Wireless/Redundant Edge Services xl Module Management and Configuration Guide WS.02.xx and greater

Table Of Contents
1-82
Introduction
Layer 2 and Layer 3 Roaming Between RPs and Modules
However, Wireless Edge Services xl Modules supports these mechanisms to
facilitate and speed roaming between RPs adopted by different modules:
PMK caching—enables fast roaming back to a module in a WLAN that
requires WPA/WPA2 with 802.1X.
A station disassociates from one of the module’s RPs and moves to an RP
on a different module. As far as the first module knows, the station has
left the WLAN. However, the module stores the stations PMK. If the
station returns to an RP on the first module, the key is ready, and the
station can quickly connect.
Pre-authentication—enables fast roaming for the first time to a module
in a WLAN that requires WPA/WPA2 with 802.1X.
PMK caching speeds roaming only if the Wireless Edge Services xl Module
already has a PMK for the station. To create this PMK, the station must
complete 802.1X authentication. Traditionally, 802.1X authentication
occurs only when the station actually associates to one of the module’s
RPs. To speed roaming, the station can complete 802.1X authentication
to a module in advance before roaming. The module caches the PMK until
the station actually roams to it.
Redundancy groups—enables fast and seamless roaming between mod-
ules in a WLAN that requires Web-Auth.
The Wireless Edge Services xl Modules that compose a redundancy group
exchange various messages. Some of these messages can include Web-
Auth usernames and passwords. When a user enters his or her username
and password into a Web-Auth login screen, the module enforcing Web-
Auth retrieves these login credentials and submits them to a RADIUS
server. The module also sends the credentials to all other members of the
redundancy group. The other members submit the credentials to the
RADIUS server and log in the user. When the user’s station roams to an
RP on a new module, the module has already authorized it to forward
traffic, so the roam is fast and seamless.
Note Pre-authentication functions only between two Wireless Edge Services xl
Modules that are on the same VLAN. In fact, roaming between modules on
different VLANs requires special configurations discussed in the next section.
For more information about these mechanisms, see Chapter 9: Fast Layer 2
Roaming and Layer 3 Mobility and Chapter 4: Wireless Local Area Networks
(WLANs).