
12-16
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 12 Configuring Hybrid REAPWireless Device Access
Configuring Hybrid-REAP Groups
Configuring Hybrid-REAP Groups
In order to better organize and manage your hybrid-REAP access points, you can create hybrid-REAP
groups and assign specific access points to them. All of the hybrid-REAP access points in a group share
the same CCKM, WLAN, and backup RADIUS server configuration information. This feature is helpful
if you have multiple hybrid-REAP access points in a remote office or on the floor of a building and you
want to configure them all at once. For example, you can configure a backup RADIUS server for a
hybrid-REAP group rather than having to configure the same server on each access point. Figure 12-9
illustrates a typical hybrid-REAP group deployment with a backup RADIUS server in the branch office.
Figure 12-9 Hybrid-REAP Group Deployment
This feature is also required for CCKM fast roaming to work with hybrid-REAP access points. CCKM
fast roaming is achieved by caching a derivative of the master key from a full EAP authentication so that
a simple and secure key exchange can occur when a wireless client roams to a different access point.
This feature prevents the need to perform a full RADIUS EAP authentication as the client roams from
one access point to another. The hybrid-REAP access points need to obtain the CCKM cache information
for all the clients that might associate so they can process it quickly instead of sending it back to the
controller. If, for example, you have a controller with 300 access points and 100 clients that might
associate, sending the CCKM cache for all 100 clients is not practical. If you create a hybrid-REAP
group comprising a limited number of access points (for example, you create a group for four access
points in a remote office), the clients roam only among those four access points, and the CCKM cache
is distributed among those four access points only when the clients associate to one of them.
Note CCKM fast roaming among hybrid-REAP and non-hybrid-REAP access points is not supported. Refer
to the “WPA1 and WPA2” section on page 6-18 for information on configuring CCKM.
Per controller, you can configure up to 20 hybrid-REAP groups with up to 25 access points per group.
Follow the instructions in this section to configure hybrid-REAP groups using the controller GUI or CLI.
Backup RADIUS
server
WAN link
Branch
802.1x
DHCP server
VLAN 101
Local VLAN
Local switch
231941
Trunk port
native VLAN 100
Trunk port
native VLAN 100
Hybrid-REAP Access Points
Komentarze do niniejszej Instrukcji