Table Of Contents
Numerics - A - B - C - D - E - F - G - H - I - K - L - M - N - O - P - Q - R - S - T - U - V - W -
Index
Numerics
12.2(15)T 7-4
2.4-GHz WMIC, contrasted with 4.9-GHz WMIC 1-8
4.9 GHz (US Only, Public Safety) 8-2
802.11d 3-6
802.11d (world mode) 3-13
802.11h 7-2
802.1x authentication 4-13
A
AAA
server group 4-25
aaa authentication login command 4-24
aaa authorization command 4-27
aaa new-model command 4-22, 4-25
access point 3-2
security settings, matching client devices 3-25
WDS 14-2
accounting
with RADIUS 4-28
with TACACS+ 4-32, 4-37
accounting command 10-2
Address Resolution Protocol (ARP) 3-7
administrator access 4-21
Advanced Encryption Standard (AES) 1-7
AES-CCMP 11-2
Aironet 802.11 extensions 4-40
Aironet Client Utility (ACU) 8-3
antenna gains 8-4
ARPANET 4-1
attributes, RADIUS
vendor-proprietary 4-30
vendor-specific 4-29
authentication
EAP server 4-20, 3-3
local mode with AAA 4-38
MAC address 3-6
NTP associations 4-47
RADIUS
key 4-22
login 4-24
server configuration for fast secure roaming 14-5
TACACS+
defined 4-32
key 4-34
login 4-34, 4-35
authentication network-eap command 14-10
authentication types
CCKM key management 3-6
EAP-FAST 3-5
EAP-TLS 3-5
EAP-TTLS 3-5
MAC address 3-6
matching on root devices and non-root bridges 3-25
Network-EAP 3-3
open 3-2
shared key 3-2
using WPA key management 3-6
authorization
with RADIUS 4-27
with TACACS+ 4-32, 4-36
B
bandwidth
bridges 3-4
banner login command 4-5
banner motd command 4-4
banners
configuring
login 4-5
message-of-the-day login 4-4
default configuration 4-4
when displayed 4-3
basic data rate 8-5
basic settings
checking 8-3
bootloader 8-7
BOOTP 4-2
bridge
filters 3-3
bridge, wireless 3-2
Bridge Group Virtual Interface (BVI) 2-3
bridge mode 3-3, 3-7, 3-8
BSSIDs 10-3
BVI
universal workgroup bridge 3-8
C
CCKM 3-9, 3-6
CCK modulation 8-2
CDMA 1-1
CDP
disabling for routing device 2-3
enabling and disabling 2-3
monitoring 2-4
Centralized Key Management (CCKM) 11-1
certificates
configuring 3-7
channel
default setting i-xvi, 5-1, 7-1
channels
allowed per country3-14to 3-18
cipher suites
enabling 11-5
with WPA 11-8
Cisco Centralized Key Management
See CCKM
Cisco Centralized Key Management (CCKM) 1-7
Cisco Compatible eXtensions (CCX) 3-9
Cisco Express Forwarding (CEF) 7-4
Cisco IOS version 12.4(6)T 7-1
Cisco TAC 8-1
CiscoWorks 2000 10-3
CKIP 1-8
CKIP (Cisco Key Integrity Protocol) 11-2
Client MFP 15-2
clock
See system clock
clock set command 4-44
clock timezone command 4-45
CMIC 1-8, 11-2
CMIC (Cisco Message Integrity Check)
See CMIC
commands
aaa authentication login 4-24
aaa authorization 4-27
aaa new-model 4-22, 4-25
accounting 10-2
authentication network-eap 14-10
banner login 4-5
banner motd 4-4
bridge-group 5-4
cdp enable 2-3
cdp holdtime 2-2
cdp timer 2-2
clear cdp counters 2-4
clear cdp table 2-4
client profile multiple 3-11, 9-5
clock set 4-44
clock timezone 4-45
crypto map local-address 7-4
del 8-5
encapsulation 5-3
encapsulation dot1q 5-4
encryption 9-6
encryption mode cipher 11-1
hostname 4-1
infrastructure-client 3-7
interface dot11radio 9-1
interface dot11radio0 5-3
interface fastEthernet0.x 5-4
ip domain-lookup 4-3
ip domain-name 4-2
ip multicast-routing 7-1, 7-2
ip name-server 4-3
ip pim 7-1, 7-2
login authentication 4-25
ntp authenticate 4-47
ntp peer 4-49
power 8-2
power client 8-3
prompt 4-1
radius-server host 4-23
router mobile 7-1, 7-2
set 8-6
set BOOT 8-6
set next hop loopback 7-4
setting privilege levels 4-10
show cdp 2-4
show cdp entry 2-4
show cdp interface 2-4
show cdp neighbors 2-4
show cdp traffic 2-4
show controller dot11radio 8-8
show controllers dot11Radio 5-2, 8-2
show crypto ipsec 7-5
show ip mobile router 7-5
show ip mobile tunnel 7-2
speed 8-6
ssid 9-1
tftp_init 8-5
vlan 10-2
world mode 3-6
community strings
configuring 10-4
overview 10-3
connections, secure remote 4-39
console cable 2-1
console port
cable 2-2
country code 3-13
country codes, supported??to 3-18
cryptographic message integrity 11-2
crypto map 7-4
crypto map local-address command 7-4
crypto pki CLI 3-7
crypto software image 4-39
D
data rate
basic 8-5
setting 8-6
throughput 8-5
date
See NTP and system clock
daylight saving time 4-46
default
configuration, resetting 8-3
default configuration
banners 4-4
DNS 4-2
NTP 4-47
password and privilege level 4-6
SNMP 10-4
system message logging 6-3
TACACS+ 4-33
del command 8-5
Delivery Traffic Indication Message (DTIM) 10-3
DFS
operating frequency 7-2
DHCP 2-3, 4-2
DNS
default configuration 4-2
display configuration 4-3
overview 4-2
setting up 4-2
domain names
DNS 4-2
Domain Name System
See DNS
Dynamic Frequency Selection (DFS) 7-1
dynamic frequency selection (DFS) 5-1
dynamic tunnel 7-1
E
EIRP 3-14, 8-1, 11-1
enable password 4-7
enable secret password 4-7
encrypted software image 4-39
encryption for passwords 4-7
encryption mode cipher command 11-1
Enhanced Distributed Channel Access (EDCA) 1-7
error messages
setting the display destination device 6-5
severity levels 6-7
system message format 6-2
Ethernet indicator 8-1
Ethertype protocols
protocols
Ethertype 13-2
Express Security page 2-4
Extensible Authentication Protocol
See EAP
extensions, Aironet 4-40
F
Fast Ethernet Switch mobile interface card (FESMIC) 2-1
Fast Secure Roaming 3-9
fast secure roaming 14-1
and WDS 14-4
authentication server 14-5
features 1-7
filters
configuring using CLI 9-2
protocol 13-1
forward-delay time
STP 1-6
frequencies 6-1, 6-2, 6-3, 6-4, 6-5
FTP
accessing MIB files 12-2
G
get-bulk-request operation 10-2
get-next-request operation 10-2, 10-3
get-request operation 10-2, 10-3
get-response operation 10-2
GPRS 1-4
group key updates 3-23
H
history table, level and number of syslog messages 6-8
home agent
tunnel template 7-1
host name, ARPANET rules 4-1
hostname command 4-1
I
IAPP messaging 3-6
IDS Mobile Networks 7-4
image, operating system 8-5
indicators 8-1
infrastructure-client command 3-7
infrastructure device 3-7
Interior Gateway Protocol (IGP) 1-4
IP address 2-3
release and renew 2-1
ip domain-lookup command 4-3
ip domain-name command 4-2
ip multicast-routing command 7-1, 7-2
ip name-server command 4-3
ip pim command 7-1, 7-2
IP port protocols 13-4
IP protocols
protocols
IP 13-3
IPSec
crypto map 7-4
tunnel template 7-4
ISO designators for protocols 13-1
K
KCK 1-4
KEK 1-4
key features 1-7
key management types 11-8
L
LEAP
setting on client and access point 3-25
LED indicators
Ethernet 8-1
radio traffic 8-1
status 8-1
Lightweight AP Protocol (LWAPP) 3-7
Load balancing 4-40
load balancing (wireless bridge) 3-5
login authentication
with RADIUS 4-24
with TACACS+ 4-34, 4-35
login authentication command 4-25
login banners 4-3
log messages
See system message logging
loopback
crypto map 7-4
M
MAC address
authentication 3-6
troubleshooting 8-3
Management Frame Protection 15-1
access points in root mode 15-2
broadcast management frames 15-2
unicast management frames 15-2
Management Frame Protection 2
configuring 15-2
Message Authentication Code 1-5
Message Integrity Check
See MIC
Message Integrity Code (MIC)
definition 1-5
message-of-the-day (MOTD) 4-3
messages
to users through banners 4-3
method list 4-21
Metropolitan Mobile Networks (MMN) 3-3
MIBs
accessing files with FTP 12-2
location of files 12-2
overview 10-1
SNMP interaction with 10-3
MIC 4-40, 11-1, 8-3
Mobile IP
tunnel 3-8
modes
bridge 3-3, 3-7, 3-8
world 3-13
MoIP tunnel 1-5
monitoring, CDP 2-4
multicast 7-1
tunnel template 7-4
tunnel templates 7-1
multiple basic SSIDs (multiple BSSIDs)
description 10-3
requirements and guidelines 10-3
multiple client profiles
configuring WMIC 9-3, 9-5
N
name-to-address translation 4-3
Network-EAP 3-3
Network Time Protocol
See NTP
non-Cisco client 3-8
non-root access point 3-2
NTP
associations
authenticating 4-47
enabling broadcast messages 4-50
peer 4-49
server 4-49
default configuration 4-47
displaying the configuration 4-54
overview 4-41
restricting access
creating an access group 4-52
disabling NTP services per interface 4-53
source IP address, configuring 4-54
stratum 4-41
synchronizing devices 4-49
time
synchronizing 4-41
ntp authenticate command 4-47
ntp peer command 4-49
O
OFDM 1-8
OFDM modulation 8-2
P
Pairwise Master Key (PMK) 1-5
password reset 8-3
passwords
default configuration 4-6
encrypting 4-7
setting
enable 4-6
enable secret 4-7
with usernames 4-9
per-VLAN Spanning Tree (PVST) 1-2
PKI
point-to-multipoint bridge 3-4
point-to-point bridging 3-3
power client command 8-3
power level, maximum 8-4
preferential treatment of traffic
See QoS
pre-shared key 3-23
primary intersection 1-3
privilege levels
exiting 4-11
logging into 4-11
overview 4-5, 4-10
setting a command with 4-10
prompt command 4-1
protocol filters 9-2, 13-1
protocols
IP port 13-4
public key infrastructure
See PKI
Q
QoS
configuration guidelines 4-4
impact on wireless LAN 4-2
overview 4-1
precedence 4-3
quality of service
See QoS
R
radar 7-1
Transmission Power Contro and Dynamic Frequency Selection 5-1, 7-1
radio
configuring transmit power 8-2, 8-3
indicator 8-1
radio channel
frequency 5-2
number 5-2
width 5-3
radio management 14-1
radio type 5-2, 8-2
RADIUS
administrator access 4-21
attributes
vendor-proprietary 4-30
vendor-specific 4-29
configuring
accounting 4-28
authentication 4-24
authorization 4-27
communication, global 4-22, 4-28
communication, per-server 4-21, 4-22
multiple UDP ports 4-22
default configuration 4-21
defining AAA server groups 4-25
displaying the configuration 4-31
identifying the server 4-21
limiting the services to the user 4-27
method list 4-21
operation of 4-20
overview 4-19
SSID 10-2
suggested network environments 4-19
tracking services accessed by user 4-28
radius-server host command 4-23
range 8-5
rate limit, logging 6-9
redundancy (wireless bridge) 3-5
regulatory
domains 6-2, 6-5
regulatory domains3-13to 3-18, 6-1, 6-3
regulatory limits 3-13
release and renew the IP address 2-1
reloading access point image 8-5
Remote Authentication Dial-In User Service
See RADIUS
restricting access
NTP services 4-52
passwords and privilege levels 4-5
TACACS+ 4-32
reverse tunneling
tunnel templates 7-1
RFC
1157, SNMPv1 10-2
1305, NTP 4-41
1901, SNMPv2C 10-2
1902 to 1907, SNMPv2 10-2
roaming, fast secure roaming using CCKM 14-2
role 3-1
station-role command 3-1
roles
access point 3-2
bridge 3-2
workgroup bridge 3-6
root access point 3-2
router mobile command 7-1, 7-2
S
secondary intersection 1-3
secure remote connections 4-39
Secure Shell
See SSH
Secure Shell (SSH)
See SSH
security 2-4
protocol 4-21
root device and non-root bridge settings 3-25
synchronizing 3-25
troubleshooting 8-3
security settings, Express Security page 2-4
self-healing wireless LAN 14-4
sequence numbers in log messages 6-6
server group
AAA 4-25
service set identifier (SSID) 3-7, 10-1, 15-1
set BOOT command 8-6
set command 8-6
set next hop loopback command 7-4
set-request operation 10-3
severity levels, defining in system messages 6-7
shared-key authentication 3-2
show controller dot11radio command 8-8
show controllers dot11Radio command 5-2, 8-2
show crypto ipsec command 7-5
show ip mobile router command 7-5
show ip mobile tunnel command 7-2
show vlan 5-6
Simple Network Management Protocol
See SNMP
SNMP
accessing MIB variables with 10-3
agent
described 10-3
disabling 10-4
community strings
configuring 10-4
overview 10-3
configuration examples 10-9
default configuration 10-4
limiting system log messages to NMS 6-8
manager functions 10-2
MIBs, location of 12-2
overview 10-1, 10-3
snmp-server view 10-9
status, displaying 10-10
system contact and location 10-9
trap manager, configuring 10-8
traps
described 10-2
enabling 10-6
overview 10-1, 10-3
types of 10-6
versions supported 10-2
software images
delete from Flash 8-5
Spanning Tree Protocol (wireless bridge)
See STP
speed command 8-6
SSH
crypto software image 4-39
described 4-39
description 2-2
displaying settings 4-40
SSH Communications Security, Ltd. 2-2
SSID
2.4-GHz radio 10-2
configuring 10-2
default (tsunami) 8-3
disable 10-2
RADIUS 10-2
troubleshooting 8-3
understanding 10-1
VLAN 2-4, 4-12, 10-2
without VLANs 4-11
static ARP 3-8
static WEP 4-11
with open authentication, setting on client and access point 3-25
with shared key authentication, setting on client and access point 3-25
station-role command 3-1
statistics
CDP 2-4
SNMP input and output 10-10
status indicators 8-1
STP
BPDU message exchange 1-3
designated port, defined 1-3
designated switch, defined 1-3
displaying status 1-14
inferior BPDU 1-3
interface states
blocking 1-6
disabled 1-7
forwarding 1-6, 1-7
learning 1-7
listening 1-7
overview 1-5
overview 1-2
redundant bridging 3-5
root port, defined 1-3
superior BPDU 1-3
timers, described 1-4
stratum, NTP 4-41
summer time 4-46
syslog
See system message logging
system clock 4-41
configuring
daylight saving time 4-46
manually 4-44
summer time 4-46
time zones 4-45
displaying the time and date 4-44
overview 4-41
See also NTP
system message logging
default configuration 6-3
defining error message severity levels 6-7
disabling 6-4
displaying the configuration 6-11
enabling 6-4
facility keywords, described 6-11
level keywords, described 6-8
limiting messages 6-8
message format 6-2
overview 6-1
rate limit 6-9
sequence numbers, enabling and disabling 6-6
setting the display destination device 6-5
timestamps, enabling and disabling 6-6
UNIX syslog servers
configuring the daemon 6-10
configuring the logging facility 6-10
facilities supported 6-11
system name 4-1
manual configuration 4-1
T
TAC 8-1
TACACS+
accounting, defined 4-32
authentication, defined 4-32
authorization, defined 4-32
configuring
accounting 4-37
authentication key 4-34
authorization 4-36
login authentication 4-34, 4-35
default configuration 4-33
displaying the configuration 4-38
identifying the server 4-34
limiting the services to the user 4-36
operation of 4-33
overview 4-32
tracking services accessed by user 4-37
Telnet 2-1, 2-2
Temporal Key Integrity Protocol (TKIP) 11-1
Terminal Access Controller Access Control System Plus
See TACACS+
TFTP 8-5
tftp_init command 8-5
throughput 8-5
time
See NTP and system clock 4-41
timestamps in log messages 6-6
time zones 4-45
TKIP 4-40
Transmission Power Control (TPC) 5-1, 7-1
transmission power level 5-1, 7-1
transmit power 8-2, 8-3
client 8-3
regulatory limits 3-13
transmit power levels
supported by country3-13to 3-18
transmit speed 8-6
traps
configuring managers 10-6
defined 10-2
enabling 10-6
notification types 10-6
overview 10-1, 10-3
Tropos access point 3-8
troubleshooting 8-1
with CiscoWorks 10-3
with system message logging 6-1
tunnel 1-5
tunnel template
apply 7-2
dynamic tunnel 7-1
for multicast 7-1
IPSec 7-4
reverse tunneling 7-1
U
universal workgroup bridge 3-8
bridge
universal workgroup bridge 3-8
interoperability 3-6
multiple client profiles
multiple client profiles
description 1
world mode 3-6
universial workgroup bridge
static ARP 3-8
UNIX syslog servers
daemon configuration 6-10
facilities supported 6-11
message logging configuration 6-10
username-based authentication 4-9
V
VLAN
and bridges 5-2
configuring 5-3
overview 5-1
SSID 2-4, 4-11, 4-12, 10-2
with wireless bridges 5-3
vlan command 10-2
W
WDS
access point 14-2
and fast secure roaming 14-4
and WMIC 14-1
CLI commands 14-9
guidelines and requirements 14-4
universal workgroup bridge 3-9
web site
Cisco Software Center 8-7
WEP
configuring key 11-2
described 11-2
key example 11-5
key restrictions 11-4
keys 8-3
troubleshooting 8-3
with EAP 3-3
Wi-Fi Multimedia
See WMM
Wi-Fi Protected Access
See WPA
Wi-Fi Protected Access (WPA) 4-13
Wired Equivalent Privacy
See WEP
wireless bridges 5-3
Wireless Domain Services
See WDS
Wireless Domain Services (WDS) 14-1
WMIC
and WDS 14-1
multiple client profiles 9-3, 9-5
WMM
workgroup bridge 3-6
infrastructure-client 3-7
world mode 3-13
802.11d 3-12
Cisco legacy 3-12
description 3-6
enabling and disabling 3-12
world-mode command 3-6
WPA 4-11
cipher suite 11-1
description 3-6
key management 3-6
WPA2 1-7