<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ACS Wireless Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363769#M148824</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wonderful. Thanks for sharing!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Oct 2013 22:54:48 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-10-28T22:54:48Z</dc:date>
    <item>
      <title>Cisco ACS Wireless Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363764#M148740</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to test the wireless authentication and authorization with my wireless users via ACS 4.2. I have the 4.2 trial version on Windows 2003 for testing. I also have WLC 5508 and 3602i in my lab. My AD/NPS and CA are Windows 2008 R2.&lt;/P&gt;&lt;P&gt;The Windows 2003 is part of the domain; and on the ACS, if I go to External Databse &amp;gt; Database Configuration &amp;gt; Windows Database &amp;gt; Configure&lt;/P&gt;&lt;P&gt;From here I selected my domain, tick "Enalble EAP-TLS Machine Authentication". I also have mapped the domain to the group I created in ACS. &lt;/P&gt;&lt;P&gt;I also chaged the default RADIUS ports to 1812 and 1813 on the ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On my WLC 5508, I created a WLAN and set the RADIUS IP to the ACS IP address. However, I tried to join the wireless network. It keep failing.&lt;/P&gt;&lt;P&gt;I have installed the user cert on the laptop for EAP-TLS. If I changed the RADIUS server on the WLAN and pointed it to AD/NPS that I have, my test laptop was able to join the wireless network via EAP-TLS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am a little confuse about the ACS TACACS+. Is TACACS+ used only for logging into network devices for management or can it be used for regular users for authentication and authorization?&lt;/P&gt;&lt;P&gt;For example, a wireless user, which is part of the domain, need to join a wireless enterprise network for his office work. Can I use TACACS+ for this or it has to be RADIUS via ACS 4.2?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363764#M148740</guid>
      <dc:creator>steelinquisitor</dc:creator>
      <dc:date>2019-03-11T04:02:36Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS Wireless Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363765#M148749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, we can't use tacacs+ for wireless. It has to be radius.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So have you added wireless controller on ACS as a radius aaa client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What all certificates have you installed on ACS server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What error message are we getting when you point WLC towards ACS and try to authenticate wireless users?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 18:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363765#M148749</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-28T18:09:05Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS Wireless Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363766#M148757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if I understand you correctly, tacacs+ is not used for client wireless authentication. Am I right? I am assuming this is also applies to wired users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I added the WLC 5508 as a radius client "RADIUS (Cisco IOS/PIX 6.0)."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the log that I got from the ACS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 2153px;"&gt;&lt;TBODY&gt;&lt;TR style="height: 15.0pt;"&gt;&lt;TD height="20" style="height: 15.0pt; width: 56pt;" width="75"&gt;Date&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;Time&lt;/TD&gt;&lt;TD style="width: 73pt;" width="97"&gt;Message-Type&lt;/TD&gt;&lt;TD style="width: 106pt;" width="141"&gt;User-Name&lt;/TD&gt;&lt;TD style="width: 71pt;" width="95"&gt;Group-Name&lt;/TD&gt;&lt;TD style="width: 86pt;" width="115"&gt;Caller-ID&lt;/TD&gt;&lt;TD style="width: 146pt;" width="194"&gt;Network Access Profile Name&lt;/TD&gt;&lt;TD style="width: 142pt;" width="189"&gt;Authen-Failure-Code&lt;/TD&gt;&lt;TD style="width: 103pt;" width="137"&gt;Author-Failure-Code&lt;/TD&gt;&lt;TD style="width: 62pt;" width="83"&gt;Author-Data&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;NAS-Port&lt;/TD&gt;&lt;TD style="width: 80pt;" width="106"&gt;NAS-IP-Address&lt;/TD&gt;&lt;TD style="width: 89pt;" width="118"&gt;Filter Information&lt;/TD&gt;&lt;TD style="width: 140pt;" width="187"&gt;PEAP/EAP-FAST-Clear-Name&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;EAP Type&lt;/TD&gt;&lt;TD style="width: 79pt;" width="105"&gt;EAP Type Name&lt;/TD&gt;&lt;TD style="width: 48pt;" width="64"&gt;Reason&lt;/TD&gt;&lt;TD style="width: 79pt;" width="105"&gt;Access Device&lt;/TD&gt;&lt;TD style="width: 113pt;" width="150"&gt;Network Device Group&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15.0pt;"&gt;&lt;TD align="right" height="20" style="height: 15.0pt;"&gt;10/28/2013&lt;/TD&gt;&lt;TD align="right"&gt;14:25:31&lt;/TD&gt;&lt;TD&gt;Authen failed&lt;/TD&gt;&lt;TD&gt;client01@aaeng.local&lt;/TD&gt;&lt;TD&gt;Default Group&lt;/TD&gt;&lt;TD&gt;44-94-fc-5b-21-19&lt;/TD&gt;&lt;TD&gt;(Default)&lt;/TD&gt;&lt;TD&gt;EAP_TLS Type not configured&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD align="right"&gt;1&lt;/TD&gt;&lt;TD&gt;172.28.255.42&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;RK2WLC5508-01&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15.0pt;"&gt;&lt;TD align="right" height="20" style="height: 15.0pt;"&gt;10/28/2013&lt;/TD&gt;&lt;TD align="right"&gt;14:25:35&lt;/TD&gt;&lt;TD&gt;Unknown NAS&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;(Unknown)&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;172.28.255.42&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15.0pt;"&gt;&lt;TD align="right" height="20" style="height: 15.0pt;"&gt;10/28/2013&lt;/TD&gt;&lt;TD align="right"&gt;14:26:26&lt;/TD&gt;&lt;TD&gt;Authen failed&lt;/TD&gt;&lt;TD&gt;client01@aaeng.local&lt;/TD&gt;&lt;TD&gt;Default Group&lt;/TD&gt;&lt;TD&gt;44-94-fc-5b-21-19&lt;/TD&gt;&lt;TD&gt;(Default)&lt;/TD&gt;&lt;TD&gt;EAP_TLS Type not configured&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD align="right"&gt;1&lt;/TD&gt;&lt;TD&gt;172.28.255.42&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;RK2WLC5508-01&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure how to install the CA into ACS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 19:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363766#M148757</guid>
      <dc:creator>steelinquisitor</dc:creator>
      <dc:date>2013-10-28T19:45:35Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS Wireless Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363767#M148767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes that's right and it applies to wired as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ACS, please add WLC as a AAA client with &lt;STRONG&gt;radius (Cisco airespace)&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring WLC and ACS for radius settings.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080665d18.shtml"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080665d18.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may visit the below listed link to install certificate on ACS 4.2&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/configuration/guide/peap_tls.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/configuration/guide/peap_tls.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 20:05:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363767#M148767</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-28T20:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS Wireless Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363768#M148792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. The link you have provided helps me to make EAP-TLS wireless working&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 22:39:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363768#M148792</guid>
      <dc:creator>steelinquisitor</dc:creator>
      <dc:date>2013-10-28T22:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS Wireless Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363769#M148824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wonderful. Thanks for sharing!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 22:54:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363769#M148824</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-28T22:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS Wireless Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363770#M148866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have another question regarding the passwords for my servers.&lt;BR /&gt;Since I joined my Windows 2003 with ACS 4.2 to the domain, my admin password for my AD/NPS and CA servers have changed to the Windows 2003 admin password.&lt;BR /&gt;&lt;BR /&gt;Is this normal?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 13:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363770#M148866</guid>
      <dc:creator>steelinquisitor</dc:creator>
      <dc:date>2013-10-29T13:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS Wireless Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363771#M148923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that's nothing to do with ACS joining AD (Domain). This is not a default behaviour.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 13:10:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-wireless-authentication/m-p/2363771#M148923</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-30T13:10:58Z</dc:date>
    </item>
  </channel>
</rss>

