2015年8月4日火曜日

AOS: RAP password based

How to configure password-based RAP's configuration

Step1: setting isakmp key on controller
crypto isakmp key aruba123 address 0.0.0.0 netmask 0.0.0.0

Step2: setting password for each AP on controller
local-userdb add username kuro password aruba123 remote-ip 4.4.4.1 role ap-role

!provision-ap copy-provisioning-params ap-name "6c:f3:7f:cb:61:a6"

Step3: setting APs for RAP. AP needs to be connected to controller once based on CAP at least.

conf t
provision-ap
read-bootinfo  ap-name "6c:f3:7f:cb:61:a6"
pap-user "kuro"
pap-passwd "aruba123"
ikepsk "aruba123"
master 10.215.107.126
server-ip 10.215.107.126
ap-group "TK-BP"
ap-name "RAP-1"
remote-ap
show provisioning-params
reprovision ap-name "6c:f3:7f:cb:61:a6"

Step4: logging function

logging level debugging arm
logging level debugging arm subcat client-match
logging level debugging network process dhcpd
logging level informational network
logging level debugging network subcat dhcp
logging level debugging security process authmgr
logging level debugging security process crypto
logging level debugging security
logging level debugging security subcat aaa
logging level debugging security subcat ike
logging level debugging system process stm
logging level informational system
logging level debugging system process stm subcat ap
logging level debugging user
logging level debugging user subcat client-match
logging level informational wireless