Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

EAP-FAST on Autonomous AP config

I am trying to setup EAP-FAST on an autonomous 1242 AP and I cannot figure out what I have wrong in the configuration.  The config output is below and I am trying to setup automatic PAC provisioning but the authentication is failing.

Any push in the right direction would be appreciated.

Thanks

version 12.4

no service pad

service timestamps debug datetime msec

service timestamps log datetime msec

service password-encryption

!

hostname AP01

!

logging rate-limit console 9

enable secret 5 $1$PY9W$6/7dKI972HJ45EIzUDvaQ.

!

aaa new-model

!

!

aaa group server radius rad_local

server 172.20.7.5 auth-port 1812 acct-port 1813

!

aaa authentication login eap_methods group rad_local

!

aaa session-id common

no ip domain lookup

!

!

dot11 syslog

!

dot11 ssid fast

   vlan 20

   authentication open eap eap_methods

   authentication key-management wpa version 2

   guest-mode

!

!

!

username Cisco password 7 13261E010803

!

!

bridge irb

!

!

interface Dot11Radio0

no ip address

no ip route-cache

shutdown

station-role root

bridge-group 1

bridge-group 1 subscriber-loop-control

bridge-group 1 block-unknown-source

no bridge-group 1 source-learning

no bridge-group 1 unicast-flooding

bridge-group 1 spanning-disabled

!

interface Dot11Radio1

no ip address

no ip route-cache

!

encryption vlan 20 mode ciphers aes-ccm

!

ssid fast

!

dfs band 3 block

channel dfs

station-role root

bridge-group 1

bridge-group 1 subscriber-loop-control

bridge-group 1 block-unknown-source

no bridge-group 1 source-learning

no bridge-group 1 unicast-flooding

bridge-group 1 spanning-disabled

!

interface Dot11Radio1.20

encapsulation dot1Q 20

no ip route-cache

bridge-group 20

bridge-group 20 subscriber-loop-control

bridge-group 20 block-unknown-source

no bridge-group 20 source-learning

no bridge-group 20 unicast-flooding

bridge-group 20 spanning-disabled

!

interface FastEthernet0

no ip address

no ip route-cache

duplex auto

speed auto

bridge-group 1

no bridge-group 1 source-learning

bridge-group 1 spanning-disabled

!        

interface FastEthernet0.20

encapsulation dot1Q 20

no ip route-cache

bridge-group 20

no bridge-group 20 source-learning

bridge-group 20 spanning-disabled

!

interface BVI1

ip address 172.20.7.5 255.255.255.0

no ip route-cache

!

ip http server

no ip http secure-server

ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag

radius-server local

  no authentication leap

  no authentication mac

  eapfast authority info abc123

  eapfast server-key primary 7 F09B273B14FED50E90A0D2BDA469523E6F

  nas 172.20.7.5 key 7 045A09055E731F

  user eapfast nthash 7 06252D796F682A4F2034472A545D087A727A64177A3623445725740F0A06015F55

!        

radius-server host 172.20.7.5 auth-port 1812 acct-port 1813 key 7 00051105550958

bridge 1 route ip

!

!

!

line con 0

line vty 0 4

!

end

2 REPLIES

Re: EAP-FAST on Autonomous AP config

under the dot11 SSID config try adding:

Authentication network-EAP eap_methods

Sent from Cisco Technical Support iPad App

HTH, Steve ------------------------------------------------------------------------------------------------ Please remember to rate useful posts, and mark questions as answered
New Member

EAP-FAST on Autonomous AP config

I have tried that with no luck. I have also tried wpa version 1 vs version 2 with no luck.

1158
Views
0
Helpful
2
Replies
CreatePlease to create content