Cisco Wireless :: WLC 5508 Support IPSec To Radius Server?

Jan 23, 2013

I am trying to follow the Fips guide for the WLC5508 and it wants to encrypt the connection to the Radius, either with PSK key wrap or IPsec. I have the options for Ipsec only as the Windoes NPS does not support Key wrap from what a previous user confirmed for me here on the board.. But then found another post that states that the 5508 does not support IPsec?

View 5 Replies


ADVERTISEMENT

Cisco Wireless :: Does WLC 5508 (7.2) Support PEAP To MS Radius

Oct 9, 2012

I'm running version  7.2.111.3 on my WLC 5508 and I try to figure out how I can set PEAP towards my configurerd Radius servers. On my Local EAP profile I can specify PEAP, but how is it default configurerd when you just specify the radius servers on the "WLANs > Edit Test > security > AAA servers tab ?
 
The MS radius logs tell me that it is EAP and not PEAP, so the questions is does the WLC support Microsoft: Protected EAP ???
 
Dot1x_NW_MsgTask_0: Oct 10 11:02:27.279: 24:77:03:07:75:28 AAA EAP Packet created request = 0x1bd4647c.. !!!! -> should be AAA PEAP ?
*Dot1x_NW_MsgTask_0: Oct 10 11:02:27.279: 24:77:03:07:75:28 Sending EAP Attribute (code=2, length=35, id=2) for mobile 24:77:03:07:75:28*Dot1x_NW_MsgTask_0: Oct 10 11:02:27.280: 24:77:03:07:75:28 [BE-req] Radius  EAP/Local WLAN 3.

View 6 Replies View Related

Cisco Wireless :: 5508 WLC With ISE As Radius And Also External Web Server

Jan 30, 2013

I am biulding a wireless network with 5508 WLC and trying to use ISE as radius server and also to redirect the web-login to it.I was trying to understand that to achieve the external web-login, do i need to use the raduius-nac option under advanced on the guest wireless where i am trying this out. and if not, where do i actually use it?So far what i have understood that i do need to have preauth ACL on the Layer 3 security, but the issue is there is no hit reaching the ISE.

View 9 Replies View Related

Cisco Wireless :: Configuring Microsoft Radius Server For 5508?

Apr 28, 2013

I would like to know if microsoft 2008 server RADIUS server could be use for authentication on Cosco 5508 instead of Cisco ACS.

View 4 Replies View Related

Cisco Wireless :: 5508 - RADIUS Server Activated / Deactivated On WLAN X

Sep 18, 2011

Since I moved our WLC Controller ( 5508 ) from Version 7.0 to Version 7.2.111.3 I got above failure messages. Until now I changed the radius timeout from 2 to 10 seconds and also I disabled the aggressive failover without success. What else it could be ?

View 3 Replies View Related

Cisco Wireless :: WLC 5508 - Configure IPSec Between WLC And Server 2008 NPS?

Dec 13, 2011

I have been unable to get IPSec working between my WLC 5508 and a server 2008 NPS radius server. Any luck configuring this?  I have opened tickets with both Microsoft and Cisco, but so far have not been able to configure it properly. 

View 2 Replies View Related

Cisco AAA/Identity/Nac :: 5508-WLC Using MS NPS As RADIUS Server For EAP-TLS

May 18, 2011

getting a Cisco WLC to work with MS NPS server? We've done it before albeit with differnt code versions.
 
I have a Cisco 5508 WLC running 7.0.116.0 code hosting a WLAN configured for WPA2 with 802.1x for authentication.  I have two Windows NPS servers configured as the RADIUS servers for EAP-TLS authentication. Via debug info on the WLC I can see the 802.1x handshake take place with the wireless client and the WLC as well as a successful transmission of an Authentication Packet from the WLC to one of the RADIUS servers. However on the WLC I see repeated RADIUS server x.x.x.x:1812 deactivated in global list and on the NPS server I'm seeing event log errors indicating "The Network Policy Server discarded the request for a user"  along with the pertinent auth request info that I would expect the NPS server to receive from the WLC.  Based on the WLC debug info I'm never actually getting to the EAP-TLS certificate authentication part. It seems the NPS servers don't like the format of the initial RADIUS authentication request coming from the WLC and so don't respond whcih in turn casues to WLC to switch to the other NPS server which produces the same issue.

View 2 Replies View Related

Cisco :: 5508 RADIUS Server Failed To Respond To Request

May 22, 2013

We are experiencing a lot of these RADIUS failed to respond messages on our WLC's leading to a lot of RADIUS server hopping within the WLC.We are using Cisco 5508's, 1142 AP's and a Microsoft NPS RADIUS backend. SSID is WPA2+802.1xThe first workaround to this problem was to disable aggressive failover on the WLC. But this is only a temporary fix, because in the end, there will be more than 3 consequetive clients, failing to authenticate to the WLAN network. As a result, the WLC will swap to the 2nd RADIUS server configured.When we dived into this a little bit more we saw the following messages being logged on the RADIUS backend at the time we saw the RADIUS messages on the WL:Event ID: 6274: Network Policy Server discarded the request for a user.

View 16 Replies View Related

Cisco Routers :: Can RV042G IPSec VPN Support Apple IOS IPSec VPN

Apr 29, 2013

I tried any type of combination and just couldn't make it works.  Only PPTP works well. Whether Apple iOS IPSec VPN is supported or not?

View 11 Replies View Related

Cisco Wireless :: 5508 Get Access To AP Via Radius

Feb 1, 2012

i have configured 35 APs 3502i in 5508 WLC, now i want to get access to ap via radius. Currently i can connect to them via SSH with both user and password set in wireless> access point > global configuration, well, how do i configure the management AP user  through RADIUS?

View 2 Replies View Related

Cisco Wireless :: WLC 5508 Radius Accounting

Jun 5, 2013

I have a WLAN configured with 802.1x PEAP pointing to an external RADIUS server.  It works fine for the most part, but I'm having problem closing accounting sessions in RADIUS.  I've found this is related to the client table in the WLC.  The user session does not end in RADIUS unless the WLC officially removes the client from the db, which takes 5-6 minutes from what I can see (probably due to the default idle timeout of 300 seconds). 
 
For example:
 
1.  I connect my tablet to the test WLAN.  It associates and authenticates successfully and the WLC sends the accounting info to my RADIUS server, opening up a user session.  If I turn off the wifi in the tablet, the client entry stays in the WLC client table until it times out.  The WLC removes my tablet from the client table after 5-6 minutes, and then the session closes in the accounting table.  I can force the session to close much earlier by manually removing the client from the WLC.
 
2.  Same as #1, but this time instead of turning of the wifi in the tablet, I choose to connect to a different WLAN in the WLC.  The user session in the accounting DB never closes.  If I reconnect back to the original test WLAN with 802.1x, it opens up yet another user session in RADIUS accounting.  Now I have a "dead" user session in accounting that is going to be open forever unless I delete it from SQL.
 
Is this an issue with the end user client not sending the disassociation frame properly, or a config problem with the WLC?  How can I make it so that every time a client drops from an AP or moves to a different WLAN, the WLC would immediately send accounting updates to my RADIUS server and close the user session properly?

View 1 Replies View Related

3100 - No Support Of Radius Security On Wireless Adapter

Jan 6, 2013

I recently got a refurbished external (USB) wireless adapter by Netgear. It's the WNA3100 but who knows what they did to it while refurbishing it.

I tried using it to connect to the wireless network at my university, and I got the above-displayed error. So what's the deal? This RADIUS thing is not a new technology, right? So any modern wireless adapter should be able to handle it. Why would this thing not support it?

Secondly, if it doesn't work, that's alright. I need a second wireless adapter anyway, so I could use this one at home where the RADIUS thing is not an issue. But how do I make sure this does not happen again with another one that I buy? I can't seem to find anywhere in the specs anything about this compatibility. For instance, I believe I want to get this one next:URL

View 15 Replies View Related

Cisco Wireless :: WLC 5508 No Further RADIUS Authentication Requests?

Mar 18, 2013

I'm working on a project where a wi-fi client is tracked and located using RADIUS authentication requests. The problem I'm running into is that the WLC (5508) sends an RADIUS authentication request to my freeradiusd, which is ok so far, but if the client roams to another accesspoint (3602AG, 1131AG, 1252AG), the WLC does not send a further RADIUS auth. request - and the client is allowed to connect to the next ap.Is there an option like RADIUS-cache which I can disable, so that the WLC sends everytime an authentication request when a client tries to connect to an ap or roams from one ap to another one?

View 4 Replies View Related

Cisco Wireless :: Can Use WLC 5508 With OpenLDAP Directly (without Radius)

Dec 18, 2012

Can I use WLC 5508 with OpenLDAP directly (without radius) ?

View 1 Replies View Related

Cisco Wireless :: 5508 Controller With Radius Authentication

Feb 16, 2012

I am setting up a WIFI network with a Cisco 5508 controller. I want  to configure a first WIFI network (WIFI1) that will authenticate my  business laptop based on the AD computer accounts and will access my  corporate network.I want to setup a second WIFI network (WIFI2) that will authenticate  my phones and tablets devices with AD user accounts and will be on a  separate vlan with only access to the Internet.I created 2 policies on the Radius server : one that authenticate  computers coming from wireless and a second one authenticating users  coming from wireless.
 
if a user manually creates the WIFI1 network on his phone  and enter his AD username, he is going to have access to the corporate  network.  I would like to be able to say that when a request is coming  from WIFI1, only the policy for authenticating  wireless devices with computer accounts will apply and the second  policy authenticating user wouldn't apply.

View 1 Replies View Related

Cisco :: 5508 - NPS Radius

Apr 10, 2013

Cisco WLC 5508
Software Version: 7.4.100.0
Windows Server 2008R2
  
I've got everything setup on the Windows Server 2008 side of things (certificates, radius clients, etc). I added the radius server on the WLC, and configured a new W LAN to use it. Both are on the same sub net. When trying to connect to the W LAN it kept failing.  I installed wire shark on the server to monitor the radius traffic, and to my surprise there was no radius traffic showing up on the server.  The radius statistics on the WLC are at 0 as well, so it's like the WLC isn't even attempting Radius.
 
I re verified that the server was enabled on both the security tab and the W LAN itself on the WLC.  Rebooted the controller and the server, all to no avail.  I used a radius test client, and can successfully send radius commands to the server using that utility. Frustrated, I just kept trying to reconnect on my wireless device, and after about the 15th try, finally I saw radius activity on wire shark.  It rejected my access, but at least I saw activity.  It also registered radius statistics on the WLC as well.
 
So now if I keep trying to connect repeatedly, about every dozen or so times the WLC actually will send a radius request to the server.

View 8 Replies View Related

Cisco AAA/Identity/Nac :: ACS5.3 - Difference Between WebVPN And IPSEC Radius

Aug 14, 2012

I am using Cisco ACS5.3 to authenticate users (using radius) for a cisco ASA firewall for both WebVPN and IPSEC client connections.  I have been able to do this successfully.  However I need to be able to deply Cisco vendor specific attributes (VSA) for both IPSEC and WebVPN sessions using authorisation profiles.   Ideally I don't want to have to combine the attributes required for both services in the same authorisation profile, as I will have to produce alot of different profiles for the different combinations.
 
The only way I can see that you could possibilly do this is by having service selection rules that can differentiate between WebVPN and IPSEC Radius authentication requests.  I have experimented inbound VSA's without success.  Is this possible?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 5508 - ISE To Support Wireless LWA

Dec 14, 2011

How Cisco Identity Service Engine (ISE) can work with  WLAN controller 5508 to do the Local Web Authentication, on behalf tje  guest profile is create using Cisco ISE guest management?
 
As i check Cisco ISE caveat wireless only support on LWA, and LWA not supported on Authorization's VLAN assignment.
 
what i need to concern abou the ISE authentication and  authorization policy on behalf on Wireless LWA with use of ISE guest  management case?

View 1 Replies View Related

Cisco Wireless :: Radius Server Requirement With Wlc 2504?

Jul 12, 2012

I want to know if its nessary to install Certificate authority on your radius server. If we have a CA server already in the domain can we use that for this purpose or we have to install certificate authority on our DC. 

View 1 Replies View Related

Cisco Wireless :: Radius Server Authentication AIR-AP1231G-A-K9

Apr 30, 2012

Below is he output from debug radius authentication from my AP.
 
I can see request is forwarding from AP to radius but Radius is not sending any response.Not sure why its not responding.
 
I also did not under stand few out outputs also
no sg in radius-timers and
RADIUS/DECODE: parse response no app start; FAIL
what does it mean.
 
I  restarted radius server , changed secret key but no luck.
 
019639: May  1 16:15:08.727: RADIUS:  User-Name           [1]   32  "host/3KYGRH1.idcap.intdata.com"
019640: May  1 16:15:08.727: RADIUS:  Framed-MTU          [12]  6   1400
019641: May  1 16:15:08.727: RADIUS:  Called-Station-Id   [30]  16  "0012.01d6.f691"
[Code]...

View 4 Replies View Related

Cisco :: For RADIUS Integration Between WLC 5508 And MS NPS

Nov 3, 2012

We are trying to integrate Cisco WLC 5508 and Microsoft NPS 2008 to allow users to use their AD username and password to authenticate to the wireless network.I basically followed the following document but with no luck (Appendix B): URL I'v went through some threads in this forum but also with no luck,Basically, we are recieving the follwoing error in NPS event viewer:A RADIUS message was received from RADIUS client a.a.a.a with an invalid authenticator. This is typically caused by mismatched shared secrets. Verify the configuration of the shared secret for the RADIUS client in the Network Policy Server snap-in and the configuration of the network access server.

View 2 Replies View Related

Cisco Wireless :: 2504 Vs 5508 Support For 200 Laptops

Aug 10, 2012

I have a customert that needs to support 200 laptops over 16 classrooms with scalability to 400 laptops. I have a heatmap design to cover this with 22 1042 access points. Does any one know what features the 5508 has over the 2504? By reviewing the data sheets, the biggest feature difference is better support for mobility, which not a need for this deployment as they just wheel a cart of laptops into a classroom and fire them up. Also, does the 2504 support LAG across the four gig interfaces?

View 1 Replies View Related

Cisco Wireless :: 5508 Controller In HA Mode Support

Jun 6, 2011

is there a support of 1+1 mode (HA mode) at 5508 Controller? If yes Is there a HA bundle or do we have to order two identical 5508 controller ?

View 6 Replies View Related

Cisco Wireless :: C1200 Client Authentication Is Against RADIUS Server

Jan 9, 2013

i am trying to connect clients to my AP1231 which is running C1200 Software (C1200-K9W7-M), Version 12.3(8)JED. Client authentication is against RADIUS server. [code]

View 3 Replies View Related

Cisco :: How To Set Up 2008 (NPS And NASs) RADIUS Server For 802.1X Wireless Clients

Sep 25, 2012

how to set up 2008 (NPS and NASs) RADIUS Server for 802.1X Wireless clients.

View 1 Replies View Related

Cisco Wireless :: Configuring RADIUS Server On 2500 Controller

Dec 3, 2012

We have recently installed Cisco for our wireless solution. We are an education and are looking to let staff and pupils bring their own devices. The route that we are planning to take to let them join the school's WiFi is to implement a RADIUS server so that they can authenticate with their Active Directory username and password. I have tried to test the solution but so far without any success. I am using a Windows Server 2008 R2 as my NPS server, I have setup the Cisco controller as per below:
Security Tab | RADIUS | Authentication - I added my windows server there and the preshared key, the Network User and Management is ticket and the server responds to a ping command,In the WLANs Tab, I selected my test WLAN and under Security | AAA Servers I selected the RADIUS server that I configured in the Security TabI then try to logon to my test WLAN and on the Cisco WLAN controller I get the following error: AAA Authentication Failure for UserName:test User Type: WLAN USER 
Before trying to tinker with policies on the Windows Server I was wondering if the RADIUS is correctly setup on the Controller or have I missed something obvious?

View 6 Replies View Related

Cisco Wireless :: AP541N With Windows 2008 Radius Server?

Jan 24, 2011

I am trying to connect an AP541N to a radius server for Domain authentication but cannot figure out how to Configure the widows 2008 Radius server to authenticate users but cannot seem to get the AP541N to do this, how to configure both the 2008 radius server and also the AP541N?

View 2 Replies View Related

Cisco :: 1130AG Access Point Module Will Support Radius

Nov 4, 2012

In our Environment we used to Connect to wifi using   Radius Authentication Through AD Account  (Encryption: TKIP and  CIpher, Authentication Open+EAP and Network EAP,  Key management WPA) this settings  which will be done And pushed through AD Itself.We Use CIsco 1130AG, 1200 Series in most of the areas which have no Issues.But We Have Some trouble with Cisco WAP4410N Access point.In This Access point users were not able to Connect to wifi through Radius Authentication.However users were able to Connect  to these Access point, but  it is unsecured, whoever configure's the correct client settings in their PC. They can connect to SSID. This Access point is capable of supporting Radius Authentication?

View 4 Replies View Related

Cisco :: Using 5508 To Authenticate Local First Then Radius?

Sep 8, 2011

I am transitioning from RADIUS auth to local auth and i don't want to hassle everyone to change in one hit.If i can get auth requests to look in the WLC local net db first and if not found try RADIUS then this is what i am after! You can easily do it with web auth but doesnt seem so easy via WPA2 method.

View 1 Replies View Related

Cisco :: 5508 / Radius Authentication Not Working?

Apr 8, 2013

I have a 5508 controller running 7.4.100 and have a WLAN where I have radius configured. On my controller the client machine I'm using appears but the radius authentication doesn't appear to be working. Is there anything on the controller I can do to verify that the request is even being sent to my Microsoft IAS server? The log on the server doesn't show any requests from the controller so my early days guess is the controller isn't actually sending it.

View 3 Replies View Related

Cisco :: Controller 5508 With RADIUS Authentication

May 6, 2013

I'm a trainee in Network and Telecommunication, and I have to do a "model" with a controller, an AP, and a RADIUS server. Communication and configuration of the lightweight AP has been done.
 
I use an autonomous access point 1220 as the RADIUS server (no considering it as an AP), and I'm a beginner in RADIUS configuration. I get a "Processing AAA Error 'No Server' (-7) for mobile 00:24:d6:8f:2c:7e" when I launch a debug targetting my PC, connecting to the LAP.
 
Precursory : 10.137.125.71 is the IP address of the ap1220, working as the RADIUS server 10.137.125.15 is the IP address of the controller. 00:24:d6:8f:2c:7e  is the MAC address of my PC, connecting to the Wi-Fi. ping works to the RADIUS, to the controller. Each devices are connected by a layer 3 Switch, and ping each others. The Wi-Fi works when I don't use 802.1X (or when I don't use RADIUS authentication at all)
 
What I did on the RADIUS server (ap1220 autonomous) :
 
aaa new-model
radius-server local
nas 10.137.125.15 key password

[Code]......

View 5 Replies View Related

Cisco Wireless :: 7500 Can Use Customer Radius Server In Order To Authenticate

Feb 5, 2013

We use a Flex7500 with local switching and centeral authentication. My question is can i use the Customer's radius server in order to authenticate? or should my WLC have IP conncetivity to any radius server im adding?I guess what i'm really asking is should my WLC know the radius server or does the request can go back to the AP and from there to customer radius on his subnet?

View 6 Replies View Related

Linksys Wireless Router :: E4200 Isn’t Communicating To The NPS / Radius Server

Dec 17, 2011

Attempting to configure Linksys e4200 router in WPA2 Enterprise mode. Got this setup fine when using the Linksys WRVS4400N (That is until it died on me, RIP circa 2 months ago). I’m getting nothing in the NPS logs, nothing when doing a PCAP at the radius server. It appears this router isn’t communicating to the NPS/Radius server.

View 6 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved