<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC Called-Station-ID (Radius Authentication and Accounting Config) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685769#M495463</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199790"&gt;@Jason Kunst&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;One more question if you don't mind. As I mentioned in my original post. When Radius Authentication on WLC is set to IP Address it also affects Calling-Station-ID which is displayed as IP address and not MAC of endpoint on anchor WLC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it by design or bug behavior? I didn't expect Called Station ID to affect Calling Station ID behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Fri, 10 Aug 2018 13:24:46 GMT</pubDate>
    <dc:creator>Tymofii Dmytrenko</dc:creator>
    <dc:date>2018-08-10T13:24:46Z</dc:date>
    <item>
      <title>WLC Called-Station-ID (Radius Authentication and Accounting Config)</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3684045#M495453</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am currently trying to understand the effect of Called-Station-ID configuration on Cisco ISE infrastructure. I have noticed that some of our anchor WLCs are configured with IP Address as Called-Station-ID for both Authentication and Accounting and this forces Cisco ISE to display Endpoints using IP addresses, rather than MAC addresses (even though in my understanding Called-Station-ID should only affect NAD, while Calling-Station-ID refers to endpoint?).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before I'll change it, I'd like to understand what is current RECOMMENDED way to configure Authentication and Accounting with regards to Called-Station-Id. I have noticed that default setting is AP MAC:SSID for Authentication, but System MAC for Accounting. Can anyone explain why is this inconsistency? Doesn't this affect accounting or Radius session if different?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, there are loads of options, such as&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;IP Address&lt;/LI&gt;
&lt;LI&gt;AP MAC&lt;/LI&gt;
&lt;LI&gt;AP MAC:SSID&lt;/LI&gt;
&lt;LI&gt;AP Name:SSID&lt;/LI&gt;
&lt;LI&gt;AP Name&lt;/LI&gt;
&lt;LI&gt;AP Group&lt;/LI&gt;
&lt;LI&gt;Flex Group&lt;/LI&gt;
&lt;LI&gt;AP Location&lt;/LI&gt;
&lt;LI&gt;Vlan ID&lt;/LI&gt;
&lt;LI&gt;AP Eth MAC&lt;/LI&gt;
&lt;LI&gt;AP Eth MAC:SSID&lt;/LI&gt;
&lt;LI&gt;AP Label Address&lt;/LI&gt;
&lt;LI&gt;AP Label Address:SSID&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;What is practical use for all these different configuration options?&lt;/P&gt;
&lt;P&gt;Has anyone had to use something other than default 'AP MAC:SSID'?&lt;/P&gt;
&lt;P&gt;When and Why please (what have you tried to achieve)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 13:37:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3684045#M495453</guid>
      <dc:creator>Tymofii Dmytrenko</dc:creator>
      <dc:date>2018-08-08T13:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Called-Station-ID Radius Authentication and Accounting on Foreign and Anchor WLCs</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3684053#M495454</link>
      <description>&lt;P&gt;I wouldn't think called station ID shouldn't affect how ISE displays&amp;nbsp;the information for the MAC address in Context Visibility.&amp;nbsp; The only modification I make to the called station ID is for authentication and I have my customers change it to AP Name:SSID.&amp;nbsp; Then I can use Called Station ID in two ways:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use the "Ends With" condition to grab the SSID name and use it as the admission criteria to my policy sets for wireless.&amp;nbsp; That allows me to have unique policy sets for each SSID.&lt;/LI&gt;
&lt;LI&gt;Use string matches on the AP name to know what site the user is connecting at to allow a SSID to behave different at one location vs. another.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 12:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3684053#M495454</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-08-08T12:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Called-Station-ID Radius Authentication and Accounting on Foreign and Anchor WLCs</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3684077#M495455</link>
      <description>Thanks for this one! Does it mean you have a long list of AuthZ rules in your environment to support different behavior in different locations? Also, does it mean your hostnames (at least APs) have distinct location string encoded?&lt;BR /&gt;&lt;BR /&gt;In our environment we rely on SSID ID instead (Airespace:Airespace-Wlan-Id). All our SSIDs are configured in a consistent fashion across the board. But, yeah... I would agree that matching SSID by name is more flexible.</description>
      <pubDate>Wed, 08 Aug 2018 12:55:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3684077#M495455</guid>
      <dc:creator>Tymofii Dmytrenko</dc:creator>
      <dc:date>2018-08-08T12:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Called-Station-ID Radius Authentication and Accounting on Foreign and Anchor WLCs</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3684144#M495456</link>
      <description>If you want to treat clients differently at different location based on the AP name your APs would have to have a consistent naming convention with a location code embedded in the name.  I have really only used this on one customer case.  They wanted their guest wireless users to be treated differently at their remote sites vs. the main office.  You would have different Authz rules based on AP name in that case.  I have used WLAN ID in the past, but as you pointed out that requires you to have consistent WLAN IDs across all your controllers.  The SSID name is consistent by default.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 08 Aug 2018 14:02:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3684144#M495456</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-08-08T14:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Called-Station-ID (Radius Authentication and Accounting Config)</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3684531#M495457</link>
      <description>&lt;P&gt;Can anyone from Cisco to comment? In particular, why by default Authentication is set to AP MAC:SSID, but Accounting is using System MAC? Shouldn't these two be configured identically? What's the impact on logging/accounting or session handling if these two things are configured differently / separately?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 22:25:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3684531#M495457</guid>
      <dc:creator>Tymofii Dmytrenko</dc:creator>
      <dc:date>2018-08-08T22:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Called-Station-ID (Radius Authentication and Accounting Config)</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685631#M495458</link>
      <description>&lt;P&gt;&lt;SPAN&gt;By default Authentication is set to AP MAC:SSID, But you can change it to use any other attribute . It depends on how the customer would want to authenticate the endpoint.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;In ISE, MAC-Address is the unique identifier for the endpoint. Hence session handling or accounting is on MAC address / session id&amp;nbsp; . There is no impact on the logs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Nidhi&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 09:08:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685631#M495458</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-08-10T09:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Called-Station-ID (Radius Authentication and Accounting Config)</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685722#M495459</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/359830"&gt;@Nidhi&lt;/a&gt;. Could you please explain why Accounting's default value is System MAC (which is WLC's MAC address), rather than AP MAC:SSID (Authentication's config). Wouldn't it be better to have both set to identical config? Any ipmpact at all? Does it only affects Accounting logging and nothing else?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 12:33:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685722#M495459</guid>
      <dc:creator>Tymofii Dmytrenko</dc:creator>
      <dc:date>2018-08-10T12:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Called-Station-ID (Radius Authentication and Accounting Config)</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685739#M495460</link>
      <description>&lt;P&gt;The fields you are asking about have no impact on ISE.&amp;nbsp; If you want to use the field then use them, but ISE doesn't use them for critical operations.&amp;nbsp; If you want to know the logic why Authentication is different than Accounting engage the Cisco Wireless team and find out their logic.&amp;nbsp; The settings you are seeing are the default setting on the WLC.&amp;nbsp; Like I said I usually change authentication to AP Name:SSID because I want to use that data in that field in my rules.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 12:58:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685739#M495460</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-08-10T12:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Called-Station-ID (Radius Authentication and Accounting Config)</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685746#M495461</link>
      <description>Correct&lt;BR /&gt;&lt;BR /&gt;Also recommend looking at&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/top-six-important-cisco-wlc-settings-for-ise-integration/ta-p/3643795" target="_blank"&gt;https://community.cisco.com/t5/security-documents/top-six-important-cisco-wlc-settings-for-ise-integration/ta-p/3643795&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-6/b_Cisco_Wireless_LAN_Controller_Configuration_Best_Practices.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-6/b_Cisco_Wireless_LAN_Controller_Configuration_Best_Practices.html&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 10 Aug 2018 13:06:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685746#M495461</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-08-10T13:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Called-Station-ID (Radius Authentication and Accounting Config)</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685762#M495462</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199790"&gt;@Jason Kunst&lt;/a&gt; thanks for these! I will have a read now.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/192011"&gt;@paul&lt;/a&gt; thanks a lot!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 13:16:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685762#M495462</guid>
      <dc:creator>Tymofii Dmytrenko</dc:creator>
      <dc:date>2018-08-10T13:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Called-Station-ID (Radius Authentication and Accounting Config)</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685769#M495463</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199790"&gt;@Jason Kunst&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;One more question if you don't mind. As I mentioned in my original post. When Radius Authentication on WLC is set to IP Address it also affects Calling-Station-ID which is displayed as IP address and not MAC of endpoint on anchor WLC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it by design or bug behavior? I didn't expect Called Station ID to affect Calling Station ID behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 13:24:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685769#M495463</guid>
      <dc:creator>Tymofii Dmytrenko</dc:creator>
      <dc:date>2018-08-10T13:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Called-Station-ID (Radius Authentication and Accounting Config)</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685778#M495464</link>
      <description>As Paul mentioned you would have to reach out to the wireless team to get specific answers on that product line&lt;BR /&gt;</description>
      <pubDate>Fri, 10 Aug 2018 13:35:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-called-station-id-radius-authentication-and-accounting/m-p/3685778#M495464</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-08-10T13:35:19Z</dc:date>
    </item>
  </channel>
</rss>

