The objective of this document is to show you how to configure RADIUS in Cisco Business Wireless (CBW) Access Point (AP).
If you are looking to configure RADIUS in your CBW AP, you have come to the right place! The CBW APs support the latest 802.11ac Wave 2 standard for higher performance, greater access, and higher-density networks. They deliver industry-leading performance with highly secure and reliable wireless connections, for a robust, mobile end-user experience.
Remote Authentication Dial-In User Service (RADIUS) is an authentication mechanism for devices to connect and use a network service. It is used for centralized authentication, authorization, and accounting purposes. A RADIUS server regulates access to the network by verifying the identity of the users through the login credentials entered. For example, a public Wi-Fi network is installed in a university campus. Only those students who have the password can access these networks. The RADIUS server checks the passwords entered by the users and grants or denies access to the Wireless Local Area Network (WLAN) as appropriate.
If you are ready to configure RADIUS on your CBW AP, let’s get started!
This toggled section highlights tips for beginners.
Log into the Web User Interface (UI) of the Primary AP. To do this, open a web browser and enter https://ciscobusiness.cisco. You may receive a warning before proceeding. Enter your credentials.You can also access the Primary AP by entering https://[ipaddress] (of the Primary AP) into a web browser.
If you have questions about a field in the user interface, check for a tool tip that looks like the following:
Navigate to the menu on the left-hand side of the screen, if you don’t see the menu button, click this icon to open the side-bar menu.
These devices have companion apps that share some management features with the web user interface. Not all features in the Web user interface will be available in the App.
If you still have unanswered questions, you can check our frequently asked questions document. FAQ
Login to your CBW AP using a valid username and password.
Click on the bidirectional arrow symbol at the top of the web user-interface (UI) to Switch to Expert View.
You will see the following pop-up screen. Click OK to proceed.
Navigate to Management > Admin Accounts.
To add the RADIUS servers, click on the RADIUS tab.
From the Authentication Call Station ID Type drop-down list, choose the option that is sent to the RADIUS server in the Access-Request message. The following options are available:
Select the Authentication MAC Delimiter from the drop- down list. The options are:
Choose the Accounting Call Station ID Type from the drop-down list.
Choose the Accounting MAC Delimiter from the drop-down list.
Specify the RADIUS server Fallback Mode from the drop-down list. It can be one of the following:
If you enabled Active Fallback mode, enter the name to be sent in the inactive server probes in the Username field.
You can enter up to 16 alpha numeric characters. The default value is cisco-probe.
If you enabled Active Fallback mode, enter the probe interval value (in seconds) in the Interval field. The interval serves as inactive time in passive mode and probe interval in active mode.
The valid range is 180 to 3600 seconds, and the default value is 300 seconds.
Enable the AP Events Accounting slider button to activate sending of accounting requests to RADIUS server.
During network issues, the APs join/disjoin from the primary AP. Enabling this option ensures that these events are monitored and the accounting requests are sent to the RADIUS server to help you detect the network issues.
Click Apply.
To configure the RADIUS Authentication server, click on Add RADIUS Authentication Server.
In the Add/Edit RADIUS Authentication pop-up window, configure the following:
Click Apply.
To Add RADIUS Accounting Server, you would follow the same steps as in Step 15 as the page contains similar fields.
To configure WLAN that is going to handle WPA2 authentication with RADIUS, navigate to Wireless settings > WLAN.
Click on Add New WLAN/RLAN.
In the General tab, enter the Profile Name. The SSID field will auto-populate. You can choose to enable Local Profiling. Click Apply.
Navigate to WLAN Security tab. From the Security Type drop-down menu, choose WPA2Enterprise. Select External Radius as the Authentication Server. You can choose to enable Radius Profiling.
Navigate to RADIUS Server section. Click on Add RADIUS Authentication Server.
Verify the details of the RADIUS Authentication Server that you have configured and click Apply.
Click on Add RADIUS Accounting Server.
Verify the details of the RADIUS Accounting Server that you have configured and click Apply.
Navigate to VLAN & Firewall, Traffic Shaping, Advanced, and Scheduling tabs to configure the settings based on your network preferences. Click Apply.
To test the RADIUS authentication, do the following:
Navigate to Advanced > Primary AP Tools.
Click on Troubleshooting Tools.
In the Radius Response section, enter the Username and Password for the WLAN Profile that you have configured previously and click Start.
Once the verification is completed successfully, you will see the following notification on your screen.
There you have it! You have now learned the steps to configure RADIUS on your CBW AP. For more advanced configurations, refer to the Cisco Business Wireless Access Point Administration Guide.