Cisco Catalyst IW9167E Heavy Duty Access Point Configuration Guide, Release 26.1.x

PDF

Cisco Catalyst IW9167E Heavy Duty Access Point Configuration Guide, Release 26.1.x

Configure and authenticate wireless profiles

Want to summarize with AI?

Log in

Learn how wireless profiles provide a pre-configured set of network settings to enable secure, consistent, and automated wireless connections, and describes the process for configuring secure wireless access using 802.1X authentication.


A wireless profile is a pre-configured set of network settings that enables devices to connect to a wireless network automatically and securely.

  • Allows devices to connect automatically without manual reconfiguration.

  • Stores network details such as SSID, security type, encryption method, and passphrase.

  • Minimizes credential entry errors and ensures secure, consistent connections.

  • Simplifies distribution and management of network settings across multiple devices.

  • Enables easy switching between saved networks (for example, home, office, or public Wi-Fi).

Configuring secure wireless access using 802.1X authentication

To configure secure wireless access using 802.1X authentication, complete these tasks:


Create a WLAN

This procedure describes how to create a WLAN.

You can create Wireless Local Area Network (WLAN) to provide wireless connectivity within a specific area, enabling devices to connect to the network without physical cables. WLANs enhance mobility by allowing users to move freely within the network's coverage area while maintaining connectivity. They reduce the need for extensive cabling, simplifies setup, and lower costs.

Before you begin

Configure Extensible Authentication Protocol (EAP), if you access multiple SSID.

Procedure

1.

Choose Profile > WLAN .

2.

Click Create .

3.

Select Authentication in WLAN Profile Configurations .

The Authentication types are:

  • Open : It provides access to networks without a password.

  • OWE : Opportunistic Wireless Encryption (OWE) provides automatic encryption for open networks without a password.

  • PSK : Pre-Shared Key (PSK) secures networks using a shared password for authentication and encryption.

  • SAE : Simultaneous Authentication of Equals (SAE) secures networks with strong password-based authentication and encryption.

  • EAP : Extensible Authentication Protocol (EAP) supports various authentication methods.

    You can configure EAP in WLAN either in Default EAP Profile or EAP Profile List . For details on EAP Profile configuration, see Create EAP profile .

    To select the EAP Profile List , you need to provide t Username , Password , and Key Management information. For more details, see Map EAP profile to SSID .

4.

Update the required Key Management details based on Authentication .

The Key Management types are:

  • dot11r : 802.11r (Fast Transition)

  • dot11w : 802.11w (Protected Management Frames)

  • WPA2 : secures Wi-Fi with AES encryption.

  • WAP3 : enhances Wi-Fi with stronger encryption and password security.

5.

Click Update & apply to device .


Create 802.1X profile

You can use a 802.1X Profile to define authentication settings for IEEE 802.1X, enabling secure, controlled, and authenticated network access for users and devices.

Perform these steps to create 802.1X profile.

Procedure

1.

Choose Profile > EAP.

2.

Click Create in DOT1x PROFILE area.

3.

Enter Dot1x Profile Name, Username and Password.

4.

Click Update & Apply to Device.


EAP profiles and SSID maps

You can use EAP profiles to define secure authentication methods (example: Protected Extensible Authentication Protocol (PEAP), Extensible Authentication Protocol - Transport Layer Security (EAP-TLS)) for validating users or devices on a wireless network. Similarly, you can configure SSID maps to associate network names (SSIDs) with specific policies, VLANs, or EAP profiles. Together, they ensure secure access, proper segmentation, and efficient network management.


Create EAP profile

To securely authenticate users and devices in networks, EAP is required as it provides robust access control and data protection. EAP is essential for IIoT ecosystems that require scalable and secure device authentication. It offers flexibility and multiple authentication methods, which are critical for network security and safeguarding sensitive data.

Before you begin

Configure 802.1x profile. For more details see, Create 802.1X profile.

Perform these steps to create EAP profile.

Procedure

1.

Choose Profile > EAP.

2.

Click Create in EAP PROFILE area.

3.

Update the Profile Name, EAP Method and Dot1x Credential Profile in EAP Profile Configurations .

4.

Click Update & Apply to Device.


Map EAP profile to SSID

Mapping the Extensible Authentication Protocol (EAP) to an Service Set Identifier (SSID) provides secure and authenticated access for devices connecting to the wireless network.

Perform these steps to map EAP profile to SSID.

Procedure

1.

Choose Profile > WLAN.

2.

Click Create.

3.

Update Profile Name and DTIM Period.

4.

Select EAP in Authentication.

5.

Select the Profile Name provided while creating the EAP in EAP Profile from the drop-down.

6.

Select Key Management from the drop-down.

7.

Click Update & apply to device.


Procedure

1.

From the Network page, choose the desired uplink radio in Wireless Interface.

2.

Select the WLAN to be mapped from the WLAN Profile drop-down.

3.

Select WGB in Radio Mode .

4.

Click Update & apply to device .