Cisco Wireless :: 5508 Get Access To AP Via Radius

Feb 1, 2012

i have configured 35 APs 3502i in 5508 WLC, now i want to get access to ap via radius. Currently i can connect to them via SSH with both user and password set in wireless> access point > global configuration, well, how do i configure the management AP user  through RADIUS?

View 2 Replies


ADVERTISEMENT

Cisco Wireless :: WLC 5508 Radius Accounting

Jun 5, 2013

I have a WLAN configured with 802.1x PEAP pointing to an external RADIUS server.  It works fine for the most part, but I'm having problem closing accounting sessions in RADIUS.  I've found this is related to the client table in the WLC.  The user session does not end in RADIUS unless the WLC officially removes the client from the db, which takes 5-6 minutes from what I can see (probably due to the default idle timeout of 300 seconds). 
 
For example:
 
1.  I connect my tablet to the test WLAN.  It associates and authenticates successfully and the WLC sends the accounting info to my RADIUS server, opening up a user session.  If I turn off the wifi in the tablet, the client entry stays in the WLC client table until it times out.  The WLC removes my tablet from the client table after 5-6 minutes, and then the session closes in the accounting table.  I can force the session to close much earlier by manually removing the client from the WLC.
 
2.  Same as #1, but this time instead of turning of the wifi in the tablet, I choose to connect to a different WLAN in the WLC.  The user session in the accounting DB never closes.  If I reconnect back to the original test WLAN with 802.1x, it opens up yet another user session in RADIUS accounting.  Now I have a "dead" user session in accounting that is going to be open forever unless I delete it from SQL.
 
Is this an issue with the end user client not sending the disassociation frame properly, or a config problem with the WLC?  How can I make it so that every time a client drops from an AP or moves to a different WLAN, the WLC would immediately send accounting updates to my RADIUS server and close the user session properly?

View 1 Replies View Related

Cisco Wireless :: 5508 WLC With ISE As Radius And Also External Web Server

Jan 30, 2013

I am biulding a wireless network with 5508 WLC and trying to use ISE as radius server and also to redirect the web-login to it.I was trying to understand that to achieve the external web-login, do i need to use the raduius-nac option under advanced on the guest wireless where i am trying this out. and if not, where do i actually use it?So far what i have understood that i do need to have preauth ACL on the Layer 3 security, but the issue is there is no hit reaching the ISE.

View 9 Replies View Related

Cisco Wireless :: WLC 5508 No Further RADIUS Authentication Requests?

Mar 18, 2013

I'm working on a project where a wi-fi client is tracked and located using RADIUS authentication requests. The problem I'm running into is that the WLC (5508) sends an RADIUS authentication request to my freeradiusd, which is ok so far, but if the client roams to another accesspoint (3602AG, 1131AG, 1252AG), the WLC does not send a further RADIUS auth. request - and the client is allowed to connect to the next ap.Is there an option like RADIUS-cache which I can disable, so that the WLC sends everytime an authentication request when a client tries to connect to an ap or roams from one ap to another one?

View 4 Replies View Related

Cisco Wireless :: Can Use WLC 5508 With OpenLDAP Directly (without Radius)

Dec 18, 2012

Can I use WLC 5508 with OpenLDAP directly (without radius) ?

View 1 Replies View Related

Cisco Wireless :: 5508 Controller With Radius Authentication

Feb 16, 2012

I am setting up a WIFI network with a Cisco 5508 controller. I want  to configure a first WIFI network (WIFI1) that will authenticate my  business laptop based on the AD computer accounts and will access my  corporate network.I want to setup a second WIFI network (WIFI2) that will authenticate  my phones and tablets devices with AD user accounts and will be on a  separate vlan with only access to the Internet.I created 2 policies on the Radius server : one that authenticate  computers coming from wireless and a second one authenticating users  coming from wireless.
 
if a user manually creates the WIFI1 network on his phone  and enter his AD username, he is going to have access to the corporate  network.  I would like to be able to say that when a request is coming  from WIFI1, only the policy for authenticating  wireless devices with computer accounts will apply and the second  policy authenticating user wouldn't apply.

View 1 Replies View Related

Cisco Wireless :: Does WLC 5508 (7.2) Support PEAP To MS Radius

Oct 9, 2012

I'm running version  7.2.111.3 on my WLC 5508 and I try to figure out how I can set PEAP towards my configurerd Radius servers. On my Local EAP profile I can specify PEAP, but how is it default configurerd when you just specify the radius servers on the "WLANs > Edit Test > security > AAA servers tab ?
 
The MS radius logs tell me that it is EAP and not PEAP, so the questions is does the WLC support Microsoft: Protected EAP ???
 
Dot1x_NW_MsgTask_0: Oct 10 11:02:27.279: 24:77:03:07:75:28 AAA EAP Packet created request = 0x1bd4647c.. !!!! -> should be AAA PEAP ?
*Dot1x_NW_MsgTask_0: Oct 10 11:02:27.279: 24:77:03:07:75:28 Sending EAP Attribute (code=2, length=35, id=2) for mobile 24:77:03:07:75:28*Dot1x_NW_MsgTask_0: Oct 10 11:02:27.280: 24:77:03:07:75:28 [BE-req] Radius  EAP/Local WLAN 3.

View 6 Replies View Related

Cisco Wireless :: WLC 5508 Support IPSec To Radius Server?

Jan 23, 2013

I am trying to follow the Fips guide for the WLC5508 and it wants to encrypt the connection to the Radius, either with PSK key wrap or IPsec. I have the options for Ipsec only as the Windoes NPS does not support Key wrap from what a previous user confirmed for me here on the board.. But then found another post that states that the 5508 does not support IPsec?

View 5 Replies View Related

Cisco Wireless :: Configuring Microsoft Radius Server For 5508?

Apr 28, 2013

I would like to know if microsoft 2008 server RADIUS server could be use for authentication on Cosco 5508 instead of Cisco ACS.

View 4 Replies View Related

Cisco Wireless :: 5508 - RADIUS Server Activated / Deactivated On WLAN X

Sep 18, 2011

Since I moved our WLC Controller ( 5508 ) from Version 7.0 to Version 7.2.111.3 I got above failure messages. Until now I changed the radius timeout from 2 to 10 seconds and also I disabled the aggressive failover without success. What else it could be ?

View 3 Replies View Related

Cisco :: 5508 - NPS Radius

Apr 10, 2013

Cisco WLC 5508
Software Version: 7.4.100.0
Windows Server 2008R2
  
I've got everything setup on the Windows Server 2008 side of things (certificates, radius clients, etc). I added the radius server on the WLC, and configured a new W LAN to use it. Both are on the same sub net. When trying to connect to the W LAN it kept failing.  I installed wire shark on the server to monitor the radius traffic, and to my surprise there was no radius traffic showing up on the server.  The radius statistics on the WLC are at 0 as well, so it's like the WLC isn't even attempting Radius.
 
I re verified that the server was enabled on both the security tab and the W LAN itself on the WLC.  Rebooted the controller and the server, all to no avail.  I used a radius test client, and can successfully send radius commands to the server using that utility. Frustrated, I just kept trying to reconnect on my wireless device, and after about the 15th try, finally I saw radius activity on wire shark.  It rejected my access, but at least I saw activity.  It also registered radius statistics on the WLC as well.
 
So now if I keep trying to connect repeatedly, about every dozen or so times the WLC actually will send a radius request to the server.

View 8 Replies View Related

Cisco :: For RADIUS Integration Between WLC 5508 And MS NPS

Nov 3, 2012

We are trying to integrate Cisco WLC 5508 and Microsoft NPS 2008 to allow users to use their AD username and password to authenticate to the wireless network.I basically followed the following document but with no luck (Appendix B): URL I'v went through some threads in this forum but also with no luck,Basically, we are recieving the follwoing error in NPS event viewer:A RADIUS message was received from RADIUS client a.a.a.a with an invalid authenticator. This is typically caused by mismatched shared secrets. Verify the configuration of the shared secret for the RADIUS client in the Network Policy Server snap-in and the configuration of the network access server.

View 2 Replies View Related

Cisco :: Using 5508 To Authenticate Local First Then Radius?

Sep 8, 2011

I am transitioning from RADIUS auth to local auth and i don't want to hassle everyone to change in one hit.If i can get auth requests to look in the WLC local net db first and if not found try RADIUS then this is what i am after! You can easily do it with web auth but doesnt seem so easy via WPA2 method.

View 1 Replies View Related

Cisco :: 5508 / Radius Authentication Not Working?

Apr 8, 2013

I have a 5508 controller running 7.4.100 and have a WLAN where I have radius configured. On my controller the client machine I'm using appears but the radius authentication doesn't appear to be working. Is there anything on the controller I can do to verify that the request is even being sent to my Microsoft IAS server? The log on the server doesn't show any requests from the controller so my early days guess is the controller isn't actually sending it.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: 5508-WLC Using MS NPS As RADIUS Server For EAP-TLS

May 18, 2011

getting a Cisco WLC to work with MS NPS server? We've done it before albeit with differnt code versions.
 
I have a Cisco 5508 WLC running 7.0.116.0 code hosting a WLAN configured for WPA2 with 802.1x for authentication.  I have two Windows NPS servers configured as the RADIUS servers for EAP-TLS authentication. Via debug info on the WLC I can see the 802.1x handshake take place with the wireless client and the WLC as well as a successful transmission of an Authentication Packet from the WLC to one of the RADIUS servers. However on the WLC I see repeated RADIUS server x.x.x.x:1812 deactivated in global list and on the NPS server I'm seeing event log errors indicating "The Network Policy Server discarded the request for a user"  along with the pertinent auth request info that I would expect the NPS server to receive from the WLC.  Based on the WLC debug info I'm never actually getting to the EAP-TLS certificate authentication part. It seems the NPS servers don't like the format of the initial RADIUS authentication request coming from the WLC and so don't respond whcih in turn casues to WLC to switch to the other NPS server which produces the same issue.

View 2 Replies View Related

Cisco :: Controller 5508 With RADIUS Authentication

May 6, 2013

I'm a trainee in Network and Telecommunication, and I have to do a "model" with a controller, an AP, and a RADIUS server. Communication and configuration of the lightweight AP has been done.
 
I use an autonomous access point 1220 as the RADIUS server (no considering it as an AP), and I'm a beginner in RADIUS configuration. I get a "Processing AAA Error 'No Server' (-7) for mobile 00:24:d6:8f:2c:7e" when I launch a debug targetting my PC, connecting to the LAP.
 
Precursory : 10.137.125.71 is the IP address of the ap1220, working as the RADIUS server 10.137.125.15 is the IP address of the controller. 00:24:d6:8f:2c:7e  is the MAC address of my PC, connecting to the Wi-Fi. ping works to the RADIUS, to the controller. Each devices are connected by a layer 3 Switch, and ping each others. The Wi-Fi works when I don't use 802.1X (or when I don't use RADIUS authentication at all)
 
What I did on the RADIUS server (ap1220 autonomous) :
 
aaa new-model
radius-server local
nas 10.137.125.15 key password

[Code]......

View 5 Replies View Related

Cisco :: 5508 RADIUS Server Failed To Respond To Request

May 22, 2013

We are experiencing a lot of these RADIUS failed to respond messages on our WLC's leading to a lot of RADIUS server hopping within the WLC.We are using Cisco 5508's, 1142 AP's and a Microsoft NPS RADIUS backend. SSID is WPA2+802.1xThe first workaround to this problem was to disable aggressive failover on the WLC. But this is only a temporary fix, because in the end, there will be more than 3 consequetive clients, failing to authenticate to the WLAN network. As a result, the WLC will swap to the 2nd RADIUS server configured.When we dived into this a little bit more we saw the following messages being logged on the RADIUS backend at the time we saw the RADIUS messages on the WL:Event ID: 6274: Network Policy Server discarded the request for a user.

View 16 Replies View Related

Cisco :: 5508 WLC - Restricting SSIDs Using Win2008 Radius Servers

Feb 5, 2013

I have a customer that wants to restrict SSIDs that groups get based on their AD credentials.  Currently, he is using Windows 2008 Radius Server and AD with Cisco 5508 WLCs.  I found examples that shows this is possible but my question is if I have 2 user groups (teachers and students) in AD and apply a policy for the Radius to send SSID x to teachers and SSID y to students.  Upon successfully authentication, would this deny teachers access to SSID y and students access to SSID x?

View 10 Replies View Related

Cisco Wireless :: WLC 5508 - Access Via SP

Jan 4, 2012

Today my wlc 5508 crash. after trying to get access via sp. It doesn't responds. so i rebooted. in the sh tech i saw this message which i guess indicates the RC of the failure.   

             Start Cisco Crash Handler Serv              
Sys Name:       usa-5354-wlc-02
Model:          AIR-CT5508-K9
Version:        7.0.98.0
[code]...

Analysis of Failure:   Software was stopped by the reaper for the following reason:
Reaper Reset: Task "locpRxServerTask" missed software watchdog

View 1 Replies View Related

Cisco :: Radius For Both VPN And Admin Access On Same Router

Jul 25, 2012

I am attempting to configure Radius for use with a Cisco router for the first time. I have read a few tutorials online for setting up administrative access to the router using active directory accounts. On the surface this doesnt seem to over complicated. My question is: Is it possible to have one Cisco IOS router set up with radius authentication for administrative access AND have the same router set up for VPN clients who will be authenticated via the same Radius server? The router I am using is a Cisco ISR 2911 and the IOS version is "Cisco IOS Software, C2900 Software (C2900-UNIVERSALK9-M), Version 15.1(4)M2".

View 1 Replies View Related

Cisco Wireless :: WLC 5508 Guest Access Via WAN?

Jan 28, 2012

Is it possible to provide wireless guest access over the WAN from another office via the WLC. I have WLC 5508 in a central office and have other remote offices that have one Access Point in each office that are autonomous; I will be converting these to LWAPP. Is it possible to route guest traffic back to the WLC then forward this traffic out to the internet? How would I route this traffic out as well? install a secondary WLC in the DMZ and use anchor points. I only have one WLC

View 7 Replies View Related

Cisco Wireless :: Guest Access On 5508 WLC

Feb 3, 2013

I'm looking to implement guest WiFi access with web authentication on one of our 5508 WLC (currently deployed within a sandbox environment), but looking for some assistance. The WLC currently has a single connection from port 1 to the 'Test Site 2' switch. This is a dot1q trunk. On the WLC, the interface (for port 1) is configured as follows: [code] Currently, I have one WLAN configured with the profile name 'Guest Test 1', it's enabled and broadcasting the SSID. Security is L3 only with web authentication configured. The WLAN is configured to use the interface names "guest_wifi".
 
The issue is that when a client connects to the WLAN, it receives an IP address okay (10.99.254.x address), but doesn't seem to be able to contact the WLC to get the web authentication page. Eventually, the WLC terminates the connection due to an authentication failure.does it sound like I'm taking the correct approach here? The idea is that clients connect to the guest WLAN, which puts them on VLAN 99 and routes traffic through to the ASA and then onto the internet.

View 13 Replies View Related

Cisco Wireless :: 5508 Access Point Goes Down

Aug 7, 2012

wlc 5508 code 7.0.220.0
AIR-CAP3502E-N-K9
 
each time that for what ever reason my access point goes down(not that my access point resets by itself, if i have to move it), the setting in the vlan mapping  resets to  whatever my native vlan is, in this case 30.

View 3 Replies View Related

Cisco :: 5508 Wireless Limited Access

Nov 21, 2010

I'm using a wireless controller 5508 and 1141 Ap.Ultimately all the AP is working as LWAP.Everything is working fine.But offen end user getting "Limited Access " .At that time network is connected but i cant ping even my gateway.

View 7 Replies View Related

Cisco Wireless :: Push Access Points To Second 5508 Via HA

Aug 9, 2012

I am having an issue here.  I have 2x 5508 that each have 100 AP license and a little under 200 access points.  Basically all of the access points are using DNS to connect to the primary controller that has the DNS entry.  Basically half of my access points need to be on the second controller and in order to do this I have been using the high availability mode of each access point to push them to the second controller IP address.It was working perfectly until now.  I have pushed 28 access points to the second controller and the last two I need to push at this location just keep resetting on the primary controller.  Neither controller is configured as master controller.

View 4 Replies View Related

Cisco Wireless :: 5508 IP Scheme For Access Points

Jan 17, 2013

I have access points deployed across several buildings that each have a different IP scheme and their own T1 line. Is it possible to configure the 5508 controller to allow these access points to use the IP scheme assigned for that particular building or will dhcp always assign an IP address to the connecting client based on the IP scheme of the building that the controller resides in?

View 1 Replies View Related

Cisco Wireless :: Supported Access Points On WLC 5508

Jul 13, 2011

I need an official document from Cisco saying the APs models supported by the WLC 5508. Specially, I need to know if the AIR-AP1242AG-T-K9, converted from standalone, will be supported by the 5508.

View 1 Replies View Related

Cisco Wireless :: 5508 -Architect Guest Access

Apr 11, 2012

I just got a new requirement for our wireless roll out and I need some help. Plan the best way to provide employee and guests wireless access w/ the guests separate from the production environment.
 
We have a 5508 controller w/ 1142 APs. I have two GBICs in the interfaces (only one is being used). I want to use a back haul connection for the guest access. I am having a hard time in visioning how to physically set up the cabling from the patch panel. Again, the requirement is to not allow guest users to connect to our production network but I still want/need to manage the AP. This will eventually need to be supported for remote sites tunneling back to the primary location. 

View 7 Replies View Related

Cisco Wireless :: WLC 5508 7.3 Management Interface Access To GUI?

Jan 16, 2013

After I've upgraded software to the v7.3 and applied AP-SSO it made imposible to access the controller's gui via Service-port. So we tried to access it by management-port, but there is some problem too. It is not working from another subnets. But default gateway on management vlan is set correctly and I even tried to turn of all acl's on switch. WLC is only accessible from the same network. But at the same time wlc is replying on ping fine.All other protocols cannot connect to the controller.

View 3 Replies View Related

Cisco Wireless :: WLC 5508 - Guest Internet Access

Oct 28, 2011

I am running a 5508 WLC with 10 Access Point. we need to allow Internet Access to Guest. 10MB DSL Internet is dedicated for Guest. This link is terminated on a regular ADSL modem without being part of our network. We want all Guest Internet traffic to reach the ADSL Router. where should I create the Guest VLAN / where the DHCP for Guest users should be created. what is the best practise for similar setup.
 
Our Network is simple
ISP_Reuter-------ASA_Firewall--------------4505------------LAN-switch 2950
 
ADSL_modem------------ users connect via wireless but restricted to certain area only.

View 9 Replies View Related

Cisco Wireless :: 5508 - OID For Access Point Summary / All APs

Feb 19, 2012

What is the OID for the count of the APs connected (and Status UP) to a WLC 5508?

View 2 Replies View Related

Cisco :: 1130AG Access Point Module Will Support Radius

Nov 4, 2012

In our Environment we used to Connect to wifi using   Radius Authentication Through AD Account  (Encryption: TKIP and  CIpher, Authentication Open+EAP and Network EAP,  Key management WPA) this settings  which will be done And pushed through AD Itself.We Use CIsco 1130AG, 1200 Series in most of the areas which have no Issues.But We Have Some trouble with Cisco WAP4410N Access point.In This Access point users were not able to Connect to wifi through Radius Authentication.However users were able to Connect  to these Access point, but  it is unsecured, whoever configure's the correct client settings in their PC. They can connect to SSID. This Access point is capable of supporting Radius Authentication?

View 4 Replies View Related

Cisco AAA/Identity/Nac :: Configure ACS 5.4 As Radius Server For Network Access

May 1, 2013

I'm trying to configure ACS 5.4 as radius server for network access (PPP connections).In monitoring and reports the users have green color , but the clients cannot send data. Auth method is CHAP/MD5.
 
Allowed protocols are set to CHAP and PAP only.

View 5 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved