AP Profile
Catalyst CenterLocation in GUI:
Design » Network Settings » Wireless » AP Profiles
Diagram
Section titled “Diagram”Classes
Section titled “Classes”wireless (catalyst_center)
Section titled “wireless (catalyst_center)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| ap_profiles | List | [ap_profiles] | No |
ap_profiles (catalyst_center.wireless)
Section titled “ap_profiles (catalyst_center.wireless)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| name | String | max: 32 | Yes | |
| description | String | max: 241 | No | |
| remote_worker_enabled | Boolean | true, false | No | false |
| auth_type | Choice | NO-AUTH, EAP-TLS, EAP-PEAP, EAP-FAST | No | NO-AUTH |
| dot1x_username | String | min: 1, max: 32 | No | |
| dot1x_password | String | max: 120 | No | |
| dot1x_password_version | Integer | min: 1 | No | |
| ssh_enabled | Boolean | true, false | No | false |
| telnet_enabled | Boolean | true, false | No | false |
| management_user_name | String | min: 1, max: 32 | No | |
| management_password | String | min: 8, max: 120 | No | |
| management_password_version | Integer | min: 1 | No | |
| management_enable_password | String | min: 8, max: 120 | No | |
| management_enable_password_version | Integer | min: 1 | No | |
| cdp_state | Boolean | true, false | No | false |
| awips_enabled | Boolean | true, false | No | false |
| awips_forensic_enabled | Boolean | true, false | No | false |
| rogue_detection | Boolean | true, false | No | false |
| rogue_detection_min_rssi | Integer | min: -128, max: -70 | No | -90 |
| rogue_detection_transient_interval | Integer | No | 0 | |
| rogue_detection_report_interval | Integer | min: 10, max: 300 | No | 10 |
| pmf_denial_enabled | Boolean | true, false | No | false |
| mesh_enabled | Boolean | true, false | No | false |
| bridge_group_name | String | max: 10 | No | |
| backhaul_client_access | Boolean | true, false | No | |
| range | Integer | min: 150, max: 132000 | No | |
| ghz5_backhaul_data_rates | Choice | auto, 802.11abg, 802.11ac, 802.11ax, 802.11n | No | |
| ghz24_backhaul_data_rates | Choice | auto, 802.11abg, 802.11ax, 802.11n | No | |
| rap_downlink_backhaul | Choice | 5 GHz, 2.4 GHz | No | |
| power_profile | String | No | ||
| calendar_power_profiles | List | [calendar_power_profiles] | No | |
| country_code | Choice | AF, AE, AL, AR, AT, AO, AU, BD, BA, BB, BE, BG, BH, BM, BN, BO, BR, BT, BY, CA, CD, CH, CI, CL, CM, CN, CO, CR, CU, CY, CZ, DE, DK, DO, DZ, EC, EE, EG, EL, ES, ET, FI, FJ, FR, GB, GH, GI, GE, GR, GT, HK, HN, HR, HU, ID, IE, IL, IN, IQ, IS, IT, J2, J4, JM, JO, KE, KH, KN, KW, KZ, LA, LB, LI, LK, LT, LU, LV, LY, MA, MC, MD, ME, MK, MN, MM, MO, MT, MX, MY, NG, NI, NL, NO, NP, NZ, OM, PA, PE, PH, PK, PL, PR, PT, PY, QA, RO, RS, RU, SA, SD, SE, SG, SI, SK, SM, TH, TI, TN, TR, TW, TZ, UA, US, UY, VA, VE, VN, XK, YE, ZA, ZW, MU, ZM, BI, NA, BW, GA, UG, UZ | No | |
| time_zone | Choice | Not Configured, Controller, Delta from Controller | No | Not Configured |
| time_zone_offset_hour | Integer | min: -12, max: 14 | No | 0 |
| time_zone_offset_minutes | Integer | min: 0, max: 59 | No | 0 |
| client_limit | Integer | min: 0, max: 1200 | No | 0 |
calendar_power_profiles (catalyst_center.wireless.ap_profiles)
Section titled “calendar_power_profiles (catalyst_center.wireless.ap_profiles)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| power_profile | String | Yes | ||
| scheduler_type | Choice | DAILY, WEEKLY, MONTHLY | Yes | |
| scheduler_start_time | String | Yes | ||
| scheduler_end_time | String | Yes | ||
| scheduler_day | List | Choice[monday, tuesday, wednesday, thursday, friday, saturday, sunday] | No | |
| scheduler_date | List | Choice[1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31] | No |
AP Profiles define device-level settings for Access Points including management access (802.1X, SSH, Telnet, CDP), security features (AWIPS, rogue detection), mesh networking, power management, and client limits. They are linked to Wireless Network Profiles via Site Tags and are applicable to both SDA fabric and non-fabric deployments.
Examples
Section titled “Examples”Example-1: AP Profile with AWIPS and Rogue Detection
Section titled “Example-1: AP Profile with AWIPS and Rogue Detection”AP profile with AWIPS threat detection and rogue detection enabled for secure environments.
catalyst_center: wireless: ap_profiles: - name: SECURE_AP_PROFILE description: Secure AP profile with threat detection awips_enabled: true awips_forensic_enabled: true rogue_detection: true rogue_detection_min_rssi: -90 rogue_detection_transient_interval: 300 rogue_detection_report_interval: 60 pmf_denial_enabled: trueExample-2: AP Profile with Mesh and Calendar Power Scheduling
Section titled “Example-2: AP Profile with Mesh and Calendar Power Scheduling”AP profile with mesh networking and calendar-based power scheduling for outdoor deployments.
catalyst_center: wireless: ap_profiles: - name: MESH_OUTDOOR_PROFILE description: Outdoor mesh AP profile with power scheduling mesh_enabled: true bridge_group_name: OUTDOOR backhaul_client_access: true range: 5000 ghz5_backhaul_data_rates: 802.11ac rap_downlink_backhaul: "5 GHz" power_profile: LOW_POWER calendar_power_profiles: - power_profile: NIGHT_POWER_SAVE scheduler_type: DAILY scheduler_start_time: "22:00" scheduler_end_time: "06:00" country_code: US time_zone: ControllerNote: AP Profiles define device-level settings for Access Points. They are linked to Wireless Network Profiles via Site Tags (
catalystcenter_wireless_profile_site_tag), not directly to the Wireless Profile resource. Usepower_profilefor the always-on AP power profile name andpower_profileon eachcalendar_power_profilesrow for the scheduled profile (names must match profiles undercatalyst_center.wireless.power_profiles). The Terraform provider maps these to its API attributes internally.
Example-3: AP Profile with 802.1X Linked via Site Tag
Section titled “Example-3: AP Profile with 802.1X Linked via Site Tag”AP profile with 802.1X authentication linked to a Wireless Network Profile via a Site Tag.
catalyst_center: wireless: ap_profiles: - name: DOT1X_AP_PROFILE description: AP profile with 802.1X authentication auth_type: EAP-TLS ssh_enabled: true management_user_name: admin management_password: AdminPass123 management_enable_password: EnablePass123 cdp_state: true client_limit: 500 time_zone: Controller network_profiles: wireless: - name: ENTERPRISE_WIRELESS ssid_details: - name: CORPORATE_SSID enable_fabric: true sites: - Global/HQ/Building_A - Global/HQ/Building_B site_tags: - name: HQ_SECURE_TAG ap_profile_name: DOT1X_AP_PROFILE sites: - Global/HQ/Building_A - Global/HQ/Building_BExample-4: Comprehensive AP Profile with Mesh, 802.1X, and Rogue Detection
Section titled “Example-4: Comprehensive AP Profile with Mesh, 802.1X, and Rogue Detection”Comprehensive AP profile with mesh networking, 802.1X authentication, rogue detection, calendar-based monthly power scheduling, and timezone offset.
catalyst_center: wireless: ap_profiles: - name: COMPREHENSIVE_AP_PROFILE description: "AP configuration" remote_worker_enabled: false auth_type: EAP-FAST dot1x_username: "apuser" dot1x_password: "secret123" ssh_enabled: true telnet_enabled: false management_user_name: "admin" management_password: "secret123" management_enable_password: "enable123" cdp_state: false awips_enabled: false awips_forensic_enabled: false rogue_detection: true rogue_detection_min_rssi: -90 rogue_detection_transient_interval: 0 rogue_detection_report_interval: 10 pmf_denial_enabled: false mesh_enabled: true bridge_group_name: "Default" backhaul_client_access: true range: 12000 ghz5_backhaul_data_rates: 802.11ax ghz24_backhaul_data_rates: 802.11n rap_downlink_backhaul: "2.4 GHz" calendar_power_profiles: - power_profile: "moderate_power_profile" scheduler_type: MONTHLY scheduler_start_time: "18:00" scheduler_end_time: "08:00" scheduler_date: - "1" - "2" - "3" - "4" - "5" - "6" - "7" - "8" - "9" - "10" - "11" - "12" - "13" - "14" country_code: IN time_zone: Delta from Controller time_zone_offset_hour: 5 time_zone_offset_minutes: 30 client_limit: 200Example-5: Write-Only AP Profile Secrets
Section titled “Example-5: Write-Only AP Profile Secrets”Opt an AP profile’s dot1x_password, management_password, and management_enable_password into Terraform’s write-only handling so they are never persisted to Terraform state (requires Catalyst Center provider 0.6.1+ and Terraform 1.11+). See Device Credentials for the full write-only mechanism — declaring a <secret>_version key next to a secret opts it in, and bumping that integer tells Terraform to resend a changed value. Each of the three secrets has its own independent version.
catalyst_center: wireless: ap_profiles: - name: DOT1X_AP_PROFILE_WO description: AP profile with write-only secrets auth_type: EAP-TLS dot1x_username: apuser dot1x_password: secret123 dot1x_password_version: 1 # bump alongside `dot1x_password` to rotate it ssh_enabled: true management_user_name: admin management_password: AdminPass123 management_password_version: 1 # bump alongside `management_password` to rotate it management_enable_password: EnablePass123 management_enable_password_version: 1 # bump alongside `management_enable_password` to rotate itLocation in GUI:
Design » Network Settings » Wireless » AP Profiles
Diagram
Section titled “Diagram”Classes
Section titled “Classes”wireless (catalyst_center)
Section titled “wireless (catalyst_center)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| ap_profiles | List | [ap_profiles] | No |
ap_profiles (catalyst_center.wireless)
Section titled “ap_profiles (catalyst_center.wireless)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| name | String | max: 32 | Yes | |
| description | String | max: 241 | No | |
| remote_worker_enabled | Boolean | true, false | No | false |
| auth_type | Choice | NO-AUTH, EAP-TLS, EAP-PEAP, EAP-FAST | No | NO-AUTH |
| dot1x_username | String | min: 1, max: 32 | No | |
| dot1x_password | String | max: 120 | No | |
| ssh_enabled | Boolean | true, false | No | false |
| telnet_enabled | Boolean | true, false | No | false |
| management_user_name | String | min: 1, max: 32 | No | |
| management_password | String | min: 8, max: 120 | No | |
| management_enable_password | String | min: 8, max: 120 | No | |
| cdp_state | Boolean | true, false | No | false |
| awips_enabled | Boolean | true, false | No | false |
| awips_forensic_enabled | Boolean | true, false | No | false |
| rogue_detection | Boolean | true, false | No | false |
| rogue_detection_min_rssi | Integer | min: -128, max: -70 | No | -90 |
| rogue_detection_transient_interval | Integer | No | 0 | |
| rogue_detection_report_interval | Integer | min: 10, max: 300 | No | 10 |
| pmf_denial_enabled | Boolean | true, false | No | false |
| mesh_enabled | Boolean | true, false | No | false |
| bridge_group_name | String | max: 10 | No | |
| backhaul_client_access | Boolean | true, false | No | |
| range | Integer | min: 150, max: 132000 | No | |
| ghz5_backhaul_data_rates | Choice | auto, 802.11abg, 802.11ac, 802.11ax, 802.11n | No | |
| ghz24_backhaul_data_rates | Choice | auto, 802.11abg, 802.11ax, 802.11n | No | |
| rap_downlink_backhaul | Choice | 5 GHz, 2.4 GHz | No | |
| power_profile | String | No | ||
| calendar_power_profiles | List | [calendar_power_profiles] | No | |
| country_code | Choice | AF, AE, AL, AR, AT, AO, AU, BD, BA, BB, BE, BG, BH, BM, BN, BO, BR, BT, BY, CA, CD, CH, CI, CL, CM, CN, CO, CR, CU, CY, CZ, DE, DK, DO, DZ, EC, EE, EG, EL, ES, ET, FI, FJ, FR, GB, GH, GI, GE, GR, GT, HK, HN, HR, HU, ID, IE, IL, IN, IQ, IS, IT, J2, J4, JM, JO, KE, KH, KN, KW, KZ, LA, LB, LI, LK, LT, LU, LV, LY, MA, MC, MD, ME, MK, MN, MM, MO, MT, MX, MY, NG, NI, NL, NO, NP, NZ, OM, PA, PE, PH, PK, PL, PR, PT, PY, QA, RO, RS, RU, SA, SD, SE, SG, SI, SK, SM, TH, TI, TN, TR, TW, TZ, UA, US, UY, VA, VE, VN, XK, YE, ZA, ZW, MU, ZM, BI, NA, BW, GA, UG, UZ | No | |
| time_zone | Choice | Not Configured, Controller, Delta from Controller | No | Not Configured |
| time_zone_offset_hour | Integer | min: -12, max: 14 | No | 0 |
| time_zone_offset_minutes | Integer | min: 0, max: 59 | No | 0 |
| client_limit | Integer | min: 0, max: 1200 | No | 0 |
calendar_power_profiles (catalyst_center.wireless.ap_profiles)
Section titled “calendar_power_profiles (catalyst_center.wireless.ap_profiles)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| power_profile | String | Yes | ||
| scheduler_type | Choice | DAILY, WEEKLY, MONTHLY | Yes | |
| scheduler_start_time | String | Yes | ||
| scheduler_end_time | String | Yes | ||
| scheduler_day | List | Choice[monday, tuesday, wednesday, thursday, friday, saturday, sunday] | No | |
| scheduler_date | List | Choice[1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31] | No |
AP Profiles define device-level settings for Access Points including management access (802.1X, SSH, Telnet, CDP), security features (AWIPS, rogue detection), mesh networking, power management, and client limits. They are linked to Wireless Network Profiles via Site Tags and are applicable to both SDA fabric and non-fabric deployments.
Examples
Section titled “Examples”Example-1: AP profile with AWIPS threat detection and rogue detection enabled for secure environments:
catalyst_center: wireless: ap_profiles: - name: SECURE_AP_PROFILE description: Secure AP profile with threat detection awips_enabled: true awips_forensic_enabled: true rogue_detection: true rogue_detection_min_rssi: -90 rogue_detection_transient_interval: 300 rogue_detection_report_interval: 60 pmf_denial_enabled: trueExample-2: AP profile with mesh networking and calendar-based power scheduling for outdoor deployments:
catalyst_center: wireless: ap_profiles: - name: MESH_OUTDOOR_PROFILE description: Outdoor mesh AP profile with power scheduling mesh_enabled: true bridge_group_name: OUTDOOR backhaul_client_access: true range: 5000 ghz5_backhaul_data_rates: 802.11ac rap_downlink_backhaul: "5 GHz" power_profile: LOW_POWER calendar_power_profiles: - power_profile: NIGHT_POWER_SAVE scheduler_type: DAILY scheduler_start_time: "22:00" scheduler_end_time: "06:00" country_code: US time_zone: ControllerNote: AP Profiles define device-level settings for Access Points. They are linked to Wireless Network Profiles via Site Tags (
catalystcenter_wireless_profile_site_tag), not directly to the Wireless Profile resource. Usepower_profilefor the always-on AP power profile name andpower_profileon eachcalendar_power_profilesrow for the scheduled profile (names must match profiles undercatalyst_center.wireless.power_profiles). The Terraform provider maps these to its API attributes internally.
Example-3: AP profile with 802.1X authentication linked to a Wireless Network Profile via a Site Tag:
catalyst_center: wireless: ap_profiles: - name: DOT1X_AP_PROFILE description: AP profile with 802.1X authentication auth_type: EAP-TLS ssh_enabled: true management_user_name: admin management_password: AdminPass123 management_enable_password: EnablePass123 cdp_state: true client_limit: 500 time_zone: Controller network_profiles: wireless: - name: ENTERPRISE_WIRELESS ssid_details: - name: CORPORATE_SSID enable_fabric: true sites: - Global/HQ/Building_A - Global/HQ/Building_B site_tags: - name: HQ_SECURE_TAG ap_profile_name: DOT1X_AP_PROFILE sites: - Global/HQ/Building_A - Global/HQ/Building_BExample-4: Comprehensive AP profile with mesh networking, 802.1X authentication, rogue detection, calendar-based monthly power scheduling, and timezone offset:
catalyst_center: wireless: ap_profiles: - name: COMPREHENSIVE_AP_PROFILE description: "AP configuration" remote_worker_enabled: false auth_type: EAP-FAST dot1x_username: "apuser" dot1x_password: "secret123" ssh_enabled: true telnet_enabled: false management_user_name: "admin" management_password: "secret123" management_enable_password: "enable123" cdp_state: false awips_enabled: false awips_forensic_enabled: false rogue_detection: true rogue_detection_min_rssi: -90 rogue_detection_transient_interval: 0 rogue_detection_report_interval: 10 pmf_denial_enabled: false mesh_enabled: true bridge_group_name: "Default" backhaul_client_access: true range: 12000 ghz5_backhaul_data_rates: 802.11ax ghz24_backhaul_data_rates: 802.11n rap_downlink_backhaul: "2.4 GHz" calendar_power_profiles: - power_profile: "moderate_power_profile" scheduler_type: MONTHLY scheduler_start_time: "18:00" scheduler_end_time: "08:00" scheduler_date: - "1" - "2" - "3" - "4" - "5" - "6" - "7" - "8" - "9" - "10" - "11" - "12" - "13" - "14" country_code: IN time_zone: Delta from Controller time_zone_offset_hour: 5 time_zone_offset_minutes: 30 client_limit: 200