Guides configuration of access points as Workgroup Bridges, including tasks to enter autonomous mode, set up Wave 2 APs, configure SSID and EAP profiles, authentication servers, 802.1X credentials, certificate enrollment, radio interface, timeouts, and bridge forwarding using CLI commands.
Configure Cisco Wave 2 APs or 11AX APs in WGB or CAPWAP AP mode (CLI)
Procedure
| 1. | Enter the privileged mode of the AP. Example:
|
|
| 2. | Move the AP in to the Workgroup Bridge mode. Example:
|
|
| 3. | Configure DHCP or static IP address using the configure ap address ipv4 dhcp or configure ap address ipv4 static ip-address netmask gateway-ipaddress command. Example:DHCP IP Address
Static IP Address
|
|
| 4. | Configure an username for the AP management. Example:
|
|
| 5. | Configure the AP hostname. Example:
|
Configure an SSID profile for Cisco Wave 2 and 11AX APs (CLI)
Before you begin
Ensure you have access to the AP console and any preshared keys or EAP profiles needed for authentication.Procedure
| 1. | Create an SSID profile and specify authentication (open, PSK, or EAP) and key management options. Example:SSID profile with open authentication:
SSID profile with PSK authentication:
SSID profile with EAP authentication:
Choose the authentication protocol that matches your deployment requirements. |
|
| 2. | Attach the SSID profile to a radio interface. Example:
Binds the SSID profile for wireless bridge operations. |
|
| 3. | (Optional) Configure the DTIM period for the SSID profile. Example:
Sets the delivery traffic indication message interval for broadcast/multicast traffic.
|
|
| 4. | (Optional) Create a QoS profile. Example:
Gold, silver, platinum, and bronze options are available to prioritize traffic. |
|
| 5. | (Optional) Map the QoS profile to the SSID profile. Example:
Enables traffic prioritization for the specified SSID profile.
|
|
| 6. | (Optional) Delete an SSID profile. Example:
|
|
| 7. | (Optional) Display summary of configured and connected SSIDs. Example:
|
|
| 8. | (Optional) Display management, control, and data packet statistics for WGB SSIDs. Example:
|
Configure the authentication server (CLI)
Before you begin
Ensure you have the IP address, port number, and shared secret for the RADIUS server you are configuring.Procedure
Configure a RADIUS authentication server with a primary or secondary role, IP version (IPv4 or IPv6), port, server address, and shared secret. Example:
|
Configure dot1X credential (CLI)
Before you begin
Ensure the device is in global configuration mode before issuing these commands.Procedure
| 1. | Configure a dot1X credential profile with username and password. Example:
|
|
| 2. | Delete a dot1X credential profile. Example:
|
|
| 3. | Deauthenticate a WGB client by clearing a WGB client session based on MAC address or clear all WGB clients. Example:
To clear all WGB clients, use:
|
Configure an EAP profile (CLI)
Before you begin
Enable global configuration mode on the device and verify access to CLI.Procedure
| 1. | Configure an EAP profile and set the EAP method. Example:
Configures an EAP profile with the chosen method. The method-name can be:
|
|
| 2. | Associate a Trustpoint with the EAP profile. Use either the default or a specific name. Example:EAP profile to Trustpoint with MIC Certificate:
EAP profile to Trustpoint with CA Certificate:
Configures an EAP profile with a Trustpoint for authentication. |
|
| 3. | Attach a CA Trustpoint to the EAP profile. Example:
Attaches the CA Trustpoint.
|
|
| 4. | Configure the 802.1X credential profile for the EAP profile. Example:
Configures the 802.1X credential profile associated with the EAP profile. |
|
| 5. | (Optional) Delete an EAP profile. Example:
|
|
| 6. | (Optional) Display the WGB EAP dot1x credential profile summary. Example:
|
|
| 7. | (Optional) Display the EAP profile summary. Example:
|
|
| 8. | (Optional) Display all configured EAP and dot1x profiles. Example:
|
Configure manual-enrollment of a Trustpoint for WGB (CLI)
Before you begin
Ensure that the WGB configuration is complete and the required CA certificate is accessible. You must have administrator access to the CLI and all necessary server and certificate information.Procedure
| 1. | Configure a Trustpoint on the WGB and set the enrollment method to terminal. Example:
Defines a new Trustpoint and specifies that certificate content will be entered manually. |
|
| 2. | Authenticate the Trustpoint and input the base 64 encoded CA certificate. Example:
Authenticates a Trustpoint by pasting the CA-signed certificate. End certificate input by typing quit on a new line. |
|
| 3. | Configure the private key size for the Trustpoint. Example:
Sets the RSA key pair length for the Trustpoint’s private key. |
|
| 4. | Configure the subject name attributes for the Trustpoint’s certificate. Example:
Example:
Specifies certificate subject fields, matching your organization’s naming policy. |
|
| 5. | Generate a Certificate Signing Request (CSR) on the WGB and enroll the Trustpoint. Example:
Generates the private key and a CSR; provide the CSR output to your CA server for certificate signing. |
|
| 6. | Import the signed certificate from the CA back into the WGB Trustpoint. Example:
Installs the issued device certificate. End certificate input with the quit command on a new line. |
|
| 7. | (Optional) Delete the Trustpoint if reconfiguration is needed. Example:
Removes a Trustpoint configuration from the device. |
|
| 8. | (Optional) Display the Trustpoint summary. Example:
Shows all Trustpoints configured on the device. |
|
| 9. | (Optional) Display certificates associated with a Trustpoint. Example:
Inspect the contents of certificates for a specific Trustpoint. |
Configure auto-enrollment of a Trustpoint for workgroup bridge (CLI)
Before you begin
Ensure the device is running the appropriate WGB image and has connectivity to the CA server.Procedure
| 1. | Configure the Trustpoint and specify the CA server enrollment URL. Example:
Enrolls a Trustpoint in WGB using the CA server URL. |
|
| 2. | Authenticate the Trustpoint by fetching the CA certificate from the CA server. Example:
Fetches the CA certificate for Trustpoint authentication. |
|
| 3. | Set the private key size for the Trustpoint. Example:
Example:
|
|
| 4. | Configure the subject name for the trustpoint. Example:
Example:
Customize the subject name parameters as needed for your deployment. |
|
| 5. | Enroll the Trustpoint to request a signed certificate from the CA server. Example:
Initiates the certificate enrollment request to the CA server. |
|
| 6. | Enable auto-enrollment and specify the renewal percentage threshold. Example:
Example:
Use disable to turn off auto-enroll if needed. |
|
| 7. | (Optional) Delete the Trustpoint if it is no longer required. Example:
Removes the Trustpoint from the configuration. |
|
| 8. | (Optional) Display the summary of Trustpoints. Example:
Lists all configured Trustpoints and their status. |
|
| 9. | (Optional) Display the certificate for a specific Trustpoint. Example:
Shows the certificate configured for the specified Trustpoint. |
|
| 10. | (Optional) Display the PKI timer information. Example:
Displays timer settings related to PKI operations. |
Configure manual certificate enrollment using TFTP server (CLI)
Procedure
| 1. | Specify the enrollment method to retrieve the CA certificate and client certificate for a Trustpoint in WGB. Example:
|
|
| 2. | Authenticate the CA certificate from the specified TFTP server. Example:
Retrieves the CA certificate and authenticates it from the specified TFTP server. If the file specification is included, the WGB will append the extension “.ca” to the specified filename. |
|
| 3. | Configure the private key size for the Trustpoint. Example:
|
|
| 4. | Set the subject name for the Trustpoint. Example:
|
|
| 5. | Generate a private key and certificate signing request (CSR). Example:
Generate a private key and Certificate Signing Request (CSR) and write the request out to the TFTP server. The filename to be written is appended with the extension “.req”. |
|
| 6. | Import the signed certificate into WGB using TFTP at the console terminal, which retrieves the granted certificate. Example:
The WGB will attempt to retrieve the granted certificate using TFTP using the same filename and the file name appended with “.crt” extension. |
|
| 7. | (Optional) Display the Trustpoint summary. Example:
|
|
| 8. | (Optional) Display the content of the certificates that are created for a Trustpoint. Example:
|
Import the PKCS12 format certificates from the TFTP server (CLI)
Procedure
| 1. | Import the PKCS12 format certificate from the TFTP server. Example:
Example:
|
|
| 2. | (Optional) Display the Trustpoint summary. Example:
|
|
| 3. | (Optional) Display the content of the certificates created for a Trustpoint. Example:
Example:
|
Configure radio interface for workgroup bridges (CLI)
Procedure
| 1. | Configure a radio interface as root AP. Example:
Example:
Maps a radio interface as root AP.
|
|
| 2. | Configure the WLAN at the root AP mode radio. Example:
Example:
Enter the SSID profile name and SSID number between 1 and 16. Value can be 0 or 1. |
|
| 3. | Delete WLAN from the radio configuration. Example:
Enter the SSID profile name. Value can be 0 or 1. |
|
| 4. | Configure a radio channel to broadcast the SSID. Example:
Example:
The channel numbers are between 1 and 173. The channel width values are 20, 40, 80, and 160.
|
|
| 5. | Configure the periodic beacon interval in milliseconds. Example:
The value range is from 2 to 2000 milliseconds. |
|
| 6. | Map a radio interface to a WGB SSID profile. Example:
|
|
| 7. | Map a radio interface to a UWGB SSID profile. Example:
|
|
| 8. | Configure a radio interface. Example:
After configuring the uplink to the SSID profile, we recommend that you disable and enable the radio for the changes to be active. |
|
| 9. | Configure a radio antenna. Example:
|
|
| 10. | Configure the radio interface encryption mode. Example:
|
|
| 11. | Configure the device channel rate. Example:
|
|
| 12. | Configure the threshold duration and signal strength to trigger scanning. Example:
|
|
| 13. | Configure the static roaming channel. Example:
|
|
| 14. | (Optional) Delete the mobile channel. Example:
|
|
| 15. | (Optional) Disable the mobile channel. Example:
|
|
| 16. | (Optional) Configure the beacon miss-count. Example:
|
|
| 17. | (Optional) Display the Wi-Fi station statistics. Example:
|
|
| 18. | (Optional) Display the radio antenna statistics. Example:
|
|
| 19. | (Optional) Display the mobile station channels scan configuration. Example:
|
|
| 20. | (Optional) Display the configuration that is stored in the NV memory. Example:
|
|
| 21. | (Optional) Display the running configuration in the device. Example:
|
Configure workgroup bridge timeouts (CLI)
Use this task to configure various timeout values that control workgroup bridge (WGB) behavior, improving reliability and performance.
-
Set specific timeout limits for association, authentication, EAP, DHCP response, and channel scan processes.
Timeout values affect how long the WGB waits for events before triggering corrective actions or failure notices.
This task applies to Cisco devices in environments where precise timeout management is needed for workgroup bridge operations and troubleshooting.
Before you begin
Ensure you have privileged EXEC access on the device.
-
Verify device compatibility and active WGB configuration.
Procedure
| 1. | Configure the WGB association response timeout. Example:
The valid range is 300 to 5000 milliseconds. The default value is 5000 milliseconds. |
|
| 2. | Configure the WGB authentication response timeout. Example:
The valid range is 300 to 5000 milliseconds. The default value is 5000 milliseconds. |
|
| 3. | Configure the Universal WGB client response timeout. Example:
The valid range is 1 to 65535 seconds. The default value is 60 seconds. |
|
| 4. | Configure the WGB EAP timeout. Example:
The valid range is 2 to 60 seconds. The default value is 3 seconds. |
|
| 5. | Configure the WGB channel scan timeout. Example:
Select scan speed according to site requirements. |
|
| 6. | Configure the WGB DHCP response timeout. Example:
The valid range is 1000 to 60000 milliseconds. The default value is 60 seconds. |
|
| 7. | Display the WGB association summary. Example:
Display associated WGB clients and related statistics. |
The configured timeout parameters apply immediately and affect how the WGB responds to events and failures.
For example, to set the WGB association response timeout to 4000 milliseconds:
Device# configure wgb association response timeout 4000
What to do next
Verify timeout settings by using display commands and monitoring WGB behavior.
-
Adjust timeouts as needed for specific network or client stability.
Configure bridge forwarding for workgroup bridge (CLI)
Before you begin
The Cisco Wave 2 and 11AX APs as Workgroup Bridge recognizes the Ethernet clients only when the traffic has the bridging tag.
We recommend setting the WGB bridge client timeout value to default value of 300 seconds, or less in environment where change is expected, such as:
-
Ethernet cable is unplugged and plugged back.
-
Endpoint is changed.
-
Endpoint IP is changed (static to DHCP and vice versa).
If you need to retain the client entry in the WGB table for a longer duration, we recommend you increase the client WGB bridge timeout duration.
Procedure
| 1. | Add a WGB client using the MAC address. Example:
Example:
|
|
| 2. | Configure the WGB bridge client timeout. Default timeout value is 300 seconds. The valid range is from 10 to 1000000 seconds. Example:
Example:
|
|
| 3. | Display the WGB wired clients over the bridge. Example:
|
|
| 4. | Display the WGB Gigabit wired clients over the bridge. Example:
Example:
|
|
| 5. | Display the WGB bridge radio interface summary. Example:
Example:
|