Hybrid-Reap Groups And Backup Radius Servers; Hybrid-Reap Groups And Cckm - Cisco 2100 Series Configuration Manual

Wireless lan controller
Hide thumbs Also See for 2100 Series:
Table of Contents

Advertisement

Configuring Hybrid-REAP Groups
Figure 13-9

Hybrid-REAP Groups and Backup RADIUS Servers

You can configure the controller to allow a hybrid-REAP access point in standalone mode to perform
full 802.1X authentication to a backup RADIUS server. You can configure a primary backup RADIUS
server or both a primary and secondary backup RADIUS server. These servers are used only when the
hybrid-REAP access point is not connected to the controller.

Hybrid-REAP Groups and CCKM

Hybrid-REAP groups are required for CCKM fast roaming to work with hybrid-REAP access points.
CCKM fast roaming is achieved by caching a derivative of the master key from a full EAP authentication
so that a simple and secure key exchange can occur when a wireless client roams to a different access
point. This feature prevents the need to perform a full RADIUS EAP authentication as the client roams
from one access point to another. The hybrid-REAP access points need to obtain the CCKM cache
information for all the clients that might associate so they can process it quickly instead of sending it
back to the controller. If, for example, you have a controller with 300 access points and 100 clients that
might associate, sending the CCKM cache for all 100 clients is not practical. If you create a
hybrid-REAP group comprising a limited number of access points (for example, you create a group for
four access points in a remote office), the clients roam only among those four access points, and the
CCKM cache is distributed among those four access points only when the clients associate to one of
them.
CCKM fast roaming among hybrid-REAP and non-hybrid-REAP access points is not supported. Refer
Note
to the
Cisco Wireless LAN Controller Configuration Guide
13-16
Hybrid-REAP Group Deployment
Backup RADIUS
WAN link
802.1x
Branch
"WPA1 and WPA2" section on page 6-22
Chapter 13
DHCP server
server
VLAN 101
Local VLAN
Local switch
Trunk port
Trunk port
native VLAN 100
native VLAN 100
Hybrid-REAP Access Points
for information on configuring CCKM.
Configuring Hybrid REAPWireless Device Access
OL-17037-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

4400 series

Table of Contents