
5-24
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 5 Configuring Security Solutions
Configuring Local EAP
Figure 5-16 provides an example of a remote office using local EAP.
Figure 5-16 Local EAP Example
You can configure local EAP through either the GUI or the CLI.
Using the GUI to Configure Local EAP
Follow these steps to configure local EAP using the controller GUI.
Step 1 EAP-TLS, PEAPv0/MSCHAPv2, and PEAPv1/GTC use certificates for authentication, and EAP-FAST
uses either certificates or PACs. The controller is shipped with Cisco-installed device and Certificate
Authority (CA) certificates. However, if you wish to use your own vendor-specific certificates, they must
be imported on the controller. If you are configuring local EAP to use one of these EAP types, make sure
that the appropriate certificates and PACs (if you will use manual PAC provisioning) have been imported
on the controller. Refer to Chapter 8 for instructions on importing certificates and PACs.
Step 2 If you want the controller to retrieve user credentials from the local user database, make sure that you
have properly configured the local network users on the controller. See the “Configuring Local Network
Users” section on page 5-15 for instructions.
Step 3 If you want the controller to retrieve user credentials from an LDAP backend database, make sure that
you have properly configured an LDAP server on the controller. See the “Configuring LDAP” section on
page 5-19 for instructions.
IP
LDAP server
(optional)
Wireless LAN
controller
Cisco Aironet
Lightweight Access Point
Regional office
RADIUS server
WAN
232306
Commentaires sur ces manuels