Validate Configuration Tasks for Web Authentication

Validate Configuration Tasks for Web Authentication

Table 1. Verify Web Authentication Configuration

Command

Command Output

show wlan summary

WLC#sh wlan summary 

Number of WLANs: 10

ID    Profile Name    SSID        Status        Security 
---------------------------------------------------------------------------------------------------------------------------------------------------------
1     OPEN_NET        OPEN_NET    DOWN          [open] 
2     IPSK            IPSK        DOWN          [WPA2][PSK][FT + PSK][AES],[FT Enabled],MAC Filtering 
3     GUEST           GUEST       UP            [open],[Web Auth] 
5     LWA             LWA         DOWN          [WPA2],[Web Auth] 
6     CWA             CWA         DOWN          [WPA2],MAC Filtering 
9     PSK             PSK         DOWN          [WPA2][PSK][AES] 
10    WLC-DOT1X       WLC-DOT1X   UP            [WPA2][802.1x][FT + 802.1x][AES],[FT Enabled] 
12    WA_OPEN         OPEN        UP            [open],[Web Auth] 
13    WLC-PSK         WLC-PSK     UP            [WPA2][PSK][AES] 
15    TEST            TEST        DOWN          [WPA2][802.1x][AES]

show running-config | section parameter-map type webauth parameter-map


Device#show running-config | section parameter-map type webauth test
parameter-map type webauth test
type webauth
redirect for-login http://9.1.0.100/login.html
redirect portal ipv4 9.1.0.100

show crypto pki trustpoints certificates


Device#show crypto pki trustpoints cert
Trustpoint cert:
    Subject Name: 
    e=rkannajr@cisco.com
    cn=sthaliya-lnx
    ou=WNBU
    o=Cisco
    l=SanJose
    st=California
    c=US
    Serial Number (hex): 00
    Certificate configured.

show crypto pki certificates


Device#show crypto pki certificates certificate
Certificate
  Status: Available
  Certificate Serial Number (hex): 04
  Certificate Usage: General Purpose
  Issuer: 
    e=rkannajr@cisco.com
    cn=sthaliya-lnx
    ou=WNBU
    o=Cisco
    l=SanJose
    st=California
    c=US
  Subject:
    Name: ldapserver
    e=rkannajr@cisco.com
    cn=ldapserver
    ou=WNBU
    o=Cisco
    st=California
    c=US
  Validity Date: 
    start date: 07:35:23 UTC Jan 31 2012
    end   date: 07:35:23 UTC Jan 28 2022
  Associated Trustpoints: cert ldap12 
  Storage: nvram:rkannajrcisc#4.cer

CA Certificate
  Status: Available
  Certificate Serial Number (hex): 00
  Certificate Usage: General Purpose
  Issuer: 
    e=rkannajr@cisco.com
    cn=sthaliya-lnx
    ou=WNBU
    o=Cisco
    l=SanJose
    st=California
    c=US
  Subject: 
    e=rkannajr@cisco.com
    cn=sthaliya-lnx
    ou=WNBU
    o=Cisco
    l=SanJose
    st=California
    c=US
  Validity Date: 
    start date: 07:27:56 UTC Jan 31 2012
    end   date: 07:27:56 UTC Jan 28 2022
  Associated Trustpoints: cert ldap12 ldap 
  Storage: nvram:rkannajrcisc#0CA.cer

show crypto ca certificate verb


Device#show crypto ca certificate verb
Certificate
Status: Available
Version: 3
Certificate Serial Number (hex): 2A9636AC00000000858B
Certificate Usage: General Purpose
Issuer:
    cn=Cisco Manufacturing CA
    o=Cisco Systems
Subject:
    Name: WS-C3780-6DS-S-2037064C0E80
    Serial Number: PID:WS-C3780-6DS-S SN:FOC1534X12Q
    cn=WS-C3780-6DS-S-2037064C0E80
    serialNumber=PID:WS-C3780-6DS-S SN:FOC1534X12Q
CRL Distribution Points:
    http://www.cisco.com/security/pki/crl/cmca.crl
Validity Date:
    start date: 15:43:22 UTC Aug 21 2011
    end   date: 15:53:22 UTC Aug 21 2021
Subject Key Info:
    Public Key Algorithm: rsaEncryption
    RSA Public Key: (1024 bit)
Signature Algorithm: SHA1 with RSA Encryption
Fingerprint MD5: A310B856 A41565F1 1D9410B5 7284CB21
Fingerprint SHA1: 04F180F6 CA1A67AF 9D7F561A 2BB397A1 0F5EB3C9
X509v3 extensions:
    X509v3 Key Usage: F0000000
      Digital Signature
      Non Repudiation
      Key Encipherment
      Data Encipherment
    X509v3 Subject Key ID: B9EEB123 5A3764B4 5E9C54A7 46E6EECA 02D283F7
    X509v3 Authority Key ID: D0C52226 AB4F4660 ECAE0591 C7DC5AD1 B047F76C
    Authority Info Access:
Associated Trustpoints: CISCO_IDEVID_SUDI
Key Label: CISCO_IDEVID_SUDI

show wireless client sleeping-client

Device# show wireless client sleeping-client
Total number of sleeping-client entries: 1
MAC Address                Remaining time (mm:ss)
--------------------------------------------------------
2477.031b.aa18             59:56