user manual
8-16
Cisco Aironet 1200 Series Access Point Software Configuration Guide
OL-2159-05
Chapter 8 Security Setup
Setting Up EAP Authentication
Note You can use the same server for both EAP authentication and MAC-address authentication.
Step 2 Use the 802.1X Protocol Version (for EAP authentication) pull-down menu to select the draft of the
802.1X protocol the access point’s radio will use. EAP operates only when the radio firmware on client
devices complies with the same 802.1X Protocol draft as the management firmware on the access point.
If the radio firmware on the client devices that will associate with the access point is 4.16, for example,
you should select Draft 8. Menu options include:
• Draft 7—No radio firmware versions compliant with Draft 7 have LEAP capability, so do not select
this setting.
• Draft 8—Select this option if LEAP-enabled client devices that associate with this access point use
radio firmware versions 4.13, 4.16, or 4.23.
• 802.1x-2001 (formerly Draft 10)—Select this option if client devices that associate with this access
point use Microsoft Windows XP authentication or if LEAP-enabled client devices that associate
with this access point use radio firmware version 4.25 or later.
Table 8-3 lists radio firmware versions for Cisco Aironet products and the drafts with which they
comply.
1. The default draft setting in access point and bridge firmware version 11.06 and later is 802.1x-2001.
Note Draft standard 8 is the default setting in firmware version 11.05 and earlier, and it might remain
in effect when you upgrade the firmware to version 11.06 or later. Check the setting on the
Authenticator Configuration page in the management system to make sure the best draft standard
for your network is selected.
Step 3 Enter the name or IP address of the RADIUS server in the Server Name/IP entry field.
Step 4 Select the server type (RADIUS or TACAS) in the Server Type field.
Step 5 Enter the port number your RADIUS server uses for authentication. The default setting, 1812, is the port
setting for Cisco’s RADIUS server, the Cisco Secure Access Control Server (ACS), and for many other
RADIUS servers. Check your server’s product documentation to find the correct port setting.
Table 8-3 802.1x Protocol Drafts and Compliant Client Firmware
Firmware Version Draft 7 Draft 8 802.1x-2001
PC/PCI cards 4.13 — x —
PC/PCI cards 4.16 — x —
PC/PCI cards 4.23 — x —
PC/PCI cards 4.25 and later —— x
WGB34x/352 8.58 — x —
WGB34x/352 8.61 or later —— x
AP34x/35x 11.05 and earlier — x —
AP34x/35x 11.06 and later — xx
BR352 11.06 and later
1
— xx