Cisco 2100 Series Configuration Manual page 231

Wireless lan controller
Hide thumbs Also See for 2100 Series:
Table of Contents

Advertisement

Chapter 5
Configuring Security Solutions
Note
f.
If you chose EAP-FAST and want the device certificate on the controller to be used for
authentication, check the Local Certificate Required check box. If you want to use EAP-FAST
with PACs instead of certificates, leave this check box unchecked, which is the default setting.
Note
If you chose EAP-FAST and want the wireless clients to send their device certificates to the
g.
controller in order to authenticate, check the Client Certificate Required check box. If you want
to use EAP-FAST with PACs instead of certificates, leave this check box unchecked, which is the
default setting.
Note
h.
If you chose EAP-FAST with certificates, EAP-TLS, or PEAP, choose which certificates will be sent
to the client, the ones from Cisco or the ones from another Vendor, from the Certificate Issuer
drop-down box. The default setting is Cisco.
If you chose EAP-FAST with certificates or EAP-TLS and want the incoming certificate from the
i.
client to be validated against the CA certificates on the controller, check the Check Against CA
Certificates check box. The default setting is enabled.
If you chose EAP-FAST with certificates or EAP-TLS and want the common name (CN) in the
j.
incoming certificate to be validated against the CA certificates' CN on the controller, check the
Verify Certificate CN Identity check box. The default setting is disabled.
If you chose EAP-FAST with certificates or EAP-TLS and want the controller to verify that the
k.
incoming device certificate is still valid and has not expired, check the Check Certificate Date
Validity check box. The default setting is enabled.
Click Apply to commit your changes.
l.
Step 7
If you created an EAP-FAST profile, follow these steps to configure the EAP-FAST parameters:
a.
Click Security > Local EAP > EAP-FAST Parameters to open the EAP-FAST Method Parameters
page (see
OL-17037-01
If you check the PEAP check box, both PEAPv0/MSCHAPv2 or PEAPv1/GTC are enabled
on the controller.
This option applies only to EAP-FAST because device certificates are not used with LEAP
and are mandatory for EAP-TLS and PEAP.
This option applies only to EAP-FAST because client certificates are not used with LEAP
or PEAP and are mandatory for EAP-TLS.
Figure
5-26).
Cisco Wireless LAN Controller Configuration Guide
Configuring Local EAP
5-43

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

4400 series

Table of Contents