Cisco :: 1242 How To Setup Wireless Clients MAC+Active Directory Based Access

Oct 30, 2012

I want to setup Wireless Clients MAC+Active Directory based acess on AP 1242 standalone Wireless series.Steps i have configured :
 
1) SSID manger  under Open authentication : Selected with EAP.
2) under advacned Radius.MAC Address  AuthenticationMAC Addresses Authenticated by: Authentication Server Only
3) Server Manger : Current server list added the radius ip address 10.1.200.x

View 5 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: WLC 7.4 / ISE Authentication Via Active Directory Based On SSID And AD Group?

Apr 15, 2013

I am deploying ISE with WLC 7.4. I have two SSID(s) running in my network 1. Corporate & 2. Services. I have a domain setup lets say "AD.com" with 4 groups 1. Corporate, 2. Services, 3. Employees, 4. Contractors.Here is an example of the scenario that I want:
 
AD.com Group : Corporate's User : 1. C_USER1
2. C_USER2
3. C_USER3
4. C_USER4
5. C_USER5

[code]....
 
Now what I want to do is have 802.1x authentication on my Corporate SSID that will check in AD.com, ONLY AND in ONLY corporate group for authentication. That is only C_USER1 to C_USER5 are allowed to connect to it. Users from any other AD group shouldnt be authenticated on this SSID.The same for the services group & SSID.

View 2 Replies View Related

Cisco VPN :: Manage ASA 5520 (8.2.5) SSL Clients Through Active Directory?

Dec 24, 2012

We are trying to manage our Cisco ASA 5520 (8.2.5) SSL clients through Active Directory(ldap).

Currently the SSL VPN tunnel is up and all users are able to connect being authenticated by AD. but Group-policy to AD groups are not working. all the domain users are able to go to all the group policies .
 
I need to give access only to their respective Group policy in ASA.  Following are the available groups and GP.
 
Code...

View 3 Replies View Related

Cisco Firewall :: ASA 5505 - Get Clients To Talk To Active Directory Servers?

Nov 9, 2011

I'm trying to get a couple clients to talk to my Active Directory servers. I've created sub-interfaces on my ASA. So, my clients are on Gi0/1.139 and my two Active Directory servers are on Gi0/1.132. I've enabled traffic on TCP 53-5000 port range according to Microsoft. My clients still can't join the domain. What ports I need to open up? My AD servers are Windows 2003.

View 1 Replies View Related

Cisco Firewall :: ASA 5520 / Use Active Directory Groups For Allow Internet To Clients?

Dec 18, 2012

it is possible to create a Windows Active Directory group of users which I can use to permit access through the ASA (5520) firewall? I only can find vpn authentication with Radius but nog specific information about granting AD groups internet access via the ASA.

View 1 Replies View Related

Cisco Firewall :: ASA 5520 / Use Active Directory Groups For Allow Internet To Clients

Feb 21, 2012

it is possible to create a Windows Active Directory group of users which I can use to permit access through the ASA (5520) firewall? I only can find vpn authentication with Radius but nog specific information about granting AD groups internet access via the ASA.

View 1 Replies View Related

Cisco Wireless :: Max Number Of Clients For 1242 Setup As Workgroup Bridge?

Nov 14, 2012

I have Cisco 1242 setup as a work group bridge. Is there a rule of thumb on the max number of wired clients that can be connected at one time?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Setup AAA For Anyconnect With Active Directory On Asdm 6.4

Aug 20, 2012

Im sure this has been asked before but a quick search has not yielded any exact results so here goes
 
I have anyconnect up and working great on for vpn users using local authentication. Im going over the white papers and seeing a lot of options for NT domain, LDAP, tacacs+ etc
 
we would like remote vpn users to autherticate using their windows domain password, but Im not sure which would be the easiest and quickest option to configure, and I cant find a guide for asdm setup for this topic that doesnt cause more questions than answers . The white papers Im finding are confusing since I am a rookie at this topic.
 
what is the easiest/quickest way to setup windows domain authentication via asdm?

View 1 Replies View Related

Cisco :: Use Access Point 1242 To Do Clients Location Using WLC 5008 / NCS 1.1 / MSE3310

Dec 2, 2012

Can I use the access point 1242 to do clients location using WLC 5008, NCS 1.1 and MSE3310?On this moment I doesn´t need of CleanAir features. I want just to do location for clients and rogue aps.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: 1252 AP - 24427 Access To Active Directory Failed Error In ACS 5.1

Jan 2, 2011

I'm working on implementing a RADIUS authentication for wireless access with the following :
 
- PCs running Windows 7, protocol used is PEAP (without validating the server certificate to make it simple at first),

- AP 1252  configured to use a RADIUS server to authenticate (it's working good with an ACS server 4.2),

- ACS Server 5.1.0.44.5 running as VM connected to an AD domain and working good with VPN connections,

- AD domain running on Windows 2003 Server.
 
My ACS VM is working good since a couple of months for VPN (RADIUS) and administration (TACACS) remote access, both using Active Directory. Now, I'd like to use it to authenticate people connecting to a 1252 Cisco access point but I'm getting this error "24427 Access to Active Directory failed". I switched from PEAP to LEAP but this is the same.
 
All I can get running the expert troubleshoot
 
Investigating failure code: 24427 Access to Active Directory failedChecking if Active Directory is configuredActive Directory is configuredAttempting connection to Active DirectoryConnection to Active Directory was successful.Troubleshooting completed.Click on Show Results Summary to view results.
 
I followed this guide, at least for the ACS certificate section :
 
[URL]

View 27 Replies View Related

Cisco Wireless :: 1242 - Max Number Of Voice Clients On AP

May 30, 2012

I have a high school wireless environment that was installed approximately 5 years ago with 1242AG APs. The install was done based on 2.4GHz coverage everywhere, not for 5GHz or for good density. The high school uses wireless cisco 7921G phones for all the staff and teachers. The issue we're running into is over the last couple years more and more students are bringing in iPhones and android phones that can connect to the public wireless ssid. And with the increase of these wireless devices in the classroom, we've been experiencing more and more call dropped on the wireless phones. I have collected information on number of clients on specific APs that are in the area of most of the dropped calls. At times some of these APs have a total of 40 clients associated to them, over half of which are on the public ssid. I have thought about putting all the phones on to the 5GHz radios, but the implementation of the wireless was only for 2.4GHz coverage, so we have coverage gaps on the 5GHz network. We're thinking about adding more APs but the budget isn't available yet for that, so we're looking at what we can do to make this better for the time being.
 
Main questions are:
 
Is there a best practices number of max clients per AP in a wireless voice network?
 
Are there any other options for preventing dropped calls on the wireless?
 
I should mention I have already looked over the VoWLAN Troubleshooting Checklist at the link below and made the necessary changes to assure we are following the items on the checklist as close as possible.URL

View 9 Replies View Related

Cisco Wireless :: WAP4410n Authenticating To Active Directory?

Aug 22, 2011

I have a WAP4410n which I'd like to authenticate users against our corporate active directory. I would like to know how to achieve this - whether we require a dedicated RADIUS server, whether AD has a RADIUS engine which can be used, etc. Also, what would the pros / cons be of this setup versus using a WPA2 password?

View 2 Replies View Related

Cisco Wireless :: 1240AGs Active Directory Authentication Without WLSE?

Feb 28, 2013

I current have a network setup with five 1240AG access points. One is configured as a WDS. I also have a WLSE appliance. I have IAS configured on a domain controller running Cisco Secure ACS Agent. My setup works and my clients can authenticate with certificates to Active Directory. My problem is that I need to take my WLSE out of the mix - it is old and failing. I cannot afford a replacement. I know that in order to use WDS, I have to have a WLSE.
 
So my question is this. If I configure my APs so that do not participate in SWAN, and leave them setup to use EAP and point to my Windows IAS for RADIUS, running Cisco Secure Agent, will they be able to authenticate still.
 
To be honest, I set this up a long time ago and I cannot remember if the WLSE is required for domain authentication. I know if offered Domain Authentication and I have my Windows Server setup in there. So I am not sure if my APs can authenticate directly to the Windows Server without it.

View 4 Replies View Related

Cisco Wireless :: 1242 / How To Force Clients DHCP Renew On Mobility Event

Aug 24, 2011

I have a (single) client (it is a cisco IOS router) behind a wireless workgroup bridge (cisco1242).The client's IP address is obtained via DHCP from the wired network.Now, when roaming occurs, the Client will never have knowledge about this event,and hence will not renew its IP address until lease expiers. This is not a problem of course when Layer 2 roam occurs, but with Layer 3
roam it will interrupt the traffic.
 
The cisco's IP Mobile implementation does have this issue addressed in DCCoA scenario: the WGB is configured to send an SNMP trap on its dotradio state change;the cisco mobile router is configured with snmp-server manager to process this trap and start DHCP renew on the Down/Up event. Unfortunately, this works in Mobile IP scenario only because I cannot make it work without the mobile router registered with a home agent.

how to force DHCP renew on a client (cisco IOS router) in such a situation - event scripting, SLA,  or ...?

View 5 Replies View Related

Linksys Wireless Router :: Need Access E1000's Web-based Setup Page

Jan 6, 2012

I have a Linksys E1000 wireless router, and I seem to have either written down the password incorrectly or am using the wrong one. Regardless, I can not access the web-based setup for the router. Is there anyway to reset the username and password for it?

View 3 Replies View Related

AAA/Identity/Nac :: ACS 5.2 With Active Directory

Mar 7, 2011

I have installed ACS 5.2 and configured it to join the Company's Domain as an External database with Active directory 2008. I'm facing a problem that the user once authenticated using it's active directory account it's cached in the ACS and take a while for the ACS to clear this username. For example, if user TEST authenticates and then we removed this user from the AD and then tried again; it authenticates although this users is removed from the AD !!! same thing happens when we change the user group on the AD, it takes a while for the ACS to clear the old user attributes and get the new ones from the AD.
 
it there an aging time for this caching mechanism, or can i clear the dynamic users manually just like in ACS 4.X ?

View 3 Replies View Related

Cisco VPN :: SSL VPN With Active Directory On SR520

Apr 7, 2011

Having problems configuring an SR520 to support SSL VPN with Active Directory authentication. I set up the domain  and a user in the SR520. and get the login prompt remotely but when attempting to login using the active directory account i get a login error. I can login fine using local authentication.

View 5 Replies View Related

Servers :: Set Up Active Directory Without DHCP

Mar 23, 2011

I am trying to set up a small domain for my business. I just purchased a Windows 2008 server and would like to use it as my domain controller.Also, I just had a new ATT DSL line put in. It came with a 2Wire modem/4-port router/wireless router device, therefore the modem can handle DHCP. The line has a static IP address as well so that I can eventually use my own exchange server and web server.I have tried 2 different configurations and couldn't get either to work) I tried to put the router into Bridged Mode and use DHCP server on my server using a PPPoe connection to connect to the Internet. I was confused as to what my static IP address and default gateway of my server should be.2) Then I tried to turn DHCP server off on the server and routing back on the modem/router. This didn't work either.What method would you recommend and why? Also I have some additional questions on each method.

Method 1)

* What is the static IP address of the server. Is it in the 192.168.1.x address or the static IP assigned to my account?

* Do I need a second Nic Card And Router to connect to the rest of my network or can I use the router provide

* What would the Static IP addresses of the additional PC be. Do I need more than 1 static IP from AT&T Method 2)

* Will this allow me to use all internal IP addresses on my machines and use port forwarding if I want a specific box to be a web server or exchange server.

View 18 Replies View Related

Adding Computers To Active Directory?

Aug 27, 2012

I know that when you create a user account in active directory, the user's computer is also added to active directory. However, in what circumstance would you add a computer to active directory in which there are no user accounts created, or used ?For instance, my Linksys wrt54g router, on the main configuration tab has a space to name the router, which is appropriate called, "Linksys", and it has space to enter it's domain name, which if I named it, I guess it would be. LinksysRouter.**.local.Why add a router to an active directory domain ?Why add any other computer to an active directory domain with no users associated with it ?

View 11 Replies View Related

How To Implement Isa Server And Active Directory

Nov 29, 2012

I have 1 server where i enabled dhcp server and active directory on it . I still have to install something like ISA server on it as isa doesnt support 2008 r2. point me out on the networking , like how should i connect the clients to the server. And how the wireless router and switch should be connected to the server?

View 1 Replies View Related

Adding MS Office To Active Directory

Jan 26, 2011

I've got a fully working active directory with mandatory profiles. I'm looking into adding MS Office 2007. I have the disk and everything, but I'm wondering how to go about installing it. Must I go around each workstation installing it?

View 1 Replies View Related

How To Login Offsite With Active Directory

Dec 12, 2011

I've got this problem with our Operations Manager's laptop not letting him log in once he is offsite(at home). We use an Active Directory server here for all out workstations to log on to the domain but once he is offsite he cannot log in because the laptop obviously cannot find the sever to authorize the user. For now I just have him logging in locally to his laptop and not to the domain when he is offsite but this creates a problem; it makes two users/desktops for him, one user.domain and user.local. Is there a way to tell the machine locally that his username is authorized to let him log onto the domain account though it cannot connect to the domain server?

View 3 Replies View Related

Cisco :: Active Directory Authentication Failing?

Feb 16, 2012

I am not sure why but when I try to connect with my IPSEC VPN client, authentications are failing. The ldap test passes on the ASA but when I try to login, the VPN client gives me authentication failure even though debugs show authentication was successful.User 'test1' should be able to authenticate based on group membership.User 'test2' shouldn't be able to.I already removed the attribute-map to see if that was the problem but I am still failing authentication.

View 9 Replies View Related

Cisco AAA/Identity/Nac :: Active Directory And ACS 5.3 Failure?

May 21, 2012

I am receiving a RADIUS authentication failure stating user must change password; however, password has been changed in AD and is not requiring change password any longer on the AD side.
 
Is there a cache on the ACS that needs to be cleared? AD connection from ACS to domain is fine.  All other accounts authenticate.
 
It appears that if a user lets their account expire is when this happens.  Account has been reenabled in AD and password has been changed.  Still will not authenticate via ACS.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Active Directory Integration Acs 5.1?

Aug 24, 2011

I'm attempting to integrate an acs 5v into the domain through the gui. The connection will establish, and the status will read 'connected', just as it lists the domain I've submitted. However, I can't seem to find anything listed under the directory groups, and when I run a connection test, I simply get 'Global Catalogue port status error.' Eventually, I'd like to configure this as a radius server.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 802.1x / ACS In The Active Directory Environment?

Nov 9, 2011

question 1. in the typical active directory environment and doing wireless/wired 802.1x authentication on endpoints, should ACS join as a domain computer? 
 
question 2. for the endpoint (domain computer) join the domain, in this case is the endpoint will trust the ACS ( also domain computer) ?
 
question 3. what if there's a GPO policy to install the rootCA certificate toward the endpoints. In this case,  ACS should issue the CSR and let the domain CA to signed as the identity certificate? Am i correct?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Does Not Check Active Directory Changes

Oct 13, 2010

I am working with ACS 5.2 and using Radius authentication for vpn client.
 
The authentication method used is Active Directory in an Windows enviroment with multiple domains in the same forest.
 
My problem occurs when i change a user from one group to another in Active Directory. After that i receive the following message when try to connect:
 
15039 Selected Authorization Profile is DenyAccess
 
The message is because match the default policy. Another user in the same AD group works fine. All domain in the forest have trust relation each other. I am using universal groups to include users from all domain belongs this forest.

View 4 Replies View Related

Cisco :: WLC 2500 Active Directory Integration?

Apr 10, 2012

I recently bought a Cisco WLC 2500. I want to configure a WLAN with Active directory authentication.How I can do this?

View 4 Replies View Related

Cisco :: LMS 3.2 Integration With Microsoft Active Directory

Jun 14, 2012

i need a documentation or a procedure to how make integration LMS 3.2 with microsoft active directory to make usernames of devices  appear in end hosts reports.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Active Directory Integration

Apr 24, 2012

A customer uses Active Directory where some group names contain special characters (ç ~ '^). The Cisco ACS 5.2 is presenting the warnings: "Not all Active Directory user groups are retrieved successfully. One or more of thegroup's canonical name was not retrieved "(Category CSC Oacs_ Identity_ Stores_Diagnostics; code 24457).

What are the results of these warnings to the customer's network? Slow? Loss of access?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Integration Of ACS 4.2 And MS Active Directory

Oct 21, 2010

configure the Cisco ACS to authenticate the users from MS Active Directory. Cisco Acs = 4.2.1(15)Currently, i have multiple users configured as local databse. but now i want to authenticate with the domain users.

View 11 Replies View Related

Cisco :: Integrate 1250 To Active Directory

Jan 5, 2011

I have installed 4 unit Cisco Aironet 1250 acting as Autonomous AP each. I want to integrate these AP to Windows Active Directory for authentication level.
 
When I read configuration guide on Cisco Aironet, they must be authenticated via RADIUS server.
 
Is it possible that these AP directly authenticated to Active Directory via LDAP protocol?

View 4 Replies View Related

Active Directory - Required Bandwidth Usage?

Feb 18, 2012

Currently We have several Active Directory Domain at several Technical High Schools. These are used by us as a it educational unit(s). The Tech School System's IT Department has a fiber wan between the schools that allows communication between these units. We wanted to interconnect the unit's Active Directory's with Trusts or by combining them into one forest. However I am wondering How much bandwidth that alone would require? There make be some file access between units but not on a daily basis since the units are separate from one another. How much bandwidth do you think this would require?

View 5 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved