Extensible Authentication Protocol (EAP) Authentication Types 

802.1x Overview
It is a port access protocol for protecting networks via authentication. As a result, this type of
authentication method is extremely useful in the Wi-Fi environment due to the nature of the
medium. If a Wi-Fi user is authenticated via 802.1x for network access, a virtual port is opened on
the access point allowing for communication. If not successfully authorized, a virtual port is not made
available and communications are blocked
.

There are three basic pieces to 802.1x authentication:

  1. Supplicant – a software client running on the Wi-Fi workstation
  2. Authenticator – the Wi-Fi access point
  3. Authentication Server – a authentication database, usually a radius server such
    as Cisco* ACS*, Funk Steel-Belted RADIUS*, or Microsoft* IAS*

Extensible Authentication Protocol (EAP) is used to pass the authentication information
between the supplicant (the Wi-Fi workstation) and the authentication server
(Microsoft IAS or other). The actual authentication is defined and handled by the EAP type.
The access point acting as authenticator is only a proxy to allow the supplicant and the
authentication server to communicate
.

aaa new-model
!
!
aaa group server radius wifieap
server 10.195.2.52 auth-port 1812 acct-port 1813

!
aaa authentication login default group tacacs+ local enable
aaa authentication login wifiaaa group wifieap local
aaa authorization exec default group tacacs+ local none
aaa authorization commands 0 default group tacacs+ local none
aaa authorization commands 1 default group tacacs+ local none
aaa authorization commands 15 default group tacacs+ local none
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 0 default start-stop group tacacs+
aaa accounting commands 1 default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+

!
!
dot11 syslog
!
dot11 ssid GHG-Client-EAP
vlan 1
authentication open eap wifiaaa
authentication network-eap wifieap
authentication key-management wpa
guest-mode
!
bridge irb
!

interface Dot11Radio0
no ip address
!
encryption vlan 1 mode ciphers aes-ccm tkip

!
ssid GHG-Client-EAP
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
world-mode dot11d country GB outdoor

!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding

!
interface Vlan1
no ip address
bridge-group 1
bridge-group 1 spanning-disabled

!
interface BVI1
description LAN
ip address 192.168.1.0 255.255.255.0

!
ip radius source-interface BVI1
radius-server host 10.195.2.52 auth-port 1812 acct-port 1813 key 3Meq8LneR7t6
radius-server timeout 3

!
bridge 1 protocol ieee
bridge 1 route ip