Cisco 857 Radius Eap Wireless Authentication
Extensible Authentication Protocol (EAP) Authentication Types
802.1x Overview
It is a port access protocol for protecting networks via authentication. As a result, this type of
authentication method is extremely useful in the Wi-Fi environment due to the nature of the
medium. If a Wi-Fi user is authenticated via 802.1x for network access, a virtual port is opened on
the access point allowing for communication. If not successfully authorized, a virtual port is not made
available and communications are blocked.
There are three basic pieces to 802.1x authentication:
- Supplicant – a software client running on the Wi-Fi workstation
- Authenticator – the Wi-Fi access point
- Authentication Server – a authentication database, usually a radius server such
as Cisco* ACS*, Funk Steel-Belted RADIUS*, or Microsoft* IAS*
Extensible Authentication Protocol (EAP) is used to pass the authentication information
between the supplicant (the Wi-Fi workstation) and the authentication server
(Microsoft IAS or other). The actual authentication is defined and handled by the EAP type.
The access point acting as authenticator is only a proxy to allow the supplicant and the
authentication server to communicate.
aaa new-model
!
!
aaa group server radius wifieap
server 10.195.2.52 auth-port 1812 acct-port 1813
!
aaa authentication login default group tacacs+ local enable
aaa authentication login wifiaaa group wifieap local
aaa authorization exec default group tacacs+ local none
aaa authorization commands 0 default group tacacs+ local none
aaa authorization commands 1 default group tacacs+ local none
aaa authorization commands 15 default group tacacs+ local none
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 0 default start-stop group tacacs+
aaa accounting commands 1 default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
!
!
dot11 syslog
!
dot11 ssid GHG-Client-EAP
vlan 1
authentication open eap wifiaaa
authentication network-eap wifieap
authentication key-management wpa
guest-mode
!
bridge irb
!
!
encryption vlan 1 mode ciphers aes-ccm tkip
!
ssid GHG-Client-EAP
!
speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
station-role root
world-mode dot11d country GB outdoor
!
interface Dot11Radio0.1
encapsulation dot1Q 1 native
no cdp enable
bridge-group 1
bridge-group 1 subscriber-loop-control
bridge-group 1 spanning-disabled
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
!
interface Vlan1
no ip address
bridge-group 1
bridge-group 1 spanning-disabled
!
interface BVI1
description LAN
ip address 192.168.1.0 255.255.255.0
!
ip radius source-interface BVI1
radius-server host 10.195.2.52 auth-port 1812 acct-port 1813 key 3Meq8LneR7t6
radius-server timeout 3
!
bridge 1 protocol ieee
bridge 1 route ip