Cisco AAA/Identity/Nac :: WLC 5508 Does Not Support MAB 
			Aug 20, 2012
				As we know that WLC (i.e. 5508) does not support MAB (MAC Auth Bypass) and it supports CWA in 7.2.x. CWA is a result of successfull MAB. So how CWA work for wireless? So it means WLC support MAB?
	
	View 5 Replies
  
    
		
ADVERTISEMENT
    	
    	
        Dec 14, 2011
        How Cisco Identity Service Engine (ISE) can work with  WLAN controller 5508 to do the Local Web Authentication, on behalf tje  guest profile is create using Cisco ISE guest management?
 
As i check Cisco ISE caveat wireless only support on LWA, and LWA not supported on Authorization's VLAN assignment.
 
what i need to concern abou the ISE authentication and  authorization policy on behalf on Wireless LWA with use of ISE guest  management case?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Nov 20, 2011
        I have a new deployment of 44 3502i AP's in 3 buildings at one of my campus'.The 5508 wlc is running latest 7.0.116.0 code.I have some users who take their work with them as they go from location to location on this campus.They need to be able to smoothly switch from AP to AP without having to reauthenticate each time the next AP takes over in the handoff.On the ssid in question we run 802.1x back to 1 auth server; there is no failover auth server.All APs are in one AP Group.My thought is to add all 44 of the APs to one HREAP Group.
	View 4 Replies
    View Related
  
    
	
    	
    	
        Oct 23, 2011
        I have seen that the current WLC software release, 7.0.116.0, does not support secure LDAP using TLS. Are there any plans to incorporate this feature? (I've read that it was supported in previous releases to version 4.2). Is it in the roadmap of the product?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Mar 27, 2013
        We are moving forward with a mobility project which requires our network to authenticate/authorize based on certificates. 
 
WLAN_1 has 802.1x enabled passing the cert through to the MS CA which authorizes the cred, which in turn passes the AD creds of the user to the MS RADIUS server for authenticate/authorization.
Hardware: WLC 5508 running 7.2.110.0 3600 APs ACS 5.2 not used for AAA
 
1. As we turn up additional SSIDs, we need Mobile SSID to accept ONLY the Mobile Cert, our Internet SSID to only accept the Internal Cert and our GUEST SSID to deny ANY Cert issued by our CA.I know ISE makes this much easier, but I dont have it and need this to work as best we can until next fiscal cycle..
	View 3 Replies
    View Related
  
    
	
    	
    	
        Oct 9, 2012
        I'm running version  7.2.111.3 on my WLC 5508 and I try to figure out how I can set PEAP towards my configurerd Radius servers. On my Local EAP profile I can specify PEAP, but how is it default configurerd when you just specify the radius servers on the "WLANs > Edit Test > security > AAA servers tab ?
 
The MS radius logs tell me that it is EAP and not PEAP, so the questions is does the WLC support Microsoft: Protected EAP ???
 
Dot1x_NW_MsgTask_0: Oct 10 11:02:27.279: 24:77:03:07:75:28 AAA EAP Packet created request = 0x1bd4647c.. !!!! -> should be AAA PEAP ?
*Dot1x_NW_MsgTask_0: Oct 10 11:02:27.279: 24:77:03:07:75:28 Sending EAP Attribute (code=2, length=35, id=2) for mobile 24:77:03:07:75:28*Dot1x_NW_MsgTask_0: Oct 10 11:02:27.280: 24:77:03:07:75:28 [BE-req] Radius  EAP/Local WLAN 3.
	View 6 Replies
    View Related
  
    
	
    	
    	
        Aug 10, 2012
        I have a customert that needs to support 200 laptops over 16 classrooms with scalability to 400 laptops. I have a heatmap design to cover this with 22 1042 access points. Does any one know what features the 5508 has over the 2504? By reviewing the data sheets, the biggest feature difference is better support for mobility, which not a need for this deployment as they just wheel a cart of laptops into a classroom and fire them up. Also, does the 2504 support LAG across the four gig interfaces?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Jun 6, 2011
        is there a support of 1+1 mode (HA mode) at 5508 Controller? If yes Is there a HA bundle or do we have to order two identical 5508 controller ?
	View 6 Replies
    View Related
  
    
	
    	
    	
        Jan 23, 2013
        I am trying to follow the Fips guide for the WLC5508 and it wants to encrypt the connection to the Radius, either with PSK key wrap or IPsec. I have the options for Ipsec only as the Windoes NPS does not support Key wrap from what a previous user confirmed for me here on the board.. But then found another post that states that the 5508 does not support IPsec? 
	View 5 Replies
    View Related
  
    
	
    	
    	
        Aug 27, 2011
        I have ACS 1120 appilance does it support ACS version 5.2.0.x and corresponding patches. 
	View 2 Replies
    View Related
  
    
	
    	
    	
        Dec 18, 2011
        I have Some Alcatel Switch and I want to use ACS 5.2's tacscs+ for Alcatel Switch admin authentication.the Failure Reason:13011 Invalid  TACACS+ request packet - possibly mismatched Shared SecretsBut I was check the share secret is correct.Before I was tried associated ACS with vision 4.2 is work.
	View 12 Replies
    View Related
  
    
	
    	
    	
        Mar 11, 2012
        I am using ACS 5.3.I need to make macauthentication on Enterasys switch with Cisco ACS 5.3.I get the following error;
 
Parsing error or event type unknown:xxxxxxxxxxxxx ERROR RADIUS : RADIUS packet contains invalid attribute(s) ;Failed-Attepmt:Radius request dropped
 
How can I integrate Custom Attribute Enterasys A2 Switch with Cisco ACS 5.3 ?
	View 3 Replies
    View Related
  
    
	
    	
    	
        Apr 29, 2013
        Getting ready to order a SSL Certificate for my newly installed ACS 5.4 and before I did that i want to verify if ACS 5.4 supports Wildcard SSL's.
	View 5 Replies
    View Related
  
    
	
    	
    	
        Dec 5, 2011
        Is the ISE going to support the 2500 series Wireless LAN Controller WLC? If yes in what release and appriximately when is that due to be released?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Apr 23, 2013
        I'd like to configure ASDM access to ASA-SM using RSA SecurID authentication.I've followed instructions in this documen [URL]When I test access from CLI everything looks fine:
 
asa-vss/admin/act# test aaa-server authentication RSA
Server IP Address or name: xx.xx.xx.xx
Username: testuser
Password: **********
INFO: Attempting Authentication test to IP address <xx.xx.xx.xx> (timeout: 12 seconds)
INFO: Authentication Successful
[code]....
 
When I try to use ASDM, I'm unable to login and I can see lot of authentication error (Token reuse) messages on RSA server monitor window.It looks like ASDM 6.5(1) for ASA-SM doesn't support RSA/SDI authentication. 
	View 9 Replies
    View Related
  
    
	
    	
    	
        May 17, 2012
        we have installed nac for our customer and it works fine ,but the customer want the change the version of kaspersky antivirus from 6 to 8 end point security ,when we have try this the nac agent does not find the antivrus on the the workstation . i want to know if this version of kasoersky (end point security ) is supported by nac ,if no is ther a solution to make it works with the NAC .
	View 3 Replies
    View Related
  
    
	
    	
    	
        Jan 26, 2011
        is it possible to use wildcards in Compund Conditions in ACS 5.2? i've been suing the following to try and match a username that contains @*.*:
This would hopefully match a username like j.blogs@somewhere.com but doesn't work as expected - am i doing something wrong or are wildcards not supported in compund conditions?
	View 2 Replies
    View Related
  
    
	
    	
    	
        Aug 20, 2012
        we have deployed L3 in-band scenario for wireless 2 years ago and the solution was working without any problem. we have upgrade wireless controller to 5508, since then, when users login to the first page and certified, and they want to browse to the internet, NAC redirects the web page and ask for authenticatin again, despite the users' devices are being shown as certified devices in the list. 
	View 6 Replies
    View Related
  
    
	
    	
    	
        Dec 20, 2012
        We are running ACS 4.0 so understandably so we are looking to upgrading to a Cisco supportable version of ACS.  The limitation of our current version of ACS does not support nested AD groups.  The latest version of ACS (I think it is 5.4) will?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Nov 28, 2012
        Whether ISE-3315-K9 with ise version: Service Engine: 1.0.4.573 , supports the command level accounting 
Bascially , we have integrated Cisco Switches with Cisco ISE for Device Authentication using Radius , we are able get the authentication logs on to the devices , but for any command changes or update done on Cisco devices we are not able to get the command accounting.
	View 1 Replies
    View Related
  
    
	
    	
    	
        Dec 15, 2011
        Critical voice vlan feature, used to place a newly authenticating phone when radius server is dead into appropriate voice vlan, seems to be a new feature and I find the documentation to be incomplete.  Do the following switches support this feature in any IoS versions? WS-C4510R, 4506, 3560, 3550,2960s.
	View 1 Replies
    View Related
  
    
	
    	
    	
        May 25, 2011
        I'm looking to implement ACS 5.2 using 802.1X, we have two seperate AD domains.A single switch will need to support both ADs, so if a machine in AD1 is connected, it will be authenticated to the ACS using AD1 and applied to VLAN1, while a machine that is in AD2 will be authenticated to AD2 and applied to VLAN 2.
 
I'm looking at machine authentication, not user authentication, so I assume that I will need to import two certs from each AD.
	View 3 Replies
    View Related
  
    
	
    	
    	
        Sep 13, 2012
        How many newtork devices can Cisco Secure ACSv4.1 support is there any limit on the same? How to get the Specs of Cisco Secure ACSv4.1 on the above grounds...
	View 2 Replies
    View Related
  
    
	
    	
    	
        Sep 25, 2011
        Having an issue with Cisco ACS v5.1.0.44 and the Cisco WLC 5508. Cannot get users to authenticate and keep getting error messages referring to EAP session timeouts from WLC filling our logs. Seems to be with this model WLC because we have Cisco 4400 WLCs pointing to the same ACS with no issues. Is there a bug or special configuration that is necessary to marry the 5508 with ACS v5.1.0.44?
	View 9 Replies
    View Related
  
    
	
    	
    	
        May 18, 2011
        getting a Cisco WLC to work with MS NPS server? We've done it before albeit with differnt code versions.
 
I have a Cisco 5508 WLC running 7.0.116.0 code hosting a WLAN configured for WPA2 with 802.1x for authentication.  I have two Windows NPS servers configured as the RADIUS servers for EAP-TLS authentication. Via debug info on the WLC I can see the 802.1x handshake take place with the wireless client and the WLC as well as a successful transmission of an Authentication Packet from the WLC to one of the RADIUS servers. However on the WLC I see repeated RADIUS server x.x.x.x:1812 deactivated in global list and on the NPS server I'm seeing event log errors indicating "The Network Policy Server discarded the request for a user"  along with the pertinent auth request info that I would expect the NPS server to receive from the WLC.  Based on the WLC debug info I'm never actually getting to the EAP-TLS certificate authentication part. It seems the NPS servers don't like the format of the initial RADIUS authentication request coming from the WLC and so don't respond whcih in turn casues to WLC to switch to the other NPS server which produces the same issue.
	View 2 Replies
    View Related
  
    
	
    	
    	
        Aug 3, 2011
        I Have a requirement to migrate from ipv4 to ipv6, I have checked the scalability of all the devices for this migration except ACS 1113 Solution Engine, Version 4.2.  I couldnt reach the proper documentation to check its support for ipv6.
	View 1 Replies
    View Related
  
    
	
    	
    	
        Jun 8, 2013
        how ISE support on third party LAN switch, if the requirement is doing 802.1X based flexauth.Refer to the diagram i attached; 01 topology.png
 
Concern  1: if the 3com switch with 802.1X feature, but still without the full  feature to support FlexAuth, policy encforcement, DACL etc. In this kind  of situation, will user still able to authenticate (using method  PEAP-MSCHAP v2), but authorization just grant with permit any any?
 
Concern  2:  Can i assume i authenticated the 3com switch using  MAB? But this will cause endpoint with no 802.1X, am i right?
 
Concern  3:  cisco switch C4507-E, loaded with IOS version  Cat4500e-UNIVERSALK9-M, version 03.04 and Supervisor Engine  :WS-X45-SUP7-E, is this platform is supported in Cisco TrusctSEC? 
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jan 9, 2012
        Having issue with WLC 5508 using ACS 5.2 tacacs+ protocol to do device management.The problem statement is after key in the username and password on the WLC login page, it is endlessly prompt for authentication on WLC. Whilst on ACS monitoring and reporting i able to see it is successfully authenticated, shown at AAA protocol > TACACS+ Authentication.On ACS, the shell profile for this is setting role1 , value = ALL. 
	View 3 Replies
    View Related
  
    
	
    	
    	
        Jun 19, 2012
        We’re currently using 5508 WLC’s and leveraging Cisco ISE for radius/authentication rule sets.I’m trying to get a splash page to flash and then redirect to a website after a successful authentication to an SSID. Everything on the wireless side works with no splash page (users connect to SSID,authenticate with AD credentials using 802.1X PEAP to our Cisco ISE box, and gain access to the network).When I enable ‘Splash Page Web Redirect’ on the WLC (under L3 security), I’m unclear on the ISE box where I set this up. When I look in the Cisco documention it says:Splash Page Web Redirect—If you select this option, the user is redirected to a particular web page after 802.1X authentication successfully completes. After the redirect, the user has full access to the network. You can specify the splash web page on your RADIUS server. How I specify this on the ISE box? Or am I totally off base?
	View 10 Replies
    View Related
  
    
	
    	
    	
        May 24, 2011
        I have just recently purchased a 5505 Controller and 30 3502i AP's. On my main corporate WLAN, I would like to allow users to be able to authenticate via Active Directory username and password.I am also looking for as little client side set up as possible. From what I have researched, I will need to use some type of EAP method.
 
I have come across two methods that appear to be the top contenders.
 
EAP-FAST - The method seems to be a possibility but I see that it uses certificates. If I use this method, does it mean that I would have to import the certificates to each machine manually? Also, can I configure thsi to work with just the 5508 Controller and an AD Database server or do I need an intermediary like IAS or ACS?
 
PEAP/GTC - This method is also a possibility and I think that it does not require certificates. Does this also require an intermediary like ACS or IAS.
	View 3 Replies
    View Related
  
    
	
    	
    	
        Sep 20, 2012
        We`re using a WLC 5508 with SW 7.2.103.0.The most things are working fine, but i have a problem with the web auth.
 
Setup:
- Max Concurrent Logins for a user name is set to 1
- Max-Login Ignore Identity Response is set to enable
- Web Authentication Type is set to customized
 
The Problem:
- the user "test" is logged in at device1 (working), the same user "test" try to login at device 2 (is not working, fine!) -> login is not accepted, WLC redirects to the INTERNAL Web Login Page.The problem is the redirect to the internal web login page after failed login. If i try to login with a not existing user, the redirect is working perfect to the customized web login.
	View 4 Replies
    View Related
  
    
	
    	
    	
        Apr 4, 2013
        Environment :AP 2602, WLC 5508 V7.4, ISE 1.1.2, Prime Infras 1.2
 
For a specific SSID, we use MAC address as 1 of the conditions to authorize access only for the company-owned mobiles (smartphones and tablets), the other condition being, for the mobile, to present a valid AD user/password;this way, the so-called BYODs are rejected since this is the rule within this company ;The difficulty with this approach is the fact that there is no way in ISE Identities Endpoints nor Groups to associate a user-friendly name to the MAC address of the mobiles, which makes very tedious some actions such as a search in the ISE authentication Log based on the MAC address value itself;the question is just to know if it is planned to add a new field  in Identities Endpoints definition that would allow to associate a user-friendly name to a MAC address, for future ISE versions, 
	View 1 Replies
    View Related
  
    
	
    	
    	
        Apr 29, 2011
        I installed NGS 2.0.2 for wireless guest user management and authentication. I implement webauth via webauth page on wlc deployed.One Branch with a WLC5508 version 7.0 wireless anchor controller is working on the NGS.But now I integrate next branch with WLC4402 version 6.0.188 and the authentication of users at the new branch gets an error, wrong user/password.
 
I double checked configuration and user/password but I can't find any configuration error. Also stopping and starting of radius service and reboot of NGS still does not work. I tried to debug the radius via web interface and watched for the loggfile and there is still a reject.I also tried the freeradius command radiusd -X but I got an error when starting the radiusd -X.
 
1.) How can I figure out, if I will get the correct password from my WLC ? Are there any debug options to see more ? e.g. some cli commands, radiustest utilities or how to get the received password from the chap challenge of the debug ?
 
2.) I have appended a part from my radius loggfile. How can I find the detailed error in the radius log file? Is it correct that the password in the debug file is empty ? raiuds logg line "[radius-user-auth]  expand: %{User-Password} -> "
	View 3 Replies
    View Related