Cisco Wireless :: Enable SSH On 3500 / 3600 APs Along With Use Radius For Login Authentication

Sep 11, 2012

Can we enable ssh on 3500 /3600 APs along with use radius  for login authentication? idea here is to that  ssh will provide another method to access the AP for troubleshooting purposes.I know with autonomous mode APs this should not be an issue but not sure with  lightweight APs.

View 2 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: AP 3500 - 802.1x Wireless Authentication Against RADIUS Authenticator?

Nov 1, 2012

Would like to check out some client side setting on Wireless 802.1x authenticaiton.
 
Network setup is using

- Cisco WLC 7.2 and AP3500,
- ACS 5.3
- Microsoft Windows server 2008 hosting AD and CA services (same machine)
- Client OS is Microsoft Window 7.
 
Authentication mehtod would use PEAP-MSChap V2 Combo.
  
My question :
 
01. In AD environment, should ACS 5.3 be part of the domain computer?
 
02. To have secure connectivity, IF the security policy force client to check "Validate server certificate", which certificate it is look for? Is it ACS's identity certifate, that require CA server to sign on the CSR?
 
03. Back to client side, should the client also need to import this certificate in trusted root certification authorities?
 
Or the client will trust ACS identity certificate against the root CA certificate store at client's trusted root certification authorities, where they have the identical issuer?
 
04. Extra question: If no CA environment, would it be sufficient simply export ACS self-signed certificate and import to client computer, and it's trusted?

View 3 Replies View Related

Cisco Wireless :: 3500 / 3600 - Post 7.2.111-3 Upgrade Lost All APs?

Feb 8, 2013

Lost my access points to controller.  Not sure if it was related to upgrade from 7.1 to 7.2, or something else.
 
The console log on APs shows; 
 
*Mar  1 00:01:09.394: %CAPWAP-3-ERRORLOG: Go join a capwap controller
*Jan  1 10:24:23.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 142.100.64.8 peer_port: 5246
*Jan  1 10:24:23.424: %DTLS-5-ALERT: Received FATAL : Certificate unknown alert from 142.100.64.8
*Jan  1 10:24:23.424: %CAPWAP-3-ERRORLOG: Bad certificate alert received from peer.
*Jan  1 10:24:23.424: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 142.100.64.8:5246
*Jan  1 10:24:23.424: %CAPWAP-3-ERRORLOG: Invalid event 38 & state 3 combination.
  
All 3500/3600 APs, had been in production for months.

View 1 Replies View Related

Cisco Wireless :: 3500 / 3600 - Wireless Deployment In Warehouse

Aug 29, 2012

I am doing a predictive survey for a very large mixed environment facility.I have advised this customer that it would be best to have a professional site survey done and he understands but has requested I do a preliminary predictive survey and recommendation.  This will have both open area manufacturing and also warehouse type areas with 18ft racks and cages, The actual ceiling height is approx. 30 ft. but the building steel I-Beams are at 18 ft and would be the mounting height of the AP. I already have several installs in other buildings with the exact same structure and setup using 1242 AP and AIR-ANT2465P-R and AIR-ANT5170P-R patch antennas mounted to a board, pointing down and at 18ft.

My question is: I would like to use either the 3500E or 3600E AP with diversity patch antennas (3600E & air-ant2566 for example) but see that Cisco also recommends the 2dbi stubby Omni dipoles in this type environment. I'd just like to get some opinions and thoughts on AP and antennas.

View 3 Replies View Related

Cisco Wireless :: How To Enable 100mbps Speed On WLC 2504 With 3600 AP

Sep 13, 2012

i have cisco wlc 2504 connected with cisco 3600 ap,now the customer required n bandwidth speed ,but in wlc am not able to enable n bandwidth for ssid.in radio policy of ssid also n bandwidth is not showing,only this bandwidth showing a/g,g,b/g, and all?

View 8 Replies View Related

Cisco Application :: 3500 - Enable XML-HTTPS Protocol In ACE

Mar 9, 2011

I'm configuring ACE to enable the XML-HTTPS interface so I can import it into ANM, when I try to do a "match protocol xml-https any", I get a invalid command detected. When I tab at the match protocol command, I don't see xml-https listed (http, https, icmp, etc. is listed).

View 2 Replies View Related

Cisco AAA/Identity/Nac :: 3600 - EAP-TLS Machine Authentication ACS 5.2?

Mar 26, 2012

we have a customer with a wifi deployment aruba 3600 controller based. Corporate SSID authentication is EAP-TLS double machine and user authentication through ACS 4.2 against AD and Microsoft AC PKI infraestructure based; it was working ok. After migrating from ACS 4.2 to 5.2, both authentication (machine and user) are reported as succeed by ACS but aruba controller does not recognize machine authentication. It seems that controller sees two authentication users and not an machine followed by and user one. We have revised configuration in detail and it seems correct. We begin thinking it could be a bug .

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 For Wireless Authentication Using Radius?

Jul 4, 2012

how to setup ACS 5.3 to authenticate wireless users over radius? I currently have the SSID pointing to a Microsoft IAS server and would like to move the authentication to be done via ACS.

View 1 Replies View Related

Cisco Wireless :: Radius Authentication With Aironet 1140?

Mar 28, 2012

I try to setup a 1141 aironet AP to authenticate my user through our Ms Radius Server ( Win 2008 R2).Everything is fine with small Bussiness AP WAP4410N with the following configuration:But I can't setup successfully the aironet 1141 with the same settings and getting it works.Here is my configuration for the Aironet 1141 Vlan 1 is the ssid I want to get it work with Radius.  

View 1 Replies View Related

Cisco :: Wireless AP1140 Radius Authentication With Microsoft IAS

Sep 3, 2011

I have a Cisco C1140 Ap. I have cnfigured the device. Initially for testing i used WPA and authenticated locally. I have now setup a radius server and added my AP in as a client etc. I have changed my SSID's to authenticate with the radius server and i am having issues authenticating.I can connect via a PC and an iphone. They say that i am connected but i get no ip address and the debugs.

View 1 Replies View Related

Cisco Wireless :: WLC 5508 No Further RADIUS Authentication Requests?

Mar 18, 2013

I'm working on a project where a wi-fi client is tracked and located using RADIUS authentication requests. The problem I'm running into is that the WLC (5508) sends an RADIUS authentication request to my freeradiusd, which is ok so far, but if the client roams to another accesspoint (3602AG, 1131AG, 1252AG), the WLC does not send a further RADIUS auth. request - and the client is allowed to connect to the next ap.Is there an option like RADIUS-cache which I can disable, so that the WLC sends everytime an authentication request when a client tries to connect to an ap or roams from one ap to another one?

View 4 Replies View Related

Cisco Wireless :: 2504 - 802.1x Radius Dual Authentication

Jun 20, 2012

I configured the 2504 with 2 SSIDs for staffs and guests.I also configured the Lobby admin with web auth. But if a guest wants to connect our wireless he/she has to enter the PSK key and then only they are able to connect with the user id and password given by Lobby admin. Can we avoid this key and let the guests connect straightaway with the web auth?I’m planning to configure 802.1x & Radius dual authentication for staffs SSID..

View 5 Replies View Related

Cisco Wireless :: 5508 Controller With Radius Authentication

Feb 16, 2012

I am setting up a WIFI network with a Cisco 5508 controller. I want  to configure a first WIFI network (WIFI1) that will authenticate my  business laptop based on the AD computer accounts and will access my  corporate network.I want to setup a second WIFI network (WIFI2) that will authenticate  my phones and tablets devices with AD user accounts and will be on a  separate vlan with only access to the Internet.I created 2 policies on the Radius server : one that authenticate  computers coming from wireless and a second one authenticating users  coming from wireless.
 
if a user manually creates the WIFI1 network on his phone  and enter his AD username, he is going to have access to the corporate  network.  I would like to be able to say that when a request is coming  from WIFI1, only the policy for authenticating  wireless devices with computer accounts will apply and the second  policy authenticating user wouldn't apply.

View 1 Replies View Related

Cisco Wireless :: Radius Server Authentication AIR-AP1231G-A-K9

Apr 30, 2012

Below is he output from debug radius authentication from my AP.
 
I can see request is forwarding from AP to radius but Radius is not sending any response.Not sure why its not responding.
 
I also did not under stand few out outputs also
no sg in radius-timers and
RADIUS/DECODE: parse response no app start; FAIL
what does it mean.
 
I  restarted radius server , changed secret key but no luck.
 
019639: May  1 16:15:08.727: RADIUS:  User-Name           [1]   32  "host/3KYGRH1.idcap.intdata.com"
019640: May  1 16:15:08.727: RADIUS:  Framed-MTU          [12]  6   1400
019641: May  1 16:15:08.727: RADIUS:  Called-Station-Id   [30]  16  "0012.01d6.f691"
[Code]...

View 4 Replies View Related

Cisco Wireless :: C1200 Client Authentication Is Against RADIUS Server

Jan 9, 2013

i am trying to connect clients to my AP1231 which is running C1200 Software (C1200-K9W7-M), Version 12.3(8)JED. Client authentication is against RADIUS server. [code]

View 3 Replies View Related

Cisco Wireless :: WAP321 - Radius Authentication For Captive Portal

Aug 1, 2012

I'm fighting for a few days now to setup the captive portal of 2 wireless access point WAP321. I was able to make it work with local user authentication but now, I want to manage my guest users on active directory. So I setup the captive portal to authentication user with NPS on Windows 2011 SBS.

The problem is that my guest SSID in not encrypted, so the NPS server do not let me login. I try to setup the NPS server like that :

Uncrypted authentification (PAP, SPAP)
Service-Type : Login

View 2 Replies View Related

Linksys Wireless Router :: W610N Cannot Login - Authentication Failed

Jun 15, 2011

I use IE7.0 
192.168.1.1
user name : admin
password : admin
 
Error is saying "401 Authorization required" Browser not authentication-capable or authentication failed.

View 9 Replies View Related

Cisco Wireless :: OEAP 600 Cannot Join WLC With Authentication List Enable

Mar 17, 2012

I've got a strange problem here. In the office, my OEAP 600 can join WLC if there is no MAC authentication. When i enable MAC authentication at WLC, AP will fail to register. However, I try it at home and it works with both MAC authentication enable or disable. I suspect it is because of firewall in my office, but there shouldn't have any different in discovery and joining procedure for AP with MAC authentication enable or disable.

View 18 Replies View Related

Cisco :: (login) Command Bypasses RADIUS Servers

Jan 21, 2013

I have RADIUS servers configured to authenticate administrative users and authorize them at a low level. This is working well. I also have a local level-15 user in case all of my RADIUS servers time out and someone needs to change something. This also works well. The issue I'm having is that a low-level user can log on using the RADIUS severs, then issue the "login" command and enter the local level-15 user's credentials and then operate at level 15.

I do not want the local account to work at all, except in the case that all RADIUS servers are unavailable. What I've described above works around this. How to disable the "login" command or force it to try RADIUS servers first? This is for ASA 8.2

View 4 Replies View Related

Cisco AAA/Identity/Nac :: 7204 - Radius Auth For Login And VPN Conflicts

May 15, 2011

Im trying to configure a 7204 for radius login authentication, although the router is also configured with radius for VPN access. How can I configure it for both using 2 different raidus servers? the login via radius is working fine on another router, although that one is not doing VPN access so there's no conflict.
 
My config:
 
aaa group server radius RADIUS_AUTH      server x.x.3.11 auth-port 1645 acct-port 1646
aaa authentication login networkaccess group radius local

[Code]....

For some reason, this does not work. I cannot access the router and authenticate via x.x.3.11 radius server. I think there's a conflict between the VPN and the login authentication but im unsure how to resolve this.

View 3 Replies View Related

Cisco VPN :: SSL VPN Authentication Using Radius ASA 8.4

Apr 25, 2011

I am running ASA version 8.4(1), and anyconnect version 3.0.1047. My SSL VPN works fine, but i run into an issue with one user . his account did not work , and everytime users logged in it got this message "VPN Server could not parse request".
 
I found the problem after getting a user information meaning his username and password. His password had "&" as one of the special characters. when we change it to something that does not have that , it works just fine.
 
We are using microsoft NPS server as radius. but when i run a test within CLI it works just fine, only when anyconnect asks to authenticate it fails.

View 5 Replies View Related

Cisco Security :: Setup 3750e Switch To Login Through Radius Server

Aug 13, 2012

'm able to setup my 3750e switch to login through a radius server with my company user id and password but would like to be able to set it up that when I log in it drops me on the enable prompt. Right now I have to type >en.Then the enable password.

View 1 Replies View Related

Cisco :: Radius Authentication Time

Aug 6, 2012

Any software to measure Authentication time between client and Radius serverr.

View 8 Replies View Related

AAA/Identity/Nac :: IPS / IDS Authentication With Cisco Radius ACS 5.2

Nov 22, 2011

I have been trying to get our IPS (ASA-SSM-10 and 4260) to authenticate with Cisco Radius ACS 5.2 and they are not working. However, I was able to get them working with Microsoft Radius. Below is the logs from the IPS:
  
evStatus: eventId=1321566464942057375 vendor=Cisco  originator:    hostId: NACAIRVIDLAB1    appName: authentication    appInstanceId: 350  time: 2011/11/23 17:50:38 2011/11/23 09:50:38 GMT-08:00  controlTransaction:

[Code].....

View 0 Replies View Related

Cisco :: WCS 7.0.220.0 Authentication With RADIUS Microsoft NPS?

Nov 14, 2011

I'm running WCS 7.0.220.0.I would like to authenticate users that are able to logon the WCS, through MS Network Policy Service (RADIUS).I would like all my domain users to be member of the local group on the WCS "Lobby Ambassador", so all domain users has access to generate guest access accounts, for the web auth... I can see under the WCS Administration under AAA that it should be able to use RADIUS - but i'm not sure how to setup the NPS policy?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Radius Authentication In ACS 5.2 With AD

Mar 10, 2011

I have a questión about radius authenticaction with AD, when I log in into the network with user in AD and I make a mistake in password my radius authenticaction event in ACS 5.2 dont show me this logg. only show the authentication succeeded but dont show me the authentication failed. Maybe i must to enable same service to show the authentiaction failed. The Voice authetication works fine..
 
This is the confg in the port of the switch:
 
interface FastEthernet0/12 switchport mode access switchport access vlan 2 switchport voice vlan 10 authentication port-control auto authentication host-mode multi-domain authentication violation protect authentication event fail action authorize vlan 11 authentication event fail retry 2 action authorize vlan 11 authentication event no-response action authorize vlan 11 authentication periodic authentication timer reauthenticate 60 mab dot1x pae authenticator dot1x timeout tx-period 10 dot1x max-reauth-req 3 spanning-tree portfast end
 
Vlan 2: DATA
Vlan 10: VOICE
Vlan 11: GUEST

View 1 Replies View Related

Cisco :: Can't Do Radius Authentication Via WLC 4400

Jan 3, 2013

I am configuring an old WLC4400 with V4.2.130.0. I added a new sub-interface for VLAN 50 with proper IP for the subnet and then add the Radius server(Windows server 2008 with NPS) onto WLC4400. I then created new WLAN with WPA+WPA2 Encryption and 802.1x key management and selected the Radius server under AAA for authentication.
 
Configured the test XP with WPA-Enterprise and PEAP as EAP method. I purposely configured computer to prompt for username and password.
 
When I try to connect, I did get prompt for username and password. However after that nothing happens. It seems like laptop just keep trying to authenticate.
 
I checked windows event log and do not see anything under NPS. I know this windows server NPS setup works as it is also the authentication server for our remotevpn.
 
is there any special option I need to turn on for WLC in order for Radius authentication work? Or is there any known bug with V4.2.130.

View 13 Replies View Related

Cisco VPN :: ASA 5520 VPN With Radius Authentication?

Aug 11, 2011

I'm in the process of moving some of our remote access vpn to an asa5520 and anyconnect.
 
The problem I've come across is that when using radius as authentication, I choose any one of my connection profiles in anyconnect and log in with any username regardless of the group on radius.
 
How do I map the connection profile to a group on radius so that i can separate the users?

View 1 Replies View Related

Cisco Switching/Routing :: AAA Radius Login On 3560 Locks Domain-account

Jul 22, 2012

I´ve a little problem with the aaa authentication over RADIUS with a Cisco 3560G-48PS - IOS 12.2(58)SE2. When I try to log in to the Switch per Telnet, it didn`t works and my windows domain account is locked. Here the aaa config:
  
aaa new-model 
aaa authentication login default local group radius
aaa authorization config-commands

[Code].....

View 1 Replies View Related

Cisco Firewall :: Getting ASA 5510 Radius Authentication

May 17, 2011

I have a 5510 authenticating successfully with a RADIUS server.  I'm using it for VPN authentication and it works great.  I would also like to do this for administrator access to the ASA.  When I turn it on though, any authentication for VPN access is also granted administrative access to the ASA.  Obviously, I need to limit that to a select few users. 

View 1 Replies View Related

Cisco WAN :: Best RADIUS Server For 802.1x Wired Authentication?

Sep 2, 2012

which is the best RADIUS server for 802.1x wired authentication?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Authentication Radius Juniper NSM?

May 24, 2011

I am trying to authenticate on Juniper NSM express using cisco ACS 5.2.  The request is arriving at the cisco ACS but i am getting the following error.RADIUS requests can only be processed by Access Services that are of type Network Access.

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.0.2 Radius Authentication Setup

Jan 9, 2012

I am having ACS 4.0.2 in my network, which I want to use for 802.1x Radius Authentication for Clients on PEAP-MSCHAPv2 methodology.As per the documentation " EAP Authentication with RADIUS Server",  Doc ID: 44844.I have configured Network Configuration and populated AAA client IP range and Secret Key.
 
Question1: Under Authenticate Using option, there are various RADIUS flavors available for selection. For a Non Cisco AAA client, should I select RADIUS IETF?

Question 2: In the above snap shot, It has an option called Global Authentication Setup, where we can setup EAP configuration. Under PEAP subsection there is an option to "Allow EAP-MSCHAPv2" check box.After checking that, is a restart required to the ACS Server? Would it cause any disruptions to the existing services on the ACS?

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved