<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple SSIDs/VLAN - NPS Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242106#M126283</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is still not working for me.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Call Station ID enabled and .*:GatewayIT$&amp;nbsp; in the field my authentication failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I simply uncheck Call Station ID the RADIUS server authenticates my session.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not see anything in relation to this in the even log.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on where to go next?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Jul 2013 20:22:40 GMT</pubDate>
    <dc:creator>Gateway Church</dc:creator>
    <dc:date>2013-07-02T20:22:40Z</dc:date>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242102#M126279</link>
      <description>&lt;P&gt;I have recently set up a similar network using Ruckus equipment; however, need to do it now with Cisco...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a multiple SSIDs associated to different VLANs broadcasting.&amp;nbsp; I would like to configure a single Radius server pointed to my NPS server and allow for authentication by group to each SSID.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Ruckus I had to put in a vendor specific custom attribute and then use Roles to allow access by AD Security Group.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know how to setup something similar with Cisco?&amp;nbsp; I just need a single group to be able to autheticate to each SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Josh Price&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:35:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242102#M126279</guid>
      <dc:creator>Gateway Church</dc:creator>
      <dc:date>2019-03-11T03:35:35Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242103#M126280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is pretty straightforward. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just create a NPS policy for each SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A simple policy could check 3 conditions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Windows Groups = DOMAIN\GroupABC&lt;/P&gt;&lt;P&gt;Called Station ID = .*:SSIDNAME$&lt;/P&gt;&lt;P&gt;NAS Port ID = Wireless IEEE or Wireless Other&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just change SSIDNAME to whatever the specific SSID is, and obviously the group that you want mapped.&amp;nbsp; The SSID condition uses regex.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jun 2013 12:03:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242103#M126280</guid>
      <dc:creator>petermitchell</dc:creator>
      <dc:date>2013-06-30T12:03:49Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242104#M126281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agree with peter. In case it doesn't work, please refer the NPS event viewer logs and check in case it's not hitting the right network access policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jun 2013 12:09:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242104#M126281</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-30T12:09:57Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242105#M126282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Peter: Nice answer. +5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jul 2013 08:14:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242105#M126282</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-07-01T08:14:13Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242106#M126283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is still not working for me.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Call Station ID enabled and .*:GatewayIT$&amp;nbsp; in the field my authentication failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I simply uncheck Call Station ID the RADIUS server authenticates my session.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not see anything in relation to this in the even log.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on where to go next?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 20:22:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242106#M126283</guid>
      <dc:creator>Gateway Church</dc:creator>
      <dc:date>2013-07-02T20:22:40Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242107#M126284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Under Called Station ID, simply use &lt;STRONG&gt;*GatewayIT&lt;/STRONG&gt; and try again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 20:29:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242107#M126284</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-02T20:29:49Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242108#M126285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No luck.&amp;nbsp; I see where the formatting is coming from.&amp;nbsp; On the controller you can set:&lt;/P&gt;&lt;P&gt;Config&amp;gt;radius&amp;gt;callstationidtype&amp;gt;ap-macaddr-ssid - Sets Call Station Id Type to the format &lt;APMACADDRESS&gt;:&lt;SSID&gt;&lt;/SSID&gt;&lt;/APMACADDRESS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By doing this a wildcard:SSIDNAME should work to specify SSID.&amp;nbsp; Is there a way to verify what the controller is sending out?&amp;nbsp; ANd how to write it for Microsoft NPS to understand?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 21:08:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242108#M126285</guid>
      <dc:creator>Gateway Church</dc:creator>
      <dc:date>2013-07-02T21:08:13Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242109#M126286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess, we can run the following debugs from the WLC CLI to verify the radius access-request:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug client &lt;CLIENT mac=""&gt;&lt;/CLIENT&gt;&lt;/P&gt;&lt;P&gt;debug aaa events enable&lt;/P&gt;&lt;P&gt;debug aaa packet enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 23:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242109#M126286</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-02T23:34:56Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242110#M126287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure its "called station ID" - not "calling station ID".&amp;nbsp; You mention "Call Station ID"&amp;nbsp; above.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you use conditions not constraints in NPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check windows event log for more details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post a screenshot of your policy if your still stuck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 05:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242110#M126287</guid>
      <dc:creator>petermitchell</dc:creator>
      <dc:date>2013-07-03T05:54:06Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242111#M126288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May the link below solve your query:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://community.arubanetworks.com/t5/Authentication-and-Access/Two-SSID-s-using-802-1x-authentication-with-same-Radius-server/td-p/39038"&gt;http://community.arubanetworks.com/t5/Authentication-and-Access/Two-SSID-s-using-802-1x-authentication-with-same-Radius-server/td-p/39038&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 03:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242111#M126288</guid>
      <dc:creator>harvisin</dc:creator>
      <dc:date>2013-07-08T03:58:53Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242112#M126289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ho Josh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you get a chance to check the debugs, what exactly you're seeing in the radius request? Also, make sure you have selected called-station-id as suggested by Peter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 06:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242112#M126289</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-08T06:13:08Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242113#M126290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am sorry everyone.&amp;nbsp; I got it working on one ssid.&amp;nbsp; I then matched the settings for the second and it did not work.&amp;nbsp; I have been forced to focus on some other projects.&amp;nbsp; I will update when I return to the issue with what I did wrong or where I get hung up.&amp;nbsp; Thank you everyone for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 04:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242113#M126290</guid>
      <dc:creator>Gateway Church</dc:creator>
      <dc:date>2013-07-09T04:33:28Z</dc:date>
    </item>
    <item>
      <title>Multiple SSIDs/VLAN - NPS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242114#M126291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No issues. In your next reply do include the debugs from WLC and event viewer logs from NPS for non-working SSID/USER.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Jul 2013 14:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-ssids-vlan-nps-authentication/m-p/2242114#M126291</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-09T14:06:57Z</dc:date>
    </item>
  </channel>
</rss>

