-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Justin Hao wrote:
> 1.  If an outiside/foreign OTAP capable ap receives a list of
> your controllers from one of your OTAP capable aps, that foreign
> ap can and will attempt to associate to your controller.  unless
> your controller has otap disabled, or you have configured
> whitelist/blacklist, your controller *will* allow the ap to
> associate and download code/configuration.

Just to note, but not directly related to this OTAP issue, the
access point authorization feature (whitelist APs) is a bit of a
dark art, but works well enough.

It involves setting up a RADIUS server using the wire-side MAC
address of the AP as both the username and password. Configure the
RADIUS server by ticking the "Network User" box in the WLC interface
(obviously!).

For other RADIUS servers have the "Network User" un-ticked, and also
take care not to mix up with those servers used for WPA Enterprise,
otherwise the MAC address becomes a valid account on the network.

HTH,

- --
Oliver Gorwits, Network and Telecommunications Group,
Oxford University Computing Services
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iD8DBQFKlCPh2NPq7pwWBt4RAqt5AKCxeBa+U71fpZ78Uv/Gn0EKSD5FlACg0XtZ
7X4rwjSxZtHjzwjXpuF4ILQ=
=WAXt
-----END PGP SIGNATURE-----

**********
Participation and subscription information for this EDUCAUSE Constituent Group 
discussion list can be found at http://www.educause.edu/groups/.

Reply via email to