Configuring the Cisco Secure ACS Server for 8021x and Eapfast

Complete the following steps to configure the Cisco Secure ACS server for 802.1x authentication using the EAP-FAST method. You first add the WLC as AAA client on the Cisco Secure ACS server.

To add the WLC as a AAA client on Cisco Secure ACS, click the Network Configuration radio button. You can create a network device group to maintain a collection of AAA clients and AAA servers, or you can use the default Not Assigned network device group. In this example, the WLC is added to the Not Assigned default group. Click the Not Assigned group.

Step 1 Click Add Entry. The screen shown in Figure 8-13 is displayed.

Step 2 Complete the form by entering the hostname and IP address of the WLC. (WLC is the hostname, and 172.18.85.96 is the management IP address of the WLC in this example.)

Figure 8-13 Adding an AAA Client into Cisco Secure ACS

Figure 8-13 Adding an AAA Client into Cisco Secure ACS

Step 3

Step 4

Step 5 Step 6

Enter the shared secret to be used between the Cisco Secure ACS server and the WLC. (In this example, the key is 1qaz@WSX.)

Choose RADIUS (Cisco Airspace) under the drop-down menu in the Authenticate Using section.

Click Submit + Apply.

In this example, the Cisco Secure ACS server queries an external Windows 2003 server for authentication credentials. Navigate through the radio button sequence as follows. Click External User Databases > Database Configuration > Windows Database > Configure.

Step 7 Under the Windows EAP Settings, check the Enable password change inside PEAP or EAP-FAST checkbox, as illustrated in Figure 8-14.

Step 8 Click Submit.

Step 9 Navigate to External User Databases > Unknown User Policy and click the Check the following external user databases radio button.

Step 10 Click the Windows Database from External Databases to Selected Databases, as shown in Figure 8-15.

Step 11 Click Submit.

Figure 8-14 Windows EAP Settings

Figure 8-14 Windows EAP Settings

Figure 8-15 Selecting the Windows Database on the Unknown User Policy

Step 12 Next, you have to enable EAP-FAST support on the Cisco Secure ACS Server. To do this, navigate via the radio buttons to System Configuration > Global Authentication Setup > EAP-FAST Configuration. The screen in Figure 8-16 is displayed.

Figure 8-16 Enabling EAP-FAST on Cisco Secure ACS

Figure 8-16 Enabling EAP-FAST on Cisco Secure ACS

Step 13 Check Allow EAP-FAST.

Step 14 In this example, the recommended (default) values for Active master key TTL (1 month), Retired master key TTL (3 months), and Tunnel

PAC TTL (1 week) are selected.

Step 15 The Authority ID Info text is shown on some EAP-FAST client software; in this case, cisco is the text configured and displayed. This can be anything you want. On the other hand, the CSSC (used in this scenario) does not display this descriptive text for the PAC authority. However, the word cisco will be displayed if any other client (802.1x supplicant) is used.

Step 16 Check the Allow anonymous in-band PAC provisioning checkbox.

This enables Automatic PAC Provisioning for EAP-FAST-enabled clients.

Step 17 The CSSC supports EAP-FAST Version 1a, which uses MS-CHAPv2 for authentication. Scroll down and check EAP-MSCHAPv2 under the Allowed inner methods section, as shown in Figure 8-17.

Figure 8-17 EAP-MSCHAPv2 and EAP-FASTMaster Server Configuration

Figure 8-17 EAP-MSCHAPv2 and EAP-FASTMaster Server Configuration

Step 18 Check the EAP-FAST master server check box to configure this

Cisco Secure ACS server as the master. The Actual EAP-FAST Master server status line will say Master. Any other Cisco Secure ACS servers (if present in your organization) will use this server as the master PAC authority to avoid the need to provision unique keys for each Cisco Secure ACS in a network.

Step 19 Click Submit + Restart.

Continue reading here: Lightweight Access Point Protocol LWAPP

Was this article helpful?

0 0