4. Create virtual APs (VAPs) and deliver VAP parameters so that STAs access different
WLANs by using different security policies.
Procedure
Step 1 Enable 802.1x authentication and configure AAA globally.
l Enable 802.1x authentication.
<Huawei> system-view
[Huawei] dot1x enable
l Configure AAA.
# Set the IP address of the RADIUS server to 10.137.146.163 and set the shared key to
huawei.
[Huawei] radius-server template peap.radius.com
[Huawei-radius-peap.radius.com] radius-server authentication 10.137.146.163
1812
[Huawei-radius-peap.radius.com] radius-server accounting 10.137.146.163 1813
[Huawei-radius-peap.radius.com] radius-server shared-key simple huawei
[Huawei-radius-peap.radius.com] quit
# Configure the authentication mode, accounting mode, and domain.
[Huawei] aaa
[Huawei-aaa] authentication-scheme radius
[Huawei-aaa-authen-radius] authentication-mode radius
[Huawei-aaa-authen-radius] quit
[Huawei-aaa] accounting-scheme radius
[Huawei-aaa-accounting-radius] accounting-mode radius
[Huawei-aaa-accounting-radius] quit
[Huawei-aaa] domain peap.radius.com
[Huawei-aaa-domain-peap.radius.com] radius-server peap.radius.com
[Huawei-aaa-domain-peap.radius.com] authentication-scheme radius
[Huawei-aaa-domain-peap.radius.com] accounting-scheme radius
[Huawei-aaa-domain-peap.radius.com] quit
[Huawei-aaa] quit
Step 2 Create security profiles: security-1, security-2, security-3, security-4, and security-5.
[Huawei] wlan
[Huawei-wlan-view] security-profile name security-1
[Huawei-wlan-sec-prof-security-1] quit
[Huawei-wlan-view] security-profile name security-2
[Huawei-wlan-sec-prof-security-2] quit
[Huawei-wlan-view] security-profile name security-3
[Huawei-wlan-sec-prof-security-3] quit
[Huawei-wlan-view] security-profile name security-4
[Huawei-wlan-sec-prof-security-4] quit
[Huawei-wlan-view] security-profile name security-5
[Huawei-wlan-sec-prof-security-5] quit
Step 3 Configure security profiles for WLAN users.
l Configure a security policy for security profile security-1.
# Configure WEP open system authentication.
[Huawei-wlan-view] security-profile name security-1
[Huawei-wlan-sec-prof-security-1] wep authentication-method open-system
[Huawei-wlan-sec-prof-security-1] security-policy wep
[Huawei-wlan-sec-prof-security-1] quit
l Configure a security policy for security profile security-2.
# Configure WEP shared key authentication, WEP-40 encryption, and key phrase 12345.
[Huawei-wlan-view] security-profile name security-2
[Huawei-wlan-sec-prof-security-2] wep authentication-method share-key
[Huawei-wlan-sec-prof-security-2] wep key wep-40 pass-phrase 0 12345
[Huawei-wlan-sec-prof-security-2] wep default-key 0
Huawei AR1200 Series Enterprise Routers
Configuration Guide - WLAN 2 WLAN Security Configuration
Issue 03 (2012-01-06) Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
35