati on Role in Radio Net[...]

  • Page 136

    6-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring the Role in Radio Network Y ou can conf igure the role of an access point or bridge in a radio netw ork. Y ou can also conf igure a fallback role for root access points. The wireless devi ce automatically assumes[...]

  • Page 137

    6-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring the Ro le in Radio Netw ork Step 3 station-role non-root {bridge | wire less-clients} rep e a te r root {access-poi nt | ap-only | bridge [wireless-clients] |fallback [ repeater | shutdo wn]} scanner workgr oup-[...]

  • Page 138

    6-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring the Role in Radio Network Note When you enable the role in the radio netw ork as a non root bridge or a workgroup bridge and enable the interface using the no shut command, the physical status and the so ftware s[...]

  • Page 139

    6-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring the Ro le in Radio Netw ork Note In point-to-mul tipoint bridgin g, WGB is not recommended w ith the root bri dge. WGB should be associated to the root AP i n point-to-multipoi nt bridging setup. Configuring Dua[...]

  • Page 140

    6-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring the Role in Radio Network Radio Tracking Y ou can conf igure the access point to track or monitor the status of one of its radios. It the track ed radio goes down or is disabled, the access point shuts down the o[...]

  • Page 141

    6-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuri ng Radio Data Rates Configuring Radio Data Rates Y ou use the data rate settings to choose the data ra tes the wireless device uses for data transmi ssion. The rates are expressed i n megabits per seco nd. The wir[...]

  • Page 142

    6-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring Radio Data Rates Since multicast frames are no t retransmitted at the MA C layer , stations at the edge of the cell may f ail to recei ve t hem successfully . If reliable reception is a goal, then multicast s sh[...]

  • Page 143

    6-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuri ng Radio Data Rates Step 3 speed 802.11g, 2.4-GHz radio: {[ 1.0 ] [ 2.0 ] [ 5.5 ] [ 6.0 ] [ 9.0 ] [ 11.0 ] [ 12.0 ] [ 18.0 ] [ 24.0 ] [ 36.0 ] [ 48.0 ] [ 54.0 ] [ basic-1.0 ] [ basic-2.0 ] [ basic-5.5 ] [ basic-6[...]

  • Page 144

    6-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring MCS Rates Use the no form of the speed command to remov e one or more data rates from the conf iguration. This example sho ws how to remo ve data rates basic-2.0 and basic-5.5 from the co nfigurat ion: ap# confi[...]

  • Page 145

    6-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring Radi o Transmit Power Enabling 11ac MCS rates MCS rates are configured using the speed command. T o enable 11ac rates, it is mandatory to ha v e at least one basic rate and one 11n rate enabled. The follo wing [...]

  • Page 146

    6-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring Radio Transmit Powe r Beginni ng in priv ileged EXEC mode, fo llo w these steps to set the transmit po wer on access point radios: Use the no form of the po wer command to return the po wer setting to maximum , [...]

  • Page 147

    6-15 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring Radio Channel Setting s Limiting the Power Level for Associated Client Devices Y ou can also limit the po wer le vel on client de vices that associate to the wirel ess de vice. When a client dev ice associates [...]

  • Page 148

    6-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring Radi o Channel Settings Note In places where RF interfe rence might be causing clients to occasionally ge t disc onnected from the wireless network, setting th e wireless interface to r un on a dif ferent channe[...]

  • Page 149

    6-17 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring Radio Channel Setting s Dynamic Frequency Selection Access points with 5-GHz radios configured at th e factory for use in the United States, Europe, Singapore, K orea, Japan, Israel, and T aiwan no w comp ly wi[...]

  • Page 150

    6-18 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring Radi o Channel Settings The full list of channels that r equire DFS is sho wn in Ta b l e 6 - 3 . For autonomou s operation, DFS requires random channel selecti on among the channels listed in Ta b l e 6 - 3 . T[...]

  • Page 151

    6-19 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring Radio Channel Setting s Note W e recommend that you use the world-mode dot 11d co untry-code conf iguration interf ace command to configure a country code on DFS- enabled radios. The IEEE 802.11h protocol requ [...]

  • Page 152

    6-20 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring Radi o Channel Settings Listen Frequencies: 5180( 36) 5200( 40) 5220( 44) 5240( 48) 5260( 52) 5280( 56) 5300( 60) 5320( 64) 5500(100) 5520(104) 5540(108) 5560(112) 5580(116) 5600(120) 5620(124) 5640(128) 5660(13[...]

  • Page 153

    6-21 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring Radio Channel Setting s Blocking Channels from DFS Selection If your re gulatory do main limits the channels th at you can use in specif ic location s--for e xample, indoors or outdoors--you can block groups of[...]

  • Page 154

    6-22 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Enabling and Disabling World Mode Enabling and Disabling World Mode Y ou can conf igure the wireless d e vice to support 802.11d world mode, Ci sco leg acy w orld mode, or world mode roaming. When you enable w orld mode, th[...]

  • Page 155

    6-23 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Disabling and Enabling Short Rad io Preambles Disabling and Enabling Short Radio Preambles The radio preamble is a section of data at the h ead of a frame that helps the APs and clients to synchronize their co mmunication.[...]

  • Page 156

    6-24 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring Transmit and Receive Antenna s • Left—If the wireless de vice has remo v able antennas and you in stall a high-gain ant enna on the wireless de vice's left connector , you should use th is setting for b[...]

  • Page 157

    6-25 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Enabling and Disab ling Gratuitous Probe Response Enabling and Disabling Gratuitous Probe Response Gratuitous Probe Response (GPR) aids in conservi ng battery po wer in dual mo de phones that support cellular and WLAN mode[...]

  • Page 158

    6-26 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring the Ethern et Encapsulation Transfo rmation Method • Cisco K ey Inte grity Protocol (CKIP)—Cisco's WE P ke y permutation t echnique based on an early algorithm presented by the IEEE 802.11i security ta [...]

  • Page 159

    6-27 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Enabling and Disabling Re liable Multicast to Workg roup Bridges Beginni ng in pri vile ged EXEC mode, follo w these steps to conf igure th e encapsulation transformation method: Enabling and Disabling Reliable Multicast t[...]

  • Page 160

    6-28 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Enabling and Disabling Reliable Multicast to Workgro up Bridges Beginni ng in pri vile ged EXEC mode, follo w these steps to conf igure the encapsulation transformation method: Note T o conf igure reliable mul ticast forwar[...]

  • Page 161

    6-29 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Enabling and Disabling Pu bl ic Secure Packet Forwa rding Enabling and Disabling Public Secure Packet Forwarding Public Secure Packet F orwarding (PSPF) pre v ents client de vices associated to an access point from inadver[...]

  • Page 162

    6-30 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Enabling and Disabling Public Secure Pa cket Forwarding Configuring Protected Ports T o pre v ent communication betw een client de vices a ssociated with different access points on your wireless LAN, you can set up protecte[...]

  • Page 163

    6-31 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring the Beacon Period an d the DTIM Configuring the Beacon Period and the DTIM The beacon period is the amount of time between acc ess po int beacons in Kilomicroseconds. One Kµsec equals 1,024 m icroseconds. The [...]

  • Page 164

    6-32 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring the Maximum Data Packe t Retries Use the no form of the command to reset the R TS settings to defaul ts. Configuring the Maximum Data Packet Retries The maximum data retries setting determines the nu mber of att[...]

  • Page 165

    6-33 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring the Fragmen tation Threshold Configuring the Fragmentation Threshold The fragmentation thresh old determin es the size at which packets are fra gmented (sent as se v eral pieces instead of as one block). Use a [...]

  • Page 166

    6-34 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Performing a Ca rrier Busy Test Performing a Carrier Busy Test Y ou can perform a carrier busy test to check the radi o activity on wireless channels. During the carrier busy test, the wireless de vice drops all association[...]

  • Page 167

    6-35 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring VoIP Packet H andling The Stream page appears. Step 4 Click the tab for the radio to conf igure. Step 5 For both CoS 5 (V ideo) and CoS 6 (V oice) user priorities, choose Lo w Latency from the P acket Handl ing[...]

  • Page 168

    6-36 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Configuring VoIP Packet Hand ling In the pre vious command: • Number 1—Defines the number of times the AP should try to resend a packet that was not receiv ed properly (not ackno wledged), for a gi v en priority le v el[...]

  • Page 169

    6-37 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs Configuring ClientLink ap(config-if)#packet max-retries 3 0 fail-threshold 100 500 priority 6 d ap(config-if)#packet max-retries 3 0 fail-threshold 100 500 priority 6 drop-packet Lo w latency P acket rates can also be def [...]

  • Page 170

    6-38 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings Debugging Radi o Functions Note ClientLink is not supported on the 1040, 7 02 series access points. Using the CLI to Configure ClientLink T o enable ClientLink , enter this CLI command in interf ace conf iguration mod e on [...]

  • Page 171

    6-39 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 6 Configuring Radio Settin gs 802.11r Configuration This exampl e sho ws ho w to be gin deb ugging of th e radio system log: AP# debug dot11 syslog This exampl e show s how to stop debu gging of all radio related e v ents: AP# no debug dot11 events Not[...]

  • Page 172

    6-40 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 6 Configuring Radio Settings 802.11r Configuration[...]

  • Page 173

    CH A P T E R 7-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 7 Configuring Multiple SSIDs This chapter describe s how to configure and manage multiple Service Set Identif iers (SSIDs) on th e access point. This chapter contains the following sections: • Understanding Multiple SSIDs, page 7-2 • Config uri[...]

  • Page 174

    7-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 7 Config uring Multi ple SSIDs Understanding Multiple SSIDs Understanding Multiple SSIDs The SSID is an ASCII string that wireless networki ng devices use to estab lish and main tain wireless connectivity . Multiple access points on a network or sub-net[...]

  • Page 175

    7-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 7 Configuring Multiple SSIDs Configuring Multiple SSIDs Configuring Multiple SSIDs These sections contain conf iguratio n information for mul tiple SSIDs: • Creating an SSID Globally , page 7-3 • Using a RADIUS Serv er to Restrict SSIDs, page 7-5 No[...]

  • Page 176

    7-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 7 Config uring Multi ple SSIDs Configuring Multiple SSIDs Note Y ou use the ssid command authenticatio n options to configure an authen tication type for each SSID. See Chapter 9, “Configuring an Access Point as a Local Authenticator, ” fo r instruc[...]

  • Page 177

    7-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 7 Configuring Multiple SSIDs Configuring Multiple SSIDs Note When you enable guest SSID mode for the 802 .11g radio it applies to t he 802.11b radio as well since 802.11b and 802.11g o perate in the same 2.4Ghz band. Use the no form of the command to di[...]

  • Page 178

    7-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 7 Config uring Multi ple SSIDs Configuring Multiple Basic SSIDs (attrib ute 26). V endor -specif ic attrib utes (VSAs) allo w v endors to support their o wn e xtended attrib utes not suitable for general use. The Cisco RADIUS i mpl ementation supports o[...]

  • Page 179

    7-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 7 Configuring Multiple SSIDs Configuring Multiple Basic SSIDs • Any W i-Fi certif ied client device can associat e to an access point using multiple BSSI Ds. • Y ou can enable multiple BSSI Ds on access points that parti cipate in WDS. Configuring M[...]

  • Page 180

    7-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 7 Config uring Multi ple SSIDs Assigning IP Redirection for an SSID When client de vices r eceiv e a beacon that contains a DTIM, the y normally w ake up to check for pending packets. Longer intervals between DTIMs let client s sleep longer and preserv [...]

  • Page 181

    7-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 7 Configuring Multiple SSIDs Assigning IP Redirection for an SSID Y ou can redirect all packets from client devices associat ed using an SSID or redirect only packets directed to specific TCP or UD P ports (as defined in an access control list). When yo[...]

  • Page 182

    7-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 7 Config uring Multi ple SSIDs Including SSIDL IE in an SSID Beacon Configuring IP Redirection Beginni ng in pri vile ged EXEC mode, follo w these steps to conf igure IP redirection for an SSID: Note A CL loggi ng is not supported on the bridging in te[...]

  • Page 183

    7-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 7 Configuring Multiple SSIDs NAC Support for MBSSID Beginning in pri vile ged EXEC mode, follo w these steps to include an SSIDL IE in an SSID beacon: Use the no form of the command to disable SSIDL IEs. By def ault SSIDL IEs are disabled. NAC Support [...]

  • Page 184

    7-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 7 Config uring Multi ple SSIDs NAC Support for MBSSID When an infected client associates with an access point and sends it s state to the RADIUS server , the RADIUS server puts it i nto one of the quarantine V LAN s based on its health. This VLAN is se[...]

  • Page 185

    7-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 7 Configuring Multiple SSIDs NAC Support for MBSSID Configuring NAC for MBSSID Note This feature supports on ly Layer 2 mobility with in VLANs. Layer 3 mobility using netw ork ID is not supported in this feature. Note Before you attempt to enable N A C[...]

  • Page 186

    7-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 7 Config uring Multi ple SSIDs NAC Support for MBSSID authentication open authentication network-eap eap_methods ! dot11 ssid mktg vlan mktg-normal backup mktg-infected1, mktg-infected2, mktg-infected3 authentication open authentication network-eap eap[...]

  • Page 187

    CH A P T E R 8-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 8 Configuring Spanning Tree Protocol This chapter descibes ho w to configure Spanning T r ee Protocol (STP) on your acce ss point/bridge. This chapter contains the following sections: • Understanding Spanning Tree Protocol, page 8-2 • Config ur[...]

  • Page 188

    8-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 8 Configur ing Spanning Tree Protocol Understanding Spannin g Tree Protocol Understanding Spanning Tree Protocol This section describes ho w spanning-tree features work. It includes th is information: • STP Overvie w , page 8-2 • Access Point/Bridge[...]

  • Page 189

    8-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 8 Configuring Spannin g Tree Protocol Understanding Spanning Tree Protocol The access point/bridge maintain s a separate spanning -tree instance for each ac tiv e VLAN co nf igured on it. A bridge ID, con sisting of the brid ge priority and the access p[...]

  • Page 190

    8-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 8 Configur ing Spanning Tree Protocol Understanding Spannin g Tree Protocol • Interfaces incl uded in the spanning -tree instance are selected. Root ports and desi gnated ports ar e put in the forwarding state. • All interfaces not included in the s[...]

  • Page 191

    8-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 8 Configuring Spannin g Tree Protocol Understanding Spanning Tree Protocol Creating the Spanning-Tree Topology In Figure 8-1 , bridge 4 is elected as the spanning-tree root be cause th e priority of all the access point/bridges is set to the def ault (3[...]

  • Page 192

    8-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 8 Configur ing Spanning Tree Protocol Understanding Spannin g Tree Protocol • From blocking to listenin g or to disabled • From listening to learning or to disabled • From learning to forw arding or to disabled • From forwarding to dis abled Fig[...]

  • Page 193

    8-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 8 Configuring Spannin g Tree Protocol Understanding Spanning Tree Protocol • Discards frames re ceiv ed on the port • Does not learn addr esses • Receiv es BPDUs Note If a access point/bridge port is blocked, some broadcast or multicast packets ca[...]

  • Page 194

    8-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 8 Configur ing Spanning Tree Protocol Configuring STP Features • Does not receiv e BPDUs Configuring STP Features Y ou comp lete three m ajor steps t o co nfigure STP on the acce ss point/bridge: 1. If necessary , assign interfaces and sub-interfaces [...]

  • Page 195

    8-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 8 Configuring Spannin g Tree Protocol Configuring STP Features Configuring STP Settings Beginni ng in pri vile ged EXEC mode, follo w these steps to conf igure STP on the access point/bridge: Command Purpose Step 1 configur e terminal Enter global conf [...]

  • Page 196

    8-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 8 Configur ing Spanning Tree Protocol Configuring STP Features STP Configuration Examples These configuration e xamples sho w how to enable STP on root and non-root access po int/bridges with and without VL ANs: • Root Bridge W ithout VLANs, page 8-1[...]

  • Page 197

    8-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 8 Configuring Spannin g Tree Protocol Configuring STP Features interface GigabitEthernet0 no ip address no ip route-cache duplex auto speed auto bridge-group 1 no bridge-group 1 source-learning ! interface BVI1 ip address dhcp client-id GigabitEthernet[...]

  • Page 198

    8-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 8 Configur ing Spanning Tree Protocol Configuring STP Features antenna gain 0 peakdetect stbc station-role non-root bridge-group 1 ! interface GigabitEthernet0 no ip address no ip route-cache duplex auto speed auto bridge-group 1 bridge-group 1 path-co[...]

  • Page 199

    8-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 8 Configuring Spannin g Tree Protocol Configuring STP Features bridge-group 1 bridge-group 1 subscriber-loop-control bridge-group 1 block-unknown-source no bridge-group 1 source-learning no bridge-group 1 unicast-flooding ! interface Dot11Radio0.2 enca[...]

  • Page 200

    8-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 8 Configur ing Spanning Tree Protocol Configuring STP Features no ip route-cache duplex auto speed auto ! interface GigabitEthernet0.1 encapsulation dot1Q 1 native no ip route-cache bridge-group 1 no bridge-group 1 source-learning ! interface GigabitEt[...]

  • Page 201

    8-15 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 8 Configuring Spannin g Tree Protocol Configuring STP Features no ip address no ip route-cache ! ssid vlan1 ! antenna gain 0 stbc station-role non-root ! interface Dot11Radio0.1 encapsulation dot1Q 1 native no ip route-cache bridge-group 1 ! interface [...]

  • Page 202

    8-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 8 Configur ing Spanning Tree Protocol Displaying Spanning-T ree Status encapsulation dot1Q 3 no ip route-cache bridge-group 3 bridge-group 3 path-cost 400 ! interface BVI1 ip address dhcp client-id GigabitEthernet0 no ip route-cache ipv6 address dhcp i[...]

  • Page 203

    CH A P T E R 9-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 9 Configuring an Access Point as a Local Authenticator This chapter describes ho w to conf igure the access poin t as a local authenticator to serve as a stand-alone authenticator for a small wireless LAN or to pro v ide backup authentication servi[...]

  • Page 204

    9-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 9 Co nfiguring an Ac cess Point as a Local Authenticator Understanding Local Authentication Understanding Local Authentication Many smal l wireless LANs that could be made more secure w ith 802.1x authenticatio n do not ha ve access to a RADIUS server .[...]

  • Page 205

    9-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 9 Configuring an Acce ss Point as a Local Auth enticator Configuring a Local Au thenticator Guidelines for Local Authenticators Follo w these guidelines when conf iguring an access point as a local authenticator: • Use an access point that does not se[...]

  • Page 206

    9-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 9 Co nfiguring an Ac cess Point as a Local Authenticator Configuring a Local Authenticato r Step 3 radius-server local Enable the access point as a local authenticator and enter conf iguration mode for the auth enticator . Step 4 nas ip-addr ess key sha[...]

  • Page 207

    9-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 9 Configuring an Acce ss Point as a Local Auth enticator Configuring a Local Au thenticator This exampl e sho ws ho w to set up a lo cal authenticator used by three access points with three user groups and sev eral users: AP# configure terminal AP(confi[...]

  • Page 208

    9-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 9 Co nfiguring an Ac cess Point as a Local Authenticator Configuring a Local Authenticato r AP(config-radsrv)# user 00095125d02b password 00095125d02b group cashiers AP(config-radsrv)# user 00079431f04a password 00079431f04a group cashiers AP(config-rad[...]

  • Page 209

    9-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 9 Configuring an Acce ss Point as a Local Auth enticator Configuring a Local Au thenticator Each time the access point t ries to use the main serv ers while they are do wn, th e client de vice trying to authenticate might repor t an authentication timeo[...]

  • Page 210

    9-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 9 Co nfiguring an Ac cess Point as a Local Authenticator Configuring a Local Authenticato r In this example, the local authenticat or generates a P AC for the username joe , password-protects the file with the password bingo , sets the P A C to e xpire [...]

  • Page 211

    9-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 9 Configuring an Acce ss Point as a Local Auth enticator Configuring a Local Au thenticator If your local authenticator does not recei ve i ts time setting from an NTP serv er and it reboots frequently , P ACs generated by th e local auth enticator migh[...]

  • Page 212

    9-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 9 Co nfiguring an Ac cess Point as a Local Authenticator Configuring a Local Authenticato r The first sectio n of statistics lists cumulati v e statistics from t he local authenticator . The second section lists stats for each acces s point (N AS) auth[...]

  • Page 213

    CH A P T E R 10-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 10 Configuring WLAN Authentication and Encryption This chapter descr ibes how to co nf igure auth entication an d encryptio n schemes to protect your WLANs. Encryption can be achie v ed using shared ke ys or indi vidual client ke ys. Indi vidual c[...]

  • Page 214

    10-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 10 Configuring WL AN Authentication and Encryption Understanding Authe ntication and Encryption Mechanisms Understanding Authentication and Encryption Mechanisms Just as anyone with in range of a radio station can tune to the station's frequ ency [...]

  • Page 215

    10-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 10 Configuring WLAN Authe ntication and Encryptio n Understanding Auth entication and Encryption Mechanisms will change to WEP if a WEP cl ient joins the cell). Wh en the cell contains only AES clients, the broadcast ke y uses AES (and will change t o [...]

  • Page 216

    10-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 10 Configuring WL AN Authentication and Encryption Understanding Authe ntication and Encryption Mechanisms Open with EAP A ny ciphe r (WEP 40, WEP 128, TKIP , CKIP , CMIC, CKIP-CMIC, TKIP + WEP 40, TKIP+WEP 128, AES-CCMP , AES-CCMP+TKIP , AES-CCMP + TK[...]

  • Page 217

    10-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 10 Configuring WLAN Authe ntication and Encryptio n Understanding Auth entication and Encryption Mechanisms Y ou can enable Netwo rk EAP authentication in comb ination with Op en (with EAP or not, and any combination of MA C, namely Network EAP with or[...]

  • Page 218

    10-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 10 Configuring WL AN Authentication and Encryption Understanding Encr yption Modes Understanding Encryption Modes As encryption is defin ed at the interf ace (VLAN or radio) le ve l of the access point, and can be common to se veral SSIDs, encrypti on [...]

  • Page 219

    10-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 10 Configuring WLAN Authe ntication and Encryptio n Configuring Encryption Modes • WEP (W ired Equi valent Pri v acy)—WEP is an 802.1 1 standard encryption algorith m originally designed to pro vide your wir eless LAN with the same le v el of pri v[...]

  • Page 220

    10-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 10 Configuring WL AN Authentication and Encryption Configuring Encryp tion Modes Creating Static WEP Keys Note Y ou need to configure static WEP keys only if your access point needs to support client de vices that use static WEP . If all the client dev[...]

  • Page 221

    10-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 10 Configuring WLAN Authe ntication and Encryptio n Configuring Encryption Modes This example sh ow s how to create a 128-bit WEP k ey in slot 3 f or VLAN 22 and sets the ke y as the transmit k ey: ap1200# configure terminal ap1200(config)# interface d[...]

  • Page 222

    10-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 10 Configuring WL AN Authentication and Encryption Configuring Encryp tion Modes Because the access point’ s WEP ke y 1 is selected as the transmit ke y , WEP ke y 1 on the other de vice must ha ve t he same contents. WEP ke y 4 on the other de vice[...]

  • Page 223

    10-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 10 Configuring WLAN Authe ntication and Encryptio n Configuring Encryption Modes Use the no form of the encryption command to disable a cipher suite. Matching Cipher Suites with WPA or CCKM If you conf igure your access point to use WP A or CCKM authe[...]

  • Page 224

    10-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 10 Configuring WL AN Authentication and Encryption Configuring Encryp tion Modes Note If using WP A and CCKM as ke y ma nagement, only tk ip and aes ciphers are supported . If using only CCKM as key management, ckip, cmic, ckip-cmic, tkip, wep, and ae[...]

  • Page 225

    10-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 10 Configuring WLAN Authe ntication and Encryptio n Configuring Encryption Modes Enabling and Disabling Broadcast Key Rotation Broadcast key rotation is disabled by def ault. Note Client devices using static WEP cannot use the acces s point when you e[...]

  • Page 226

    10-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 10 Configuring WL AN Authentication and Encryption Configuring Encryp tion Modes Use the no form of the encryption command to disable b roadcast key rotation. This ex ample enables broadc ast ke y rotation on VLAN 2 2 and sets the rotation in terval t[...]

  • Page 227

    CH A P T E R 11-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 11 Configuring Authentication Types This chapter describes how to conf igure authenticati on types on the access point. This chapter contains the following sections: • Understanding Authen tication T ypes, page 11-2 • Config uring Authenticati[...]

  • Page 228

    11-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Understanding Authe ntication Types Understanding Authentication Types This section describes in detail the authentication types that you can configure on the access point. The authentication types are ti ed to the [...]

  • Page 229

    11-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Understanding Authentication Types In a scenario where you use Open authentication and WEP encryption, authentication will be successful e ven if the client and the AP WEP are mismatched. Th e client will not be ab [...]

  • Page 230

    11-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Understanding Authe ntication Types EAP Authentication to the Network This authentication t ype provides t he highest le vel o f security for your wireless network. By using t he Extensible A uthentica tion Protoco [...]

  • Page 231

    11-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Understanding Authentication Types When mutual auth entication is complete, the RADIUS serv er and the client determine a a WEP k ey or a Pairwise Mast er K ey (WP A v1/v2) that is unique to the client and pro vides[...]

  • Page 232

    11-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Understanding Authe ntication Types Figur e 1 1 -4 Sequence for MAC-Based A uthentication Combining MAC-Based, EAP, and Open Authentication Y ou can set up the access point to authen ticate c lient devices using a c[...]

  • Page 233

    11-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Understanding Authentication Types Figure 11-5 sho ws the reassociation process using CCKM. Figur e 1 1 -5 Client R eassociation Using CCKM Using WPA Key Management WP A v1 is a W i-Fi Alliance certif ication based [...]

  • Page 234

    11-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Understanding Authe ntication Types Note Unicast and multicast cipher suites adv ertised in WP A information element (and negotiated during 802.11 association) may po tentially mismatch with the ciph er suite supp o[...]

  • Page 235

    11-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Configuring Authen tica tion Types Configuring Authentication Types This section descri bes ho w to conf igure authen ticat ion types. Y ou attach conf iguration types to the access point’ s SSIDs . See the “Con[...]

  • Page 236

    11-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Configuring Authen tication Types Step 3 authentication open [ mac-address list-name [ al ternate ]] [[ optional ] eap list-name ] (Optional) Set the authenticati on type to open for this SSID. Open authenticati on[...]

  • Page 237

    11-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Configuring Authen tica tion Types Step 5 authentication network-eap list-name [ mac-address list-name ] (Optional) set the authenticati on type for the SSID t o Network-EAP . Using the Extens ible Authentication P[...]

  • Page 238

    11-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Configuring Authen tication Types Step 6 authentication key-management {[ wpa [version versionnum ber ]] | [ cc km ] } [ optional ] (Optional) Set the authenticati on type for the SSID to WP A, CCKM, or both . If y[...]

  • Page 239

    11-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Configuring Authen tica tion Types Use the no form of the SSID commands to disable th e SSID or to disable SSID features. This exampl e sets the authenticati on type for the SSID batman to Network-EAP wi th CCKM au[...]

  • Page 240

    11-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Configuring Authen tication Types Configuring Additional WPA Settings Use two opti onal settings to conf ig ure a pre-shared ke y on the access point and adjust the frequenc y of group k ey upd ates. Setting a pre-[...]

  • Page 241

    11-15 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Configuring Authen tica tion Types This exampl e sho ws ho w to conf igure a pre-shared k ey for cli ents using WP A and static WEP , with group ke y update options: ap# configure terminal ap(config-if)# ssid batma[...]

  • Page 242

    11-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Configuring Authen tication Types This exampl e sho ws how to enable MA C authentication caching with a one-hour timeout: ap# configure terminal ap(config)# dot11 aaa authentication mac-authen filter-cache timeout [...]

  • Page 243

    11-17 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Configuring Authen tica tion Types Use the no form of these commands to reset the v alues to def ault settings. Creating and Applying EAP Method Pr ofiles for the 802.1X Supplicant This section descri bes the optio[...]

  • Page 244

    11-18 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Configuring Authen tication Types Creating an EAP Method Profile Beginni ng in pri vile ged ex ec mode, follo w these steps to def ine a ne w EAP profile: Use the no command to negate a command or set it s defaults[...]

  • Page 245

    11-19 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Configuring Authen tica tion Types Command Purpose Step 1 configur e terminal Enter the global co nfiguration m ode. Step 2 interface gigabitethernet 0 Enter the interface configuration mo de for the access point?[...]

  • Page 246

    11-20 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Matching Access Point and Client Device Au thentication Types Applying an EAP Prof ile to an Uplink SSID This operation typical ly applies to repeater access points, non-roo t bridges and workgro up bridges needing[...]

  • Page 247

    11-21 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Matching Access Point and Client Device Authentication Type s T able 1 1 -1 Client and Access P oint Secur ity Set tings Security Feature Client Setting Access Point Setting Static WEP with open authentication Crea[...]

  • Page 248

    11-22 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Matching Access Point and Client Device Au thentication Types 802.1X authen tication and CCKM Enable LEAP Select a ciph er suite and enable Open with EAP and/o r Network EAP , and CCKM for the SSID. Note T o allo w[...]

  • Page 249

    11-23 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Guest Access Management Guest Access Management Guest Access allows a guest to gain access to the Internet, and the guest’ s own enterpr ise without compromising the security of the host enterprise. Guest access [...]

  • Page 250

    11-24 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Guest Access Man agement – ap(config-ssid)# authentication open – ap(config-ssid)# exit • T o enable web au thentication: – ap(config)# ip admission name W eb_auth pr oxy http – ap(config)# interface dot1[...]

  • Page 251

    11-25 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Guest Access Management Step 4 T o let the system automatically generate a r andom string as a password , check the Generate Passw ord check box. Alternati v ely , you can manually enter the passwo rd v alue. Step [...]

  • Page 252

    11-26 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Guest Access Man agement Step 4 Save the customized pages to the web server . Step 5 In the access point GUI, browse to the Management > Guest Management Services page. Step 6 Select W ebauth Login. Step 7 Brows[...]

  • Page 253

    11-27 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 11 Configuring Authen tication Types Guest Access Management Note In the pre vious commands acl-in and acl-out are the names of the Acces s-list. These A CLs allo w you to do wnload the i mage f ile from t he ma chine, where it is stored and us e it f[...]

  • Page 254

    11-28 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 11 Configurin g Authentication Types Guest Access Man agement[...]

  • Page 255

    CH A P T E R 12-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 12 Configuring WDS, Fast Secure Roaming, Radio Management, and Wireless Intrusion Detection Services This chapter describes how to configure your access points for wireless domain services (WDS), fast, secure roaming of cli ent devices, radio mana[...]

  • Page 256

    12-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Understanding WDS Understanding WDS When you conf igure W ireless Domain Services on your network, access point s on your wirele ss LAN use the WDS device ([...]

  • Page 257

    12-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Understanding Fast Secure Roaming Role of Access Points Using the WDS Device The access points on your wir eless LAN intera ct with the WDS device in[...]

  • Page 258

    12-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Understanding Wireless Intr usion Detection Services Figur e 12-2 Client Reassociation Using CCKM and a WDS Access P oint The WDS device maintains a cache o[...]

  • Page 259

    12-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring WDS • Switch port tracing and rogu e suppression—Switch port tracing and suppression uses an RF detection method th at produces the r[...]

  • Page 260

    12-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring WDS Guidelines for WDS Follo w th ese guidelines when conf iguring WDS: • A WDS access point that also serves client de vi ces supports up to [...]

  • Page 261

    12-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring WDS Figure 12-3 sho ws the required conf iguration for each de vice that pa rticipates in WDS. Figure 12-3 Configurations on Devi ces Par[...]

  • Page 262

    12-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring WDS Figure 12-4 General Setup Hostname ap pa ge Step 3 Check the Use this AP as W ireless Domain Services check box. Step 4 In the Wi reless Dom[...]

  • Page 263

    12-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring WDS Step 12 Configure the list of servers to be use d for 802.1x authen tication for wire less client devices. Y ou can specify a separat[...]

  • Page 264

    12-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring WDS For complete descriptio ns of the command s used in this e xample, co nsult the Cisco IOS Command Refer ence for Cisco Air onet Access P oi[...]

  • Page 265

    12-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring WDS Step 5 In the Password field, enter a password for the access point, and enter the password again in the Confirm Passwo rd f ield. T[...]

  • Page 266

    12-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring WDS Configuring the Authentication Server to Support WDS The WDS device and all access points participating in WDS must authenticat e to your a[...]

  • Page 267

    12-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring WDS Step 6 Check the A uthentication Settings check box. The fiel ds in the Authentication Sett ings area get enabled. Step 7 For the RA[...]

  • Page 268

    12-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring WDS Figure 12-9 Cisco ISE Networ k Access Users pag e detailed Configuring WDS Only Mode WDS access points can operate in WDS onl y mode using [...]

  • Page 269

    12-15 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring WDS Viewing WDS Information On the web-bro wser interface, b ro wse to the W ireless Services Summary page to vie w a summary of WDS sta[...]

  • Page 270

    12-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring WDS Using Debug Messages In pri vileg ed ex ec mode, use these deb ug commands to cont rol the display o f debug messages f or de vices interac[...]

  • Page 271

    12-17 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring Fast Secure Roaming Configuring Fast Secure Roaming After you conf igure WDS, access points conf igured for CCKM can pro vide fast, secu[...]

  • Page 272

    12-18 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring Fa st Secure Roaming Configuring Access Points to Support Fast Secure Roaming T o support f ast, secure roaming, the access points on your wir [...]

  • Page 273

    12-19 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring Fast Secure Roaming Figure 12-1 1 Global SSID Manager P age Step 7 On the tar get SSID wher e CCKM (fa st secure roami ng) needs to be s[...]

  • Page 274

    12-20 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring Fa st Secure Roaming CLI Configuration Example This example sho ws the CLI commands that ar e equiv alent to the steps listed in the “Configu[...]

  • Page 275

    12-21 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring Management Frame Protection Step 7 Click Appl y . Beginning in pri vile ged EXEC mode, perform these steps to conf igure 802.11r usin g [...]

  • Page 276

    12-22 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring Management Frame Pro tection associated). Client MFP lev erages the security me chanisms def ined by IEEE 802.11i to protect class 3 Unicast ma[...]

  • Page 277

    12-23 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring Management Frame Protection Configuring Client MFP The following CLI comm ands can be used to d isplay a nd clear Client MFP statistics [...]

  • Page 278

    12-24 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring Management Frame Pro tection Protection of Management Frames with 802.11w The current 802.11 standard d efines f rame types for use in the mana[...]

  • Page 279

    12-25 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring Radio Mana gement These commands are optional. Def ault time interv als ar e conf igured if these co mmands are not used. T o confi guri[...]

  • Page 280

    12-26 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring Access Points to Participate in WIDS Configuring Access Points to Participate in WIDS T o participate in WIDS, access points must be configured[...]

  • Page 281

    12-27 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 12 Configuring WDS, Fast Secure Roaming, Radio Management, an d Wireless Intrusion Dete ction Services Configuring Access Points to Participate in WIDS Beginning in pri vile ged EXEC mode, follo w these st eps to configure the access point to capture [...]

  • Page 282

    12-28 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 12 Configuring WD S, Fast Secure Roam ing, Radio Management, and Wi reless Intrusio n Detection Configuring Access Points to Participate in WIDS Configuring Monitor Mode Limits Y ou can configure threshold v alues that the access po int uses in monito[...]

  • Page 283

    CH A P T E R 13-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 13 Configuring RADIUS and TACACS+ Servers This chapter describes ho w to enable and con figur e the Remo te Authent icati on Dial-In User Service (RADIUS) and T erminal Access Cont roller Access Control System Plus (T A CA C S+), that provides det[...]

  • Page 284

    13-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling RADIUS Understanding RADIUS RADIUS is a distributed client/server system th at secures networks against unauthorized access. RADIUS clien ts run on suppo rted Cisco devices and send a[...]

  • Page 285

    13-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enab ling RADIUS Figur e 13-1 Sequence fo r EAP A uthentication As s h own i n Figure 13-1 , at the start, a wireless client device and a RADIUS server on the wired LAN use 802.1x and EAP to pe[...]

  • Page 286

    13-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling RADIUS Configuring RADIUS This section descri bes ho w to conf igure your access point to support RADIUS. At the minimum, y ou must identify t he host(s) that run the RADIUS serv er s[...]

  • Page 287

    13-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enab ling RADIUS Identifying the RADIUS Server Host Access point-to-RADIUS-server communi cation in volves se ve ral components: • Host name or IP address • Authentication destinati on port[...]

  • Page 288

    13-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling RADIUS Command Purpose Step 1 configur e terminal Enter global conf iguration mo de. Step 2 aaa new-model Enable AAA. Step 3 radius-server {hostname | ip-address}[ auth-port port-numb[...]

  • Page 289

    13-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enab ling RADIUS T o remov e the specified RADIUS server , use the no radius-server host hostna me | ip-addr ess global confi guration command. This example shows ho w to configure one RADIUS s[...]

  • Page 290

    13-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling RADIUS T o disable AAA , use the no aaa new-model global conf iguration command. T o disable AAA authentic ation, use the no aaa authentication login { default | list-name } method1 [[...]

  • Page 291

    13-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enab ling RADIUS Defining AAA Server Groups Y ou can confi gure the access point to use AAA serv er groups to g roup existi ng server hosts for authentication. Y ou select a subset of the confi[...]

  • Page 292

    13-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling RADIUS Step 3 radius-server host { hostname | ip-addr ess } [ auth-port port-number ] [ acct-port port-number ] [ timeout seconds ] [ retransmit re tr i es ] [ key string ] Specify t[...]

  • Page 293

    13-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enab ling RADIUS T o remov e the specified RADIUS server , use the no radius-server host hostna me | ip-addr ess global confi guration command. T o remove a serv er group from the conf igurati[...]

  • Page 294

    13-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling RADIUS Beginni ng in pri vileged EXEC mode, fol lo w these steps to specify RADIUS authorizatio n for pri vile ged EXEC access and network services: T o disable authorization, use th[...]

  • Page 295

    13-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enab ling RADIUS Note When WDS is configured, PoD requ ests should be directed to the WDS. The WDS forwards the disassociation request to the parent access point and th en purges the sessi on [...]

  • Page 296

    13-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling RADIUS T o return to the d efault CSID format, use t he no form of the dot11 aa a csid command, or enter dot11 aaa csid default . Note Y ou can also use the wlccp wds aaa csid comman[...]

  • Page 297

    13-15 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enab ling RADIUS Configuring Settings fo r All RADIUS Servers Beginni ng in pri vile ged EXEC mode, follo w these steps to conf igure gl obal communication set tings between the acc ess point [...]

  • Page 298

    13-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling RADIUS This example sh ow s how to set up two main ser vers with a serv er deadtime of 10 minutes: ap(config)# aaa new-model ap(config)# radius server server1 ap(config-radius-server[...]

  • Page 299

    13-17 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enab ling RADIUS For a complete list of RADIUS attribut es or more information about VSA 26, see t he RADIUS guides at the follo wing URL: http://www .cisco .com/en/US/docs/ios-xml /ios/securi[...]

  • Page 300

    13-18 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling RADIUS T o delete the v endor -proprietary RADIUS host, use the no radius-server host { hostnam e | ip-addr ess } non-standard global conf iguration command. T o disable the key , us[...]

  • Page 301

    13-19 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enab ling RADIUS Beginning in pri vile ged EXEC mode, follo w these st eps to specify WISPr RADIUS attributes on the access point: This exampl e sho ws ho w to conf igur e the WISPr location-n[...]

  • Page 302

    13-20 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling RADIUS RADIUS Attributes Sent by the Access Point T able 13-2 through Ta b l e 1 3 - 6 identify th e attrib utes sent by an a ccess point to a client in access-request, access-accept[...]

  • Page 303

    13-21 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enab ling RADIUS T a ble 13-4 Attr ibut es Sent in A ccounting-Request (start) P ack ets Attribute ID Description 1U s e r - N a m e 4 N AS-IP-Ad dress 5N A S - P o r t 6 Service-T ype 25 Clas[...]

  • Page 304

    13-22 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling RADIUS Note By default, th e access point sends reauthenti cation requests to the aut hentication serv er with the service-type attrib ute set to authenticat e-only . Ho we ver , som[...]

  • Page 305

    13-23 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enabling TACACS+ Configuring and Enabling TACACS+ This section contains this conf iguration infor mation: • Understanding T A CA CS+, page 13-23 • T A CA CS+ Operation, page 13-24 • Conf[...]

  • Page 306

    13-24 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling TACACS+ TACACS+ Operation When an administrator attempts a simple ASCII login by authenticating to an access po int using T ACA CS+, this process occurs: 1. When the connection i s e[...]

  • Page 307

    13-25 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enabling TACACS+ This section contains this conf iguration infor mation: • Default T A CA CS+ Configuration, page 13-25 • Identifying t he T ACA CS+ Server Host and Setting th e Authentica[...]

  • Page 308

    13-26 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling TACACS+ T o remov e the specified T ACA CS+ server name or address, use the no tacacs -server host hostname global conf iguratio n command. T o rem ov e a server gr oup from the conf[...]

  • Page 309

    13-27 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enabling TACACS+ T o disable AAA , use the no aaa new-model global confi guration command. T o disable AAA authentic ation, use the no aaa authentication login { default | list-name } method1 [...]

  • Page 310

    13-28 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling TACACS+ The aaa authoriza tion exec ta cacs+ local command set s these authorization pa rameters: • Use T ACA CS+ for privile ged EXEC access authorization if aut hentication was p[...]

  • Page 311

    13-29 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 13 Configuring RADIUS and TACACS+ Server s Configuring and Enabling TACACS+ T o disable accoun ting, use the no aaa accounting { network | exec } { start-stop } method 1... global confi guration command. Displaying the TACACS+ Configuration T o displa[...]

  • Page 312

    13-30 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 13 Config uring RADIUS and TACACS+ Servers Configuring and Enab ling TACACS+[...]

  • Page 313

    CH A P T E R 14-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 14 Configuring VLANs This chapter describes how to configure your access point to operate with the VLANs set up on your wired LAN. This chapter contains th e follo wing sections : • Understanding VLANs, page 14-2 • Conf iguring VLANs, p age 14[...]

  • Page 314

    14-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 14 Configuring VLA Ns Understanding VLANs Understanding VLANs A VLAN is a switched network that is logically segmen ted, by functions, project teams, or applications rather than on a physical or geographical basis. For e xample, all w orkstations and s[...]

  • Page 315

    14-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 14 Configuring VLANs Understanding VLANs Figur e 14-1 LAN and VLAN Segmentation with Wire less Devices For more inf ormation on VLAN design and conf igurati on, see the Cisco IOS Switching Services Config uration Guide at th e follo wing URL: http://ww[...]

  • Page 316

    14-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 14 Configuring VLA Ns Configuring VLANs Y ou can assign more than one SSID to a given VLAN. Howe ver , a given SSID can be mapped to only one VLAN. Also, th e SSID to VLAN mappi ng must be unique pe r interface. For e xample, you configure SSID1 and SS[...]

  • Page 317

    14-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 14 Configuring VLANs Configuri ng VLANs Configuring a VLAN Configuring your access point to sup port VLANs is a three-step process: 1. Enable the VLAN on the radio and Ethernet ports. Enabling the VLAN on the radio and Ethernet po rts also create s the[...]

  • Page 318

    14-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 14 Configuring VLA Ns Configuring VLANs Step 2 - Creating an SSID and assigning it to a VLAN Beginni ng in pri vile ged EXEC mode, follo w these steps to assign an SSID to a VLAN. Step 3 - Assigning encryption settings to a VLAN on a given radio interf[...]

  • Page 319

    14-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 14 Configuring VLANs Configuri ng VLANs • Assign an SSID to a VLAN • Assign an AES-CCMP encryption method t o a VLAN • Assign an SSID to a radio inte rface ap# configure terminal ap(config)# interface dot11Radio 0.31 ap(config-subif)# encapsulati[...]

  • Page 320

    14-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 14 Configuring VLA Ns Configuring VLANs Use the no form of the command to remov e the name from the VLAN. Use the show dot11 vlan-name priv ileged EXEC command to list all the VLAN na me and ID pairs configured on the access point. Using a RADIUS Serve[...]

  • Page 321

    14-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 14 Configuring VLANs Configuri ng VLANs Other 0 995 0 packets, 0 bytes input 0 packets, 0 bytes output Other 0 995 0 packets, 0 bytes input 0 packets, 0 bytes output Other 0 995 4330 packets, 363704 bytes input 995 packets, 75675 bytes output Virtual L[...]

  • Page 322

    14-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 14 Configuring VLA Ns VLAN Configuration Ex ample VLAN Configuration Example This example sh ow s how to use VLANs to manage wireless de vices on a colle ge campus. In thi s exam ple, three l e vels of access are a vailable thro ugh VLANs conf igured [...]

  • Page 323

    14-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 14 Configuring VLANs VLAN Configuration Example T able 14-2 sho ws the commands needed to config ure the three VLANs in this example. T able 14-3 sho ws the results of the con figur ation commands i n T able 14-2 . Use the show running command to disp[...]

  • Page 324

    14-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 14 Configuring VLA Ns VLAN Configuration Ex ample Notice that when yo u config ure a bridge group on the radio interf ace, these commands are set automatically: bridge-group 2 subscriber-loop-control bridge-group 2 block-unknown-source no bridge-group[...]

  • Page 325

    CH A P T E R 15-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 15 Configuring QoS This chapter describes how to conf igure quality of se rvice (QoS) on your access point. W ith this feature, you can provide preferential treatment to certain traff i c at the expense of others. W i thout QoS, the access point o[...]

  • Page 326

    15-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 15 Configuring QoS Understanding QoS for Wireless LANs Understanding QoS for Wireless LANs T ypically , networks o perate on a best-ef fort deli v ery ba sis, which means that all traf f ic has equal priority and an equal chance of being deli vered in [...]

  • Page 327

    15-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 15 Configuring QoS Understanding QoS for Wireless LANs Regardless of the client support (or lack of supp ort) for WM M, Cisco access points support WMM and can be configured to pr ovide wireless QoS i n the downst ream directi on (from the AP to wa rd [...]

  • Page 328

    15-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 15 Configuring QoS Understanding QoS for Wireless LANs 2. QoS Element for W ir eless Phones sett ing—If you enable the QoS Elemen t for W ire less Phones setting, dynamic voice classifiers are created for ar e created for R TP-based traff ic, which a[...]

  • Page 329

    15-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 15 Configuring QoS Understanding QoS for Wireless LANs The access point uses WMM enhancements in packets sent to client devices that support WMM. The access point applies basic Q oS policies to pack ets sent to clients that do not support WMM. Use the [...]

  • Page 330

    15-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 15 Configuring QoS Configuring QoS Step 3 Enter the values for the follo wing: • Client-Rssi—Minimum Recei v e Signal Strength Indicator (RSSI) requi red for the client to be eligible for band select. The range is from 20 t o 90. • Cycle-Count—[...]

  • Page 331

    15-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 15 Configuring QoS Configuri ng QoS • QoS does not create additional band width for your wireless LAN ; it helps control the allocat ion of bandwidth. If y ou ha ve plenty o f bandwidth on your wireless LAN, you mi ght not need to conf igure QoS. •[...]

  • Page 332

    15-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 15 Configuring QoS Configuring QoS Note Y ou can also select tw o preconf igured QoS polic ies: WMM and Spectralink. When you select either of these, a set of default classifications are automatically populated in the Classification fie l d . Step 4 If[...]

  • Page 333

    15-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 15 Configuring QoS Configuri ng QoS • Assured Forw arding — Class 3 Medium • Assured Forw arding — Class 3 Hig h • Assured Forw arding — Class 4 Lo w • Assured Forw arding — Class 4 Medium • Assured Forw arding — Class 4 Hig h • C[...]

  • Page 334

    15-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 15 Configuring QoS Configuring QoS Step 16 Use the Apply Policies to Interface/VLANs drop-down lis ts to apply po licies to the access point Ethernet and radio ports. If VLA Ns are confi gured on the access point , drop-do wn list s for each VLANs’ [...]

  • Page 335

    15-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 15 Configuring QoS Configuri ng QoS IGMP Snooping When Internet Group Membership Prot ocol (IGMP ) snooping is enabl ed on a switch, the switch forwards multicast traf f ic only to those po rts where the switch regist ers that multicast tr af fi c as [...]

  • Page 336

    15-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 15 Configuring QoS Configuring QoS Rate Limiting Rate limiting pro vides control o v er the data traf f ic transmitted or recei ved on an interf ace.The Class-Based Policing feature performs the follo w ing functions: • Limits the input or output t [...]

  • Page 337

    15-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 15 Configuring QoS Configuri ng QoS Figur e 15-4 Radio Access Categ or ies Pag e W irel ess clients using TCLAS and TSPEC can request a class of serv ice through an ADDTS (add T raff ic Stream Request) sent to the access point be fore th e client init[...]

  • Page 338

    15-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 15 Configuring QoS Configuring QoS Optimized Voice Settings Using the Admi ssion Control check bo xes, you can cont rol client use of the acc ess categories. When you enable admission control for an acce ss category , clients associated to the access [...]

  • Page 339

    15-15 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 15 Configuring QoS Configuri ng QoS Follo w these steps to enable admission control on an SSID: Step 1 Open the SSID Manager page. Step 2 Select an SSID. Step 3 Under General Settings , select Enable in the Call Admission Contr ol fie l d . Troublesho[...]

  • Page 340

    15-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 15 Configuring QoS Configuring QoS – If Low Latency is selected, you can configure the amou nt of retries that the A P should u se before discarding the current pack et and sending the nex t one. For l ow latency traf f ic, skipping a packet is usua[...]

  • Page 341

    CH A P T E R 16-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 16 Configuring Filters This chapter describe s how to configure and manage MA C address, IP , and EtherT ype filters on the access point using the we b-bro wser interface. Th is chapter contains the follo wing sections: • Understanding Filters, [...]

  • Page 342

    16-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 16 Configuring Filters Understanding Filters Understanding Filters Protocol filters (IP protocol , IP port, and EtherT ype ) prev ent or allow the use of specific protocol s through the acc ess point’ s Ethernet and rad io ports. Y ou c an set up ind[...]

  • Page 343

    16-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Browser Interface Configuring Filters Using the Web-Browser Interface This section descri bes ho w to conf igure and enab le f ilters using the web-bro wser interface. Y ou complet e two steps to[...]

  • Page 344

    16-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Br owse r Interface Follo w this lin k path to reach the Address Filters page: 1. Click Services in the page na vigat ion bar . 2. In the Services page list, click Filters . 3. On the Apply Filte[...]

  • Page 345

    16-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Browser Interface Figur e 16-2 Apply Filters P ag e Step 12 Select the f ilter number from one of the MA C drop-down lists. Y ou can apply the f ilter to either or bot h the Ethernet and radio p [...]

  • Page 346

    16-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Br owse r Interface The follo wing example applies the MA C address access li st 701 created above to the Radio 0 interface, in the inbound direct ion. Ho we ver , no VLAN was creat ed on the int[...]

  • Page 347

    16-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Browser Interface Step 3 Click Advanced Security to bro wse to the Adv anced Security: MA C Address Authentication page. Figure 16-4 sho ws the MA C Addre ss Authentication page. Figur e 16-4 Adv[...]

  • Page 348

    16-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Br owse r Interface Step 1 Crea ting a MA C address access-list using the command access -list number-700-799. Step 2 Us e the global configuration command dott11 association mac-li st list-numbe[...]

  • Page 349

    16-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Browser Interface Determining the source of MAC Authentication T o def ine the source of MA C address verif ication f or SSID MA C authenticat ion, go to Security > Advanced Security > MA C[...]

  • Page 350

    16-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Br owse r Interface Using the AP internal RADIUS server for MAC address auth entication If you want t o use a list of MA C ad dresses defin ed in the AP internal RADIUS ser ver page, go t o Secu[...]

  • Page 351

    16-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Browser Interface In the Corporate Servers secti on, you can add a ne w serv er for your AP . F or this: Step 1 Ente r the AP’ s IP addre ss in the Server fi e l d Step 2 Enter the same Shared[...]

  • Page 352

    16-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Br owse r Interface Creating a Time-Based ACL T ime-based A C Ls are A CLs that can be enabled or disabled for a specific period of time. This capabili ty provid es robust ness and the flexib il[...]

  • Page 353

    16-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Browser Interface ACL Logging A CL logging i s not supported on the bridging interf aces of AP platforms. When applied on brid ging interface, it wi ll work as if conf igured without “log” o[...]

  • Page 354

    16-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Br owse r Interface Creating an IP Filter Follo w these steps to create an IP f ilter: Step 1 Follow th e link path to the IP Filters page. Step 2 If you are crea ting a new f ilter , make sure [...]

  • Page 355

    16-15 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Browser Interface Step 15 When the filter is comp lete, click A pply . The f ilter is sa v ed on the access point, b ut it is not en abled until you apply it on the Appl y Filters pa ge. Step 16[...]

  • Page 356

    16-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Br owse r Interface Figur e 16-8 EtherT ype Filt ers P ag e Follo w th is link path to reach the EtherT ype Filters page: 1. Click Services in the page na vigat ion bar . 2. In the Services page[...]

  • Page 357

    16-17 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Browser Interface Step 8 Select Fo r w a r d A ll or Block All from the Defa ult Action menu. The f ilter’ s defaul t action must be the opposite of the actio n for at least one of th e Ethert[...]

  • Page 358

    16-18 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 16 Configuring Filters Configuring Filters Using the Web-Br owse r Interface[...]

  • Page 359

    CH A P T E R 17-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 17 Configuring CDP This chapter describes ho w to conf igure Cisco D iscov ery Protocol (CDP) on you r access point. Note For complete syntax and usage in formation f or the commands used in this chapter, refer to the Cisco Air onet IOS Command Re[...]

  • Page 360

    17-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 17 Configur ing CDP Understanding CDP Understanding CDP Cisco Discov ery Protoc ol (CDP) is a de vice-disco v ery pro tocol that runs on all Cisco networ k equipment. Each de vice sends identi fying messages to a multicast address, and e ach de vice mo[...]

  • Page 361

    17-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 17 Configuring CDP Configuring CDP Use the no form of the CDP commands to return to the def ault settings. This exampl e sho ws ho w to conf igur e and v erify CDP characteristics: AP# configure terminal AP(config)# cdp holdtime 120 AP(config)# cdp tim[...]

  • Page 362

    17-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 17 Configur ing CDP Configuring CDP This e xample sho ws how to enable CD P . AP# configure terminal AP(config)# cdp run AP(config)# end Disabling and Enabling CDP on an Interface CDP is enabled by def ault on all supported in terfaces to send and r ec[...]

  • Page 363

    17-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 17 Configuring CDP Monitori ng and Maintaining CDP Monitoring and Maintaining CDP T o monitor and mai ntain CDP on your de vice, perform o ne or more of these tasks, be ginning in pri vile ged EXEC mode. Belo w are si x exampl es of output from t he CD[...]

  • Page 364

    17-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 17 Configur ing CDP Monitoring and Maintaining CDP Protocol Hello: OUI=0x00000C, Protocol ID=0x0112; payload len=27, value=0000000 0FFFFFFFF010221FF00000000000000024B293A00FF0000 VTP Management Domain: '' Duplex: full ------------------------[...]

  • Page 365

    17-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 17 Configuring CDP Enabling CDP Logging GigabitEthernet0/8 is up, line protocol is down Encapsulation ARPA Sending CDP packets every 60 seconds Holdtime is 180 seconds AP# show cdp neighbor Capability Codes: R - Router, T - Trans Bridge, B - Source Rou[...]

  • Page 366

    17-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 17 Configur ing CDP Enabling CDP Logging[...]

  • Page 367

    CH A P T E R 18-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 18 Configuring SNMP This chapter describe s how to configure the Simple Network Managemen t Protocol (SNM P) on your access point. Note For complete sy ntax and usage information for th e command s used in this chapter , refer to the Cisco IOS Com[...]

  • Page 368

    18-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 18 Configu ring SNMP Understanding SNMP Understanding SNMP SNMP is an appli cation-layer protocol that p r ovides a message format for communication between SNMP manage rs and agents. The SN MP manager ca n be part of a net work management system (NMS)[...]

  • Page 369

    18-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 18 Configuring SNMP Understanding SNMP T able 18-1 lists the SNMP v ersions and security le vels supported on access points. SNMP Manager Functions The SNMP manager uses information in the MIB to perform the oper ations described in T able 18-2 . T abl[...]

  • Page 370

    18-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 18 Configu ring SNMP Understanding SNMP SNMP Agent Functions The SNMP agent responds to SNMP manager request s as follo ws: • Get a MIB variable—The SNM P agent b egins this func tion in r esponse to a request f rom the NMS. The agent retriev es th[...]

  • Page 371

    18-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 18 Configuring SNMP Configuring SNMP Figur e 18-1 SNMP Networ k For information on supported MIBs and ho w to access them, see Appendix B, “Supported MIBs. ” Configuring SNMP This section descri bes ho w to conf igure SNMP on your access point. I t[...]

  • Page 372

    18-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 18 Configu ring SNMP Configuring SNMP Enabling the SNMP Agent No specif ic CLI command exists to enable SNMP . The f irst snmp-server glo bal conf iguration command that you enter enab les the supported v ersions of SNMP . Y ou can also enable SNMP on [...]

  • Page 373

    18-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 18 Configuring SNMP Configuring SNMP Beginni ng in pri vile ged EXEC mode, follo w these steps t o config ure a community string on th e access point: Command Purpose Step 1 configur e terminal Enter global co nfiguration mode. Step 2 snmp-server commu[...]

  • Page 374

    18-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 18 Configu ring SNMP Configuring SNMP T o disable access fo r an SNMP community , set the community st ring for that commun ity to the null string (do not enter a v alue for th e community string). T o remove a sp ecific commu nity string, use the no s[...]

  • Page 375

    18-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 18 Configuring SNMP Configuring SNMP Access points running this Cisco IOS release can have an unli mited number of trap managers. Community strings can be an y length. T able 18-4 describes the supported access point tr aps (notif ication types). Y ou [...]

  • Page 376

    18-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 18 Configu ring SNMP Configuring SNMP T o remove the specified host from re ceiving traps, use th e no snmp-server host host global confi guration command. T o disable a specif ic trap type, use the no snmp-server enable traps notif ication-t ypes glo[...]

  • Page 377

    18-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 18 Configuring SNMP Configuring SNMP Using the snmp-server view Command In global conf iguration mod e, use the snmp-server view command to access Stan dard IEEE 802.11 MIB objects through IEEE view and the dot11 read-write community string. This exam[...]

  • Page 378

    18-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 18 Configu ring SNMP Displaying SNMP Status This example sho ws how to allo w read-only access for all objects to members of access list 4 that use the comacces s community string. No other SNMP managers ha v e access to any o bjects. SNMP Authenticat[...]

  • Page 379

    CH A P T E R 19-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 19 Configuring Repeater and Standby Access Points and Workgroup Bridge Mode This chapter describes how to conf ig ure your a ccess point as a repeater , as a hot standby unit, or as a workgroup bridge. This chapter co ntains the following sections[...]

  • Page 380

    19-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Understanding Repeater Ac cess Points Understanding Repeater Access Points A repeater access point is not connected to the wired LAN ; it is placed within radio range of an [...]

  • Page 381

    19-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 19 Configuring Repeater a nd Standby Access Po ints and Workgro up Bridge Mode Configuring a Repeater Access Point Figur e 19-1 Access P oint as a Repea ter Configuring a Repeater Access Point This section pro vides instruct ions for setting u p an acc[...]

  • Page 382

    19-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Configuring a Re peater Access Point Default Configuration Access points are configured as root units by default. T able 19-1 sho ws the def ault v alues for settings that c[...]

  • Page 383

    19-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 19 Configuring Repeater a nd Standby Access Po ints and Workgro up Bridge Mode Configuring a Repeater Access Point Setting Up a Repeater Beginning in Pri vileged Exec mode, fol low th ese steps to conf igure an access point as a repeater: Command Purpo[...]

  • Page 384

    19-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Aligning Antennas The follo wing example sho ws how to set up a repeat er access point with three potential parents, designated 1 t o 3: AP# configure terminal AP(config)# i[...]

  • Page 385

    19-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 19 Configuring Repeater a nd Standby Access Po ints and Workgro up Bridge Mode Aligning Antennas Use the show dot11 antenna-alignment command to list the MA C addre sses and signal lev el for the last 10 de vices that responded to the probe. Verifying [...]

  • Page 386

    19-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Aligning Antennas Setting Up a Repeater As a EAP-FAST Client Y ou can set up a repeater access point to authenticat e to your network l ike other wire less client devices. A[...]

  • Page 387

    19-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 19 Configuring Repeater a nd Standby Access Po ints and Workgro up Bridge Mode Understanding Hot Standby Understanding Hot Standby Hot Standby mode designates an access point as a backup for another acces s point. The standby access point is placed nea[...]

  • Page 388

    19-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Configuring a Hot Standby Access Point Note The MA C address of th e monitored access point might ch ange if a BSSID on the monitored unit is added or deleted. If you use m[...]

  • Page 389

    19-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 19 Configuring Repeater a nd Standby Access Po ints and Workgro up Bridge Mode Configuring a Hot Standby Access Po int Beginni ng in Pri vileg ed Exec mode , follow these st eps to enable hot standby mode on an access point: Command Purpose Step 1 con[...]

  • Page 390

    19-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Configuring a Hot Standby Access Point After you enable standby mode, conf igure the settings that you recorded from the monitored access point to match on the standby acce[...]

  • Page 391

    19-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 19 Configuring Repeater a nd Standby Access Po ints and Workgro up Bridge Mode Understanding Workgroup Bridge Mode Use this command to check the stand by confi guration: show iapp standby-parms This command di splays the MAC address of the st andby ac[...]

  • Page 392

    19-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Understanding Wo rkgroup Brid ge Mode Figure 19-2 sho ws an access point in workgroup br idge mode. Figur e 1 9-2 Access P oint in W or k gr oup Br idg e Mode Treating Work[...]

  • Page 393

    19-15 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 19 Configuring Repeater a nd Standby Access Po ints and Workgro up Bridge Mode Understanding Workgroup Bridge Mode bridges, t hat can as sociat e to an access point or bridge. T o increase be yond 20 the number of w orkgroup bridges that can associate[...]

  • Page 394

    19-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Understanding Wo rkgroup Brid ge Mode Y ou can also conf igure the per iodicity of scans. When the connection con ditions deteriorate, the workgroup b ridge scans for a bet[...]

  • Page 395

    19-17 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 19 Configuring Repeater a nd Standby Access Po ints and Workgro up Bridge Mode Workgroup Bridge VLAN Tagging Configuring a Client VLAN If the de vices connected to the w orkgroup br idge’ s Ethernet port should all b e assigned to a particular VLAN,[...]

  • Page 396

    19-18 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Configuring Work group Bridge Mode Step 3 station-ro le workgr oup-bridge [universal m ac-addr ess ] Set the radio role to w orkgroup bridge. (Optional) When conf igured as[...]

  • Page 397

    19-19 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 19 Configuring Repeater a nd Standby Access Po ints and Workgro up Bridge Mode Configuring Workgroup Bridge Mode Step 6 infrastructure-ssid Designate the SSID as an infrastruc ture SSID. Note The workgroup b ridge must use an infrastr ucture SSID to a[...]

  • Page 398

    19-20 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Configuring Work group Bridge Mode This e xample sho ws ho w to configur e an access poin t as a w orkgroup bridge. In this example, the workgroup bri dge uses the conf igu[...]

  • Page 399

    19-21 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 19 Configuring Repeater a nd Standby Access Po ints and Workgro up Bridge Mode Using Workgroup Bridges in a Lightweight Environment This example sho ws ho w to set up a workgroup bridge with the parent access points, designated 1 and 2: AP(config-if)#[...]

  • Page 400

    19-22 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Using Workgroup Bridge s in a Lightweight Environment Guidelines for Using Workgroup Br idges in a Lightweight Environment Follo w th ese guidelines for using w orkgroup br[...]

  • Page 401

    19-23 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 19 Configuring Repeater a nd Standby Access Po ints and Workgro up Bridge Mode Using Workgroup Bridges in a Lightweight Environment • When you delete a workgroup bridg e record from the controller , all of the workgroup bridge wired clients’ recor[...]

  • Page 402

    19-24 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 19 Configurin g Repeater and Stan dby Access Points and Workgroup Br idge Mode Using Workgroup Bridge s in a Lightweight Environment[...]

  • Page 403

    CH A P T E R 20-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 20 Managing Firmware and Configurations This chapter describ es how to manipulate the Flash fi le system, ho w to copy configuration f iles, and ho w to archiv e (upload and do wnload) software images. Note For complete sy ntax and usage informati[...]

  • Page 404

    20-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with the Flash File System Displaying Available File Systems T o display t he av ailable f ile systems on your access point , use the show f ile systems pri vileged EXEC command as sho wn in this e xampl[...]

  • Page 405

    20-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with the Flash File System Setting the Default File System Y ou can specify the f ile system or directory that the system uses as the def ault f ile system by using the cd filesystem: pri vile ged EXEC co[...]

  • Page 406

    20-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with the Flash File System Displaying Information About Files on a File System Y ou can vie w a list of the co ntents of a f ile system before mani pulating its contents. F or e xample, before copying a [...]

  • Page 407

    20-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with the Flash File System T o delete a directory with all i ts files and subdi rectories, use the delete /force /r ecursive filesystem :/ file - ur l privileged EXEC command. Use the /recursiv e ke yword[...]

  • Page 408

    20-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with the Flash File System Deleting Files When you no longer need a file on a Flash memory de vice, you can perman ently delete it. T o delete a file or directory from a speci fied Flash de vice, use the[...]

  • Page 409

    20-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with the Flash File System Displaying the Contents of a tar File T o display t he contents of a tar f ile on the screen, use this pri vileged EXEC command: archiv e tar /table sour ce-url For sour ce-url [...]

  • Page 410

    20-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Configuration Files Extracting a tar File T o extract a tar file into a directo ry on the Flash file system, use this pr ivile ged EXEC com mand: archiv e tar /xtract sour ce-url flash:/ fil e - u r[...]

  • Page 411

    20-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Configuration File s Yo u c a n c o p y ( dow nload ) configuratio n files fro m a TFTP , FTP , or RCP serv er to the running configuration of the access point for v arious reasons: • T o restore a[...]

  • Page 412

    20-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Configuration Files config uration is used. Ho we ver , some commands in the existin g conf iguration migh t not be replaced or nega ted. In this case, the resulting conf iguration file is a mixt u[...]

  • Page 413

    20-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Configuration File s Preparing to Download or Upload a Configuration File by Using TFTP Before you be gin do wnloading or up loading a conf igurat ion f ile by using TFTP , perform these tasks: • [...]

  • Page 414

    20-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Configuration Files Use one of these privile ged EXEC commands: • copy system:running-config tftp : [[[ // location ] / dir ectory ] / f ilename ] • copy n vram:startup-conf ig tftp: [[[ // loc[...]

  • Page 415

    20-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Configuration File s Preparing to Download or Upload a Configuration File by Using FTP Before you be gin do wnloading o r uploading a conf igurat ion f ile by using FTP , perform th ese tasks: • E[...]

  • Page 416

    20-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Configuration Files Connected to 172.16.101.101 Loading 1112 byte file host1-confg:![OK] ap# %SYS-5-CONFIG: Configured from host1-config by ftp from 172.16.101.101 This exampl e sho ws how to speci[...]

  • Page 417

    20-15 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Configuration File s Building configuration...[OK] Connected to 172.16.101.101 ap# This example sh ow s how to store a startup conf iguration f ile on a serv er by using FTP to cop y the file: ap# c[...]

  • Page 418

    20-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Configuration Files Preparing to Download or Upload a Configuration File by Using RCP Before you be gin do wnloading o r uploading a conf igurat ion f ile by using RCP , perform th ese tasks: • E[...]

  • Page 419

    20-17 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Configuration File s This example sho ws ho w to cop y a conf iguration f ile named host1-confg from the netadmin1 directory on the remote se rver with an IP address of 172 .16.101.101 an d load and[...]

  • Page 420

    20-18 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Software Image s This exampl e sho ws how to copy the run ning conf iguration f ile named ap2-confg to the netadmin1 directory on the remote host with an IP address of 172.16.101.101: ap# copy syst[...]

  • Page 421

    20-19 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Software Images The protocol you use d epends on which type of serv er you are using. Th e FTP and RCP transport mechanisms provide faster performance and more reliable deli very of data than TFTP .[...]

  • Page 422

    20-20 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Software Image s The info.ver f ile is always at the end of the tar file and contains the same informatio n as the info f ile. Because it is the last f ile in the tar f ile, its e xistence means th[...]

  • Page 423

    20-21 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Software Images Note T o a v oid an unsuccessful do wnl oad, use the archi ve do wnload-sw /safe command , which do wnloads the image fi rst and does not delete the current runnin g version un til t[...]

  • Page 424

    20-22 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Software Image s Note If the Flash de vice has suf f icient space to hold tw o images and you w ant to o verwrite one of these images with the same versi on, you must specify the /ov erwrite optio [...]

  • Page 425

    20-23 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Software Images Y ou download an access point image f ile from a se rver to upgrade the access point software. Y ou can ov erwrite th e current i mage with th e ne w one or k eep the current image a[...]

  • Page 426

    20-24 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Software Image s config uration command. This ne w name wil l be used during all archi v e operations. The ne w username is stored in NVR AM. If you are acce ssing the access point through a T elne[...]

  • Page 427

    20-25 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Software Images Note T o a v oid an unsuccessful do wnl oad, use the archi ve do wnload-sw /safe command , which do wnloads the image fi rst and does not delete the current runnin g version un til t[...]

  • Page 428

    20-26 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Software Image s If you specify the /lea ve-old-sw , the existing f iles are not remo v ed. If there is not enough space to instal l the ne w image and k eep the r unning image, the do wn load proc[...]

  • Page 429

    20-27 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Software Images The archiv e upload-sw command b uilds an image f ile on the serv er by uploading th ese fi les in order: info, the Cisco IOS image, th e HTML files, and i nfo.ver . After these f il[...]

  • Page 430

    20-28 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Software Image s RCP requires a client to send a remote usern ame on each RCP request to a server . When you cop y an image from the access point to a server by using RCP , the Cisco IO S software [...]

  • Page 431

    20-29 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Software Images Downloading an Image File by Using RCP Y ou can download a ne w image fi le an d replace or keep the current image. Caution For the do wnload and upload algo rithms to op erat e prop[...]

  • Page 432

    20-30 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Software Image s Note T o a v oid an unsuccessful do wnl oad, use the archi ve do wnload-sw /safe command , which do wnloads the image fi rst and does not delete the current runnin g version un til[...]

  • Page 433

    20-31 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Software Images Note If the Flash de vice has suf f icient space to hold tw o images and you w ant to o verwrite one of these images with the same versi on, you must specify the /ov erwrite optio n.[...]

  • Page 434

    20-32 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Software Image s The archi ve upload-sw pri vile ged EXEC command buil ds an image f ile on the serv er by uploading these files in order: info, the Cisco IOS i mage, the HTML files, and info.ver .[...]

  • Page 435

    20-33 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 20 Managing Firmware and Configurations Working with Software Images Browser TFTP Interface The TFTP interface allo ws you to use a TFTP se rver on a network de vice to load the access point image file. F ollo w the instruct ions belo w to use a TFTP [...]

  • Page 436

    20-34 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 20 Mana ging Firmware and Configurations Working with Software Image s[...]

  • Page 437

    CH A P T E R 21-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-29225-01 21 Configuring L2TPv3 Over UDP/IP Layer 2 T unneling Protocol (L2TPv3), is a tunneling protocol that enables tunnel ing of Layer 2 packets ov er IP core networks. L2TPv3 tunnel is a cont rol connection between th e end points. One L2TPv3 tu nnel c[...]

  • Page 438

    21-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01 Chapter 21 Config uring L2T Pv3 Over UDP/IP Configuring L2TP Class Note The bridge id on interf aces with same vlan id must be the same. The follo wing are not suppo rted: • T unnel establishment using IPv6 ad dress • SNMP and GUI conf iguration • Multip[...]

  • Page 439

    21-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-29225-01 Chapter 21 Configuring L2TPv3 Over UDP/IP Configuring Pseudow ire Class Note Multiple l2tp classes can be configured. Examples ap1# configure terminal ap1(config)# l2tp-class myl2tpclass ap1(config-l2tp-class)# hostname myhost1 ap1(config-l2tp-class)# hello 15[...]

  • Page 440

    21-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01 Chapter 21 Config uring L2T Pv3 Over UDP/IP Relationship betwee n L2TP Class and Pseudowire Cla ss Relationship between L2TP Class and Pseudowire Class Multiple pseudo wire classes can be conf igured. A ps eudowi re class can configured with an y one of the av[...]

  • Page 441

    21-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-29225-01 Chapter 21 Configuring L2TPv3 Over UDP/IP Mapping SSID to the T unnel/Xconnect This interface allo ws access to an AP through the tunnel. This interface is associated with a VDT interface with same inde x. T raffic fro m this interf ace is tunn eled though a t[...]

  • Page 442

    21-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-29225-01 Chapter 21 Config uring L2T Pv3 Over UDP/IP Configuring TCP mss adjust Configuring TCP mss adjust T o conf igure TCP mss adjust fo r tunnel clients u se the dot11 l2tp tcp mss tcp mss value command in the conf iguration mode. dot11 l2tp tcp mss tcp mss value E[...]

  • Page 443

    CH A P T E R 22-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 22 Configuring System Message Logging This chapter describes how to conf igure sy stem message logging on your acces s point. Note For complete sy ntax and usage information for th e command s used in this chapter , refer to the Cisco IOS Confi gu[...]

  • Page 444

    22-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 22 Config uri ng System Message Logg ing Understanding System Message Lo gging Understanding System Message Logging By default, access points send the outpu t from system messages and deb ug pri vile ged EXEC commands to a logging process. The l ogging[...]

  • Page 445

    22-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 22 Configuring System Message Logging Configuring System Message Lo gging This example show s a partial access point system message : *Mar 1 00:00:29.219: %LINK-6-UPDOWN: Interface GigabitEthernet0, changed state to up *Mar 1 00:00:29.335: Starting Eth[...]

  • Page 446

    22-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 22 Config uri ng System Message Logg ing Configuring System Message Logging Disabling and Enabling Message Logging Message logging is enabled by default. It must be en abled to send messages to any d estination other than the console. When enabled, log[...]

  • Page 447

    22-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 22 Configuring System Message Logging Configuring System Message Lo gging Setting the Message Display Destination Device If message logging is en abled, you ca n send messages to specific locati ons in addition to the cons ole. Beginni ng in pri vile g[...]

  • Page 448

    22-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 22 Config uri ng System Message Logg ing Configuring System Message Logging Enabling and Disabling Timestamps on Log Messages By default, log messag es are not timestamped. Beginni ng in pri vile ged EXEC mode, follo w these steps to enable ti mestampi[...]

  • Page 449

    22-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 22 Configuring System Message Logging Configuring System Message Lo gging T o disable sequence numbers, use the no service sequence-numbers global confi guration command. This example sh ow s part of a logging display with sequenc e numbers enabled: 00[...]

  • Page 450

    22-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 22 Config uri ng System Message Logg ing Configuring System Message Logging T able 22-3 describes the level keyw ords. It also lists the co rresponding sy slog definitions from the most sev ere lev el to the leas t sev ere level. The software generates[...]

  • Page 451

    22-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 22 Configuring System Message Logging Configuring System Message Lo gging Beginni ng in pri vile ged EXEC mode, follo w these steps to change the l e vel and h istory table size defaults: When the history table is fu ll (it contains the maximum number [...]

  • Page 452

    22-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 22 Config uri ng System Message Logg ing Configuring System Message Logging Configuring the System Logging Facility When sending system log messages to an e xternal de vi ce, you can cause the access point to identify its messages as originating from [...]

  • Page 453

    [...]

  • Page 454

    22-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 22 Config uri ng System Message Logg ing Displaying the Logging Configuration[...]

  • Page 455

    CH A P T E R 23-1 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 23 Troubleshooting This chapter pro vides trou bleshooting procedures for b asic problems with the wirel ess dev ice. For the most up-to-date, detail ed troubleshooting i nformation, refer to the Cisco T A C website at the follo wing URL (select T[...]

  • Page 456

    23-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 23 Troublesho oting Checking the LED Indica tors Checking the LED Indicators If your wireless de vice is not communicating, fir st check the LED indicators on th e de vice to quickly assess the device’ s status. The LED indicator setup is not the sam[...]

  • Page 457

    23-3 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 23 Troubleshooting Checking Basic Setting s Note An 802.3af compliant switch (Cisco o r non-Cisco) is capable of sup plying suf f icient po wer for full operation. Note When an AP 2700 or AP 3700 is runni ng in lo w po wer mode with PoE 802.3af po wer [...]

  • Page 458

    23-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 23 Troublesho oting Resetting to the Defa ult Conf iguration SSID CONFIG W ARNING: [SSID]: If radio client s are using EAP-F AST , A UTH OPEN with EAP should also be configured. If you are using the GUI, this warning message appears: WA R N I N G : “[...]

  • Page 459

    23-5 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 23 Troubleshooting Resetting to the Default Configuration Using the Web Browser Interface Follo w th ese steps to delete the current con figurati on and return al l wireless de vice settings to the f actory defaults usin g the web bro wser interface: S[...]

  • Page 460

    23-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 23 Troublesho oting Reloading the A ccess Point Image ...done initializing Flash. Step 5 Us e the dir flash: command to display the contents of Flash and f ind the conf ig.txt config uration f ile. ap: dir flash: Directory of flash:/ 3 .rwx 223 <dat[...]

  • Page 461

    23-7 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 23 Troubleshooting Reloading the Access Point Image Using the MODE button Y ou can use the MODE b utton on all access points to relo ad the access point image f ile from an acti ve T ri vial File T ransfer Protocol (TFTP) server on your netw ork or on [...]

  • Page 462

    23-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 23 Troublesho oting Reloading the A ccess Point Image Browser HTTP Interface The HTTP interface enables you to bro wse to the wireless de vice image f ile on your PC an d do wnload the image to the wireless de vice. Follo w the instructions belo w to u[...]

  • Page 463

    23-9 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 23 Troubleshooting Reloading the Access Point Image Using the CLI Follo w the steps b elo w to reload the wireless d e vice image using the CLI. When the wireless de vice begins to boot, you interrupt the bo ot process and use boot loader comm ands to [...]

  • Page 464

    23-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 23 Troublesho oting Reloading the A ccess Point Image Step 7 When the display becomes full, t he CLI pauses and d isplays --MORE-- . Press the spacebar to continue. extracting info (286 bytes) ap3g2-k9w7-mx.152-4.JB5/ (directory) ap3g2-k9w7-mx.152-4.J[...]

  • Page 465

    23-11 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 23 Troubleshooting Image Recovery on the 1520 Access Point IP_ADDR=192.168.133.160 NETMASK=255.255.255.0 Step 10 Enter the boot command to reboot the wireless device. When the wireless device reboots, it loads the new image. ap: boot Obtaining the Acc[...]

  • Page 466

    23-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 23 Troublesho oting Image Recovery on the 1520 Access Point T o perform image reco very on the 1520 access point, follo w these st eps: Step 1 With the access point po wered off, connect an RJ45 co nsole cable to the console port (). The console port [...]

  • Page 467

    23-13 Cisco IOS Software Configuratio n Guide for Cisco Aironet Ac cess Points OL-30644-01 Chapter 23 Troubleshooting Image Recovery on the 1520 Access Point Note If the ENABLE_BREAK=no envir onmental variable is set, yo u will not be able to escape to the bootloader . Step 5 Cable the 1520 access point’ s LAN port (“PoE In”) to a TFTP server[...]

  • Page 468

    23-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Chapter 23 Troublesho oting Image Recovery on the 1520 Access Point[...]

  • Page 469

    A-1 Cisco IOS Software Configuration Guide for Cisco Aironet Access Points OL-30644-01 APPENDIX A Protocol Filters The tables in this appendix list some of the prot ocol s that you can f ilter on th e access point. The tables include: • T able A-1, EtherT ype Protocols • T able A-2, IP Protocol s • T able A-3, IP Port Prot ocols In each table[...]

  • Page 470

    A-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix A Protocol Filters T able A -1 EtherT ype Prot ocols Protocol Additional Identifier ISO Designator ARP — 0x0806 RARP — 0x8035 IP — 0x0800 Berkele y T railer Ne gotiation — 0x1000 LAN T est — 0x0708 X.25 Le vel3 X.25 0x0805 Ban yan — 0x0B AD[...]

  • Page 471

    A-3 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix A Protocol Filters T able A -2 IP Protocols Protocol Additional Identifier ISO Designator dummy — 0 Internet Control Message Protocol ICMP 1 Internet Group Management Prot ocol IGMP 2 T ransmission Control Protocol TCP 6 Exterior Gate way Prot ocol EG[...]

  • Page 472

    A-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix A Protocol Filters T able A -3 IP P or t Pr ot ocols Protocol Additional Identifier ISO Designator TCP port service multiple x er tcpmux 1 echo — 7 discard (9) — 9 systat (11) — 11 daytime (13) — 13 netstat (15) — 15 Quote of the Day qotd quo[...]

  • Page 473

    A-5 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix A Protocol Filters TSAP iso-t sap 102 CSO Name Serv er cso-ns csnet-ns 105 Remote T elnet rtelnet 107 Postoff ice v2 POP2 POP v2 109 Postoff ice v3 POP3 POP v3 110 Sun RPC sunrpc 111 tap ident authentication auth 113 sftp — 115 uucp-path — 117 Netwo[...]

  • Page 474

    A-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix A Protocol Filters SNMP Unix Multiple xer s mux 199 AppleT alk Routi ng at-rtmp 201 AppleT alk name bindin g at- nbp 202 AppleT alk echo at-echo 204 AppleT alk Zone Inform ation at-zis 206 NISO Z39.50 da tabase z3950 210 IPX — 213 Interactiv e Mail A[...]

  • Page 475

    B-1 Cisco IOS Software Configuration Guide for Cisco Aironet Access Points OL-30644-01 APPENDIX B Supported MIBs This appendi x lists the Simple Network Manag ement Protocol (SNMP) Management Information Bases (MIBs) that the access point su pports for this soft w are release. The Cisco IOS SNMP agent supports SNMPv1, SNMPv2, and SNMPv3. This ap pe[...]

  • Page 476

    B-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix B Supported MIBs Using FTP to Acce ss the MIB Files • CISCO-MEMOR Y -POOL-MIB • CISCO-PR OCESS-MIB • CISCO-PR ODUCTS-MIB • CISCO-SMI-MIB • CISCO-TC-MIB • CISCO-SYSLOG-MIB • CISCO-WDS-INFO-MIB • ENTITY -MIB • IF-MIB • OLD-CISCO-CHASS[...]

  • Page 477

    C-1 Cisco IOS Software Configuration Guide for Cisco Aironet Access Points OL-30644-01 APPENDIX C Error and Event Messages This appendix lists t he CLI error and e vent message s. The appendix contains the follo wing sections: • Con v entions, page C-2 • Software Auto Upgrade Message s, page C-3 • Association Man agement Messages, page C-5 ?[...]

  • Page 478

    C-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es Conventions Conventions System error messages are displa yed in the fo rmat shown in Ta b l e C - 1 . T able C-1 System Er ror Messag e F or mat Message Component Description Example Error identif ier A string cate gorizing [...]

  • Page 479

    C-3 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages Software Auto Upgrade Message s Software Auto Upgrade Messages Error Message SW-AUTO-UPGRADE-2-FATAL_FAILURE: “At tempt to upgrade softw are failed, software on flash may be deleted. Pl ease copy software into flash. Explana[...]

  • Page 480

    C-4 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es Software Auto Upgrade Messages Error Message AUTO-INSTALL-4-IP_ADDRESS_DH CP: “The radio is operating in automati c install mode and has set ip address dhcp.” Explanation The radio is o perating in automati c install m o[...]

  • Page 481

    C-5 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages Association Management Message s Association Management Messages Error Message DOT11-3-BADSTATE: “%s %s -> %s.” Explanation 802.11 associ ation and ma nagement use s a ta ble-dri v en state machin e to keep track and tr[...]

  • Page 482

    C-6 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es Unzip Mess ages Error Message DOT11-4-DIVER_USED: Interf ace $s, Mcs rates 8-15 disabled due to only one transmit or recieve antenna enab led Explanation These rates require that at least 2 rece iv e and transmit antennas be[...]

  • Page 483

    C-7 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages System Log Messages System Log Messages Error Message %DOT11-4-LOADING_RADIO: Interface [ chars], loading the radio firmware ([chars]) Explanation The radio has been stopped to load ne w firmw are. Recommended Action None. Err[...]

  • Page 484

    C-8 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es 802.11 Subsystem Messages 802.11 Subsystem Messages Error Message DOT11-6-FREQ_USED: “Interfa ce %s, frequency %d selected.” Explanation After scanning for an unused frequency , th e indicated interface selected the disp[...]

  • Page 485

    C-9 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages 802.11 Subsystem Messages Error Message DOT11-3-TX_PWR_OUT_OF_RANGE : “Interface %s Radio transmit power out of range.” Explanation The transmitter po wer le vel is outside the normal range on the indicated radio interf ac[...]

  • Page 486

    C-10 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es 802.11 Subsystem Messages Error Message DOT11-6-DFS_SCAN_START: “DF S: Scanning frequency %d MHz for %d seconds.” Explanation The de vice has beg un its DFS scanning process. Recommended Action None. Error Message DOT11[...]

  • Page 487

    C-11 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages 802.11 Subsystem Messages Error Message DOT114-NO_MBSSID_BACKUP_VLA N: “Backup VLANs cannot be configured if MBSSID is not enabled. %s not starte d. Explanation T o enable a backup VLAN, MBSSID mod e should be conf igured. [...]

  • Page 488

    C-12 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es 802.11 Subsystem Messages Error Message DOT11-2-UPLINK_FAILED: “Upl ink to parent failed: %s.” Explanation The connection to the p arent access point fail ed for the displayed reason . The uplink will stop its connectio[...]

  • Page 489

    C-13 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages 802.11 Subsystem Messages Error Message DOT11-4-MAXRETRIES: “Packet to client %e reached max retries, removing the client.” Explanation The maximum packet send retry limit has been reached a nd th e client is being remove[...]

  • Page 490

    C-14 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es 802.11 Subsystem Messages Error Message DOT11-4-RADIO_NO_FREQ: “Int erface &s, all frequencies have been blocked, interface not started.” Explanation The frequencies set for operation are in valid an d a channel sca[...]

  • Page 491

    C-15 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages 802.11 Subsystem Messages Error Message DOT11-4-FLASHING_RADIO: “Interfa ce %s, flashing radio firmware (%s).” Explanation The indicated interface radio has bee n stop ped to load the indicated new firmw are. Recommended [...]

  • Page 492

    C-16 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es 802.11 Subsystem Messages Error Message DOT11-4-UPLINK_LINK_DOWN: “ Interface %s, parent lost: %s.” Explanation The connection to the parent ac cess point on the indicated interf ace was lost for the reason indicated. T[...]

  • Page 493

    C-17 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages 802.11 Subsystem Messages Error Message DOT11-6-ANTENNA_GAIN: “Inte rface %s, antenna position/gain changed, adjusting transmitter power.” Explanation The antenna gain has chan ged so the list of allo wed po wer le v els [...]

  • Page 494

    C-18 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es 802.11 Subsystem Messages Error Message DOT11-4-CKIP_MIC_FAILURE: “CKIP MIC failure was detect ed on a packet (Digest 0x%x) received from %e).” Explanation CKIP MIC failure was detected on a frame. A failure of the CKIP[...]

  • Page 495

    C-19 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages 802.11 Subsystem Messages Error Message DOT11-4-TKIP_REPLAY: “TKIP TSC replay was detected on a packet (TSC 0x%ssx received from %e).” Explanation TKIP TSC replay was detected on a frame. A replay of the TKIP TSC in a rec[...]

  • Page 496

    C-20 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es 802.11 Subsystem Messages Error Message SOAP_FIPS-2-INIT_FAILURE: “ SOAP FIPS initialization failure: %s.” Explanation SO AP FIPS initiali zation failure. Recommended Action None. Error Message SOAP_FIPS-4-PROC_FAILURE:[...]

  • Page 497

    C-21 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages Inter-Access Point Protocol Messages Error Message DOT11-6-MCAST_DISCARD: “%s mode multicast packets are discarded in %s multicast mode.” Explanation The access point conf igured as a w orkgroup b ridge and drops infrastr[...]

  • Page 498

    C-22 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es Local Authenticator Messages Error Message RADSRV-4-NAS_KEYMIS: NAS sh ared key mismatch. Explanation The local RADIUS server receiv ed an authen tication request b ut the message signature indicates that th e shared ke y t[...]

  • Page 499

    [...]

  • Page 500

    C-24 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es WDS Messages WDS Messages Error Message WLCCP-WDS-6-REPEATER_STOP: WLCCP WDS on Repe ater unsupported, WDS is disabled. Explanation Repeater access points do not support WDS. Recommended Action None. Error Message WLCCP-WDS[...]

  • Page 501

    C-25 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages Mini IOS Messages Error Message WLCCP-NM-6-WNM_LINK_UP: Lin k to WNM is up Explanation The network manager is n ow r esponding to k eep-acti ve messages. Recommended Action None. Error Message WLCCP-NM-6-RESET: Resetting WLCC[...]

  • Page 502

    C-26 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es Access Point/Bridge Messages Access Point/Bridge Messages Error Message APBR-4-SEND_PCKT_FAILED: Failed to Send Packet on port ifDescr (error= errornum)errornum: status er ror number HASH(0x2096974) Explanation The access p[...]

  • Page 503

    C-27 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages LWAPP Error Messages LWAPP Error Messages Error Message LWAPP-3-CDP: Failure sendin g CDP Update to Controller. Reason “s” Explanation Could not send access point CDP updat e to controller Recommended Action None. Error M[...]

  • Page 504

    C-28 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es Sensor Messages Sensor Messages Error Message SENSOR-3-TEMP_CRITICAL: Sys tem sensor “d” has exceeded CRITCAL temperature thresholds Explanation One of the measured en vironmental test points exceeds the e xtreme th res[...]

  • Page 505

    C-29 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages SNMP Error Messages Error Message SENSOR-3-VOLT_NORMAL: Syste m sensor “d”(“d”) is now operating under NORMAL voltage Explanation One of the measured en vironmental test points is under normal operating voltage. Recom[...]

  • Page 506

    C-30 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es SSH Error Mess ages Error Message SNMP-4-NOENGINEIDV6: Remote snmpEngineID f or Unrecognized format ‘ %P’ not found when creating user: “s” Explanation An attempt to create a user f ailed.This is likely b ecause the[...]

  • Page 507

    C-31 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 Appendix C Error and Event Messages SSH Error Messages Error Message SSH-5-SSH_CLOSE: SSH Sessio n from “%s”(tty = “%d”) for user ’”%s”’ using crypto cipher ’”%s”’ closed Explanation The SSH Session closure information Recommended Action[...]

  • Page 508

    C-32 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 Appendix C Error and Event Messag es SSH Error Mess ages[...]

  • Page 509

    GL-1 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 GLOSSARY 802.11 The IEEE standard that specifies carrier sense media access control and physical layer specif ications for 1- and 2- megabi t-per -second (Mbps) wireless LANs operating in the 2. 4-GHz band. 802.11a The IEEE standard that specifies carrier sense[...]

  • Page 510

    Glossary GL-2 Cisco IOS Software Configuration Gu ide for Cisco Airo net Access Points OL-30644-01 beacon A wireless LAN packet that signals the av ailability and presence of the wireless de vice. Beacon packets are sent by access points and base stations; howe ver , client radio ca rds send beaco ns when op erating in computer to computer (Ad Hoc)[...]

  • Page 511

    Glossar y GL-3 Cisco IOS Software Configuration Gu ide for Cisco Aironet Access Points OL-30644-01 dipole A type of low-gain (2.2-dBi ) antenna consisting of two (often i nternal) elements. domain n ame The text name th at refers to a grouping o f networks or netw ork resources based on org anization-type or geography; for e xample: name.com—comm[...]