Cisco :: Multiple Lobby Admin Account With ACS 5.3
Jan 25, 2012Any way to create multiple lobby admin account on ACS and each account will have access to only specific WLANs on the WLC?
View 6 RepliesAny way to create multiple lobby admin account on ACS and each account will have access to only specific WLANs on the WLC?
View 6 RepliesI have two 5508 WLCs. Both have APs attached to them. If I create a guest account with the lobby administrator on one, will that user account be able to log in to the network if the client is attached to the ohter WLC? So far, I have found that I need to create the same user on both WLC's, in order to have the user login.
View 2 Replies View RelatedHow to configure a LobbyAdmin account for WLC 7.0 on a 5.1 ACS? I'm very new to ACS 5. How to configure it.
I've got the ACS policy working that allows me to login to the WLC using a user account with full rights but the Lobby admin account can login with full rights as well. I've tried setting the custome attributes in the shell profiles with role0-mandatory-LobbyAmbassador, task0-Mandatory-Configure Guest User and task1-Mandatory-Lobby Ambassador User Preferences but it still doesn't work.
I was wondering if there is a way to limit the ability of the "lobby admin" account to only be able to give out 24 hour wireless access? The situation is this, we are going to move the roles of guest wireless over to our lobby administrators, but we are afraid they might break policy and give out 30 day wireless access so they dont have to keep renewing guest access each day. We want to limit access to 24 hour "tokens" for all guest unless its a unique situation.
View 2 Replies View RelatedWhy do need Cisco NAC guest server when we have WLC 5508 already configured. The Guest user access can be given by the WLC itself too. We can create users in WLC also and grant access to the user to access internet for specific time frame. My query is - what is so different in Cisco NGS that it is considered good in terms of Guest users access. What are the advatages of NGS.
View 4 Replies View RelatedWe currently have about 8 WLC 4400 series controllers deployed around the company, one of these controllers is acting as an Achor controller for GUEST wifi access for visitors to the company, as a result of this we have many users with "LobbyAdmin" access to setup users.
We have recently introduced a Cisco WCS to manage these devices but its not fully implemented/active to see all WLC's.I need to be able to report on the LobbyAdmin users to see who is setting up accounts and for who etc. Currently access to the WLC/WCS is done via Local admin accounts. All accounts for the LobbyAdmin people are setup on our anchor controller.
I have added the anchor controller for this to the WCS system but when looking in Administration/AAA/Groups the LobbyAdmin groups shows No Members.Is there a way that i can import the Lobby Admin names from the anchor WLC to the WCS so i can do reports/audit checks on these users?
We created the admin account during the setup and were able to log into the Web GUI, but we can't use this admin to access the CLI by using ssh, always said permission denied.
View 3 Replies View RelatedWe installed one Extreme Network's 'Summit X450e-48p' switch in our organization. Unfortunately, we forgot it's admin account password and we don't have any other account on this switch to work on it.Anybody to guide us how to break admin account password for a Summit switch. We don't want factory reset.
View 6 Replies View RelatedI'm crazy with this version of ACS, it is totally diferent than ACS 4.2, which is familiar for me and seems to difficult to config for me.Although I have red a lot of post about problems with the integration WCS 7.0 and ACS 5.2 using TACACs+ for admin or lobby access to the web portal I can't do login into WCS as Lobby ambassador using ACS 5.2 because always show me the error "User has no usergroups assigned".Steps I followed:
- I create a "shell profile" with the custom attributes of the group "lobby ambassador".
- In default device admin / authorization, I create a rule matching this "shell profile".
I see lot os Hit counts and passed in logs, but the message written previously.In ACS 4.2 I had to create the custom attribute "HTTP" and string "Wireless- WCS" to work with, but now I don't know if it is necessary and I don't know how to do it.
We've set our WCS up to do AAA through our ACS 5.3 which works great. So in order to log into the WCS for Administration or as a Lobby Ambassador (to create guest users etc) the AAA is all done by the ACS, GREAT!
I have assigned a set of users the Lobby Ambassador role as passed that back through TACACS to the WCS, so those users have their role setup as Lobby Ambassador and are limited from doing anything else, as expected.
What I want to know is: With normal local AAA on the WCS, when you created a Lobby Ambassador account, you could give the account a set of defaults for any guests accounts created by that Lobby Ambassador account, which was good, so Lobby Ambassadors couldn't set up unlimited time accounts and stuff like that.
What I want to know now is that since I'm now doing all the AAA on the ACS, is there an attribute I can pass to the WCS in the Shell Profile, along with the roles etc telling the WCS what the guest user creation defaults for the Lobby Ambassador account is, so that we can continue to limit the defaults of any guest account that the Lobby Ambassador accounts create, as it used to be? We'd really like different lobby ambassadors to be able to do different things as well. i.e., Lobby Ambassador X can only create accounts for one region. Lobby Ambassador Y can create Unlimited time accounts where the others can not. We used to do this by assigning different guest user creation defaults to different lobby ambassador accounts on the WCS.
I was wondering if the 2504 has the lobby ambassador feature available. Customer requires temp username/passwords for guests managed through web gui. I couldn't find conclusive documentation it was included so I figured I'd check here before calling Cisco.
View 2 Replies View RelatedIs there a module or way to create a Guest Access Lobby on the ASA 5525? We currenly leverage the WLC to do this for us, but are moving to a routed access enviornment which is causing some issues. We would like to offload the guest access responsibility to the ASA if possible.
View 1 Replies View Relatedhow i can configure a second ssid for guest access in our environment. this is our network setup prior to this request: Internet----Firewall (not ASA)---ce520---C1131AG and CME router is also connecting to the ce520 switch. we only have two vlans: one for voice and two for data.
Presently, there is no vlan configured on the AP because it on broadcasting ont ssid and wireless users gets IP from a windows DHCP server on the LAN. the configuration on the ce520 switch port for the AP and other switches say access vlan is the DATA vlan which automatically becomes the native vlan for all trunk port connecting the AP and other Stiches to the network.
Now with this new requirement, i have made my research and i have configured the AP to broadcast both the production and the guest Vlans. The two vlans are 20-DATA and 60-Guest. I made the DATA vlan on the AP the native vlan since the poe switch is using the DATA vlan as native on the trunk ports. I configured the firewall to serve as DHCP server for the guest ssid and i have added the ip helper-address on the guest vlan interface on all switches while the windows server remains the dhcp server for the production DATA Vlan. I have confirmed that the AP, switches can ping the default gateway of the guest dhcp server which is another interface on the firewall. I can now see and connect to all broadcasted ssids but the problem is I am not getting IP addresses from both the production dhcp server and guest dhcp server when i connected to the ssid one at a time. My AP config is attached below.
Do i need to redesign the whole network to have a native vlan other nthan the data vlan? Does the access point need to be aware of the voice vlan? Do the native Vlan on the AP need to be in Bridge-group 1 or can i leave it in bridge-group 20?
My question is if I can configure 3 ssid, for 3 different VLAN and add the DHCP address from a WAP4410N AP, when you upgrade to the latest version of IOS I can have this functionality?
View 2 Replies View RelatedIs it possible to have multiple dhcp pools for multiple VLANs? The switch is a 6509 and/or 4506 catalyst. I don't want to use server-based products.
View 5 Replies View RelatedI am trying to build a new network from scratch, I have the WLC 5508 w/ Aironet 3600e APs connected to my Netgear Smart Switches and a Linksys RV082 router that I'm using as my DHCP server with several VLANs for several stuff on my Switches.
I have 2 questions:
1. Can I have 5 Interfaces configured on 5 different VLANs, each SSID on each a different Port:
Port 1: Controller management only=> 192.168.x.x /24
Port 2: SSID 1: WiFi Internal=> 172.16.x.x/12 (Radius Auth with no sharing)
Port 3: SSID 2: WiFi Internal w/ sharing=> 192.168.x.x/24 (Radius Auth with sharing)
Port 4 :SSID 3: WiFi Guest=> 10.0.x.x/8 (Web Auth)
Port 5: SSID 4: WiFi IT=> 192.168.x.x/24 ( Radius or certificate Auth with access to the controller management interface)
2. How can I use the Controller as the DHCP server for all the WiFi traffic, and how should that be configured to work with my other DHCP server?
i`m facing a problem configuring the mentioned access point to act as stand alone access point with multiple SSID assigned to differnet VLANs the problem is that
1) i`m not able to broadcast the both SSIDs in the same time from the Access point
2) i need to make the radius server to manage the SSID access for the wireless clients (trying to find a way in which the aceess point sends a log for the radius server containing the VLAN id /IP address of the the SSID) you may find the below info about the IOS ver. & the configuration?
i`m running IOS /c1100-k9w7-mx.123-8.JEE/c1100-k9w7-mx.123-8.JEE?
I recently purchased a RV042 device but when I tried to set my DDNS account I realized that the only two providers are dyndns.org and 3322.net. We already have an account in no-ip.com and several services using the [URL] host.
How can I set up a no-ip account in my rv042?
What is my isp account number
View 2 Replies View Relatedin our university we have internet account that allows us to use till 100Mb per a week.how can I use internet without account?
View 1 Replies View RelatedI'm currently setting my ACS 5.x for oridinary person to disable account if password not changed for certain date, But some VIP accounts need to exclude from this condition?
View 3 Replies View RelatedI can create a read-only account on the ACS 5 server? I have the ACSAdmin account.
View 1 Replies View RelatedA 'com.liferay.portal.NoSuchUserException.no such user with primary key 10002491'' error was encounterd when I tried to access ACS 5.2 dashboard using my account (10002491). Using ACSAdmin account I can view the dashboard. My account and ACSAdmin has the same profile and privilege in ACS.
View 1 Replies View Relatedhow many unsucessful attempts a user has to access the LMS application prior to the account being locked? Is this configurable?
View 3 Replies View RelatedSomeone tricked me by sending false email and gained control of my email address. I tried to log on and change my password but I cannot. How can I regain control. I am not experienced with computers. I would also like to learn more about computer basics to start.
View 2 Replies View Relatedfor two days it will not let me sign into my hotmail account...also two days ago got popup for adobe X?? it would not go away, so I accidently said yes, when it wanted to load onto my computer, I did get it off my computer, but, it keeps popping up and now I cannot get into my personal hotmail account.
View 1 Replies View RelatedWhen I turn on computer I can only work my internet on guest account will not work on the other account how can i fix this problem?
View 3 Replies View RelatedMy question relates to Facebook and the Internet in general. There are some very inappropriate pictures of me that are posted on a fake facebook user account. Whoever posted these pictures has stolen the identity of a guy that I went to school with. The Police are involved. I tried contacting Facebook multiple times, but I had no such luck. Is there any way that I can find out the ISP of this fake account, find out if these pictures were uploaded to the www. and request for them to be removed? What other actions can I take to get these pictures taken down. It has now become very serious, and these pictures are from 6 years ago when I was a little immature teenager.
View 2 Replies View RelatedMake a Wi-Fi account
View 2 Replies View RelatedI put in my email address at gmail. Once in a while it will come up, but mostly is filed with pages of ad material.Sometimes when it does come up, it does not come up with the 'from who' really large and the description hard to read as are the message content.
View 1 Replies View RelatedMy gmail account does not work. when i login with my user name and passsword it cant acept and messaged that wrong password. then i click forgot password and verifyed. then i change my password and opend my account. but main problem is there that when i sign out and again login with changed password appears same error that wrong password.
View 1 Replies View RelatedI do not know my wireless account name and do not know how to retrieve it.
View 1 Replies View RelatedI just setup an account at [URL],and I want to set it up in my router. I have a D-link DIR 655 with firmware 1.21 and when I set it up under dynamic dns it wont connect. It'll say "connecting" then disconnect right afterwards. I have my host name and log in information correct.
Is my firmware causing me this issue?