To configure a Cisco WLC for WPA-PEAP and IAS, perform the following steps:
-
Set up IAS security details:
-
Select Security on the Cisco WLC home page.
-
Select RADIUS Authentication under
AAA.
-
Click New for RADIUS Authentication
Servers.
-
Enter the IP Address of your IAS server in the Server IP
Address field.
-
Select ASCII for Shared Secret
Format.
-
Enter your Shared Secret as an ASCII string.
This shared secret must be the same as the one entered in the IAS RADIUS
Clients when setting up Cisco WLC as a RADIUS Client in IAS.
-
Accept the default of 1812 for Port
Number.
-
Set Server Status to Enabled.
-
Accept defaults for the remaining settings, and then click
Apply.
-
Select RADIUS Authentication under
AAA to confirm that the Cisco WLC can reach the IAS
server. For the entry of your IAS server, click Ping.
-
Set up the SSID details:
-
Select WLANS on the Cisco WLC home page.
-
Click New for WLANS.
-
Enter your SSID for WLAN SSID.
-
Accept defaults for the remaining settings, and then click
Apply.
-
Click Edit for the SSID you entered.
-
Select 802.11 b/g for Radio
Policy.
-
Check Enabled for Admin
Status.
-
Set the value to 0 to indicate no session timeout for Session
Timeout (Secs). Cisco WLC does not support RADIUS-set session
timeouts.
-
Select Platinum (Voice) for Quality Of
Service (QoS).
-
Uncheck Enabled for Client
Exclusion.
-
Check Override and then enter the IP address of your
DHCP server For DHCP Server.
-
Select WPA for Layer 2
Security, .
-
Accept defaults for the remaining settings, and click
Apply.
-
Configure Cisco WLC general settings
-
Ensure the following settings:
-
AP Multicast Mode Support is enabled.
-
Load Balancing is disabled.
-
Band Select is disabled.
-
P2P Blocking Action is disabled.
-
Over The Air Provisioning of AP is
disabled.
-
Client Load Balancing is disabled.