<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC Radius Credentials Caching in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757114#M10151</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have Radius Authentication working. I even have Active Directory being used as the external database for clients. The problem is that a user that never has logged into a laptop(configure for AD) get as Domain not available if we try the via wireless for that users first login. I fully understad the issue which is the client have not been issued an IP because they have not been authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More than likely there is not a workaround for this scenerio other than login via wireless with the new AD user credentials. In effect caching the AD profile locally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would like to address is because my users are Transient (nurses and doctors that share laptops) is how to lessen number of time for a wired loggin by caching the AD account in at the WLC. I may be off base to the function of this feature but its not very well documented (from what I have found)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 Jul 2007 20:33:41 GMT</pubDate>
    <dc:creator>Mike Lydick</dc:creator>
    <dc:date>2007-07-31T20:33:41Z</dc:date>
    <item>
      <title>WLC Radius Credentials Caching</title>
      <link>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757112#M10149</link>
      <description>&lt;P&gt;We are using PEAP with ACS/AD as the external Database. The issue or behavior that we are experiencing is that clients require a Cached  AD Token for the user authenticate against for the first time. The Client does not get an IP until authenticated and therefore cannot contact the DC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have shared laptops an its not feasible to cache all AD profiles(Tokens) to the laptop. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will the Radius Authentication Server - Credential Caching option help by caching authenticated client sessions to the WLC and allow user to authenticate against multiple laptops? Is the above behavior correct(cached Token required)? Is there another approach to authenticating shared resources with PEAP/Radius(ACS)/AD &lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 21:23:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757112#M10149</guid>
      <dc:creator>Mike Lydick</dc:creator>
      <dc:date>2021-07-03T21:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Radius Credentials Caching</title>
      <link>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757113#M10150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In order to perform RADIUS authentication, for controller login and management, ensure that the Admin-auth-via-RADIUS flag is enabled on the controller.&lt;/P&gt;&lt;P&gt;This can be verified from the output of the show radius summary command. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080782507.shtml" target="_blank"&gt;http://cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080782507.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2007 19:53:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757113#M10150</guid>
      <dc:creator>umedryk</dc:creator>
      <dc:date>2007-07-31T19:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Radius Credentials Caching</title>
      <link>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757114#M10151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have Radius Authentication working. I even have Active Directory being used as the external database for clients. The problem is that a user that never has logged into a laptop(configure for AD) get as Domain not available if we try the via wireless for that users first login. I fully understad the issue which is the client have not been issued an IP because they have not been authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More than likely there is not a workaround for this scenerio other than login via wireless with the new AD user credentials. In effect caching the AD profile locally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would like to address is because my users are Transient (nurses and doctors that share laptops) is how to lessen number of time for a wired loggin by caching the AD account in at the WLC. I may be off base to the function of this feature but its not very well documented (from what I have found)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2007 20:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757114#M10151</guid>
      <dc:creator>Mike Lydick</dc:creator>
      <dc:date>2007-07-31T20:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Radius Credentials Caching</title>
      <link>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757115#M10152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know what you are talking about. We use PEAP-MSCHAPv2 with machine authentication and it works great. Brand new user that has never logged on to the wireless computer can get authenticated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2007 16:31:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757115#M10152</guid>
      <dc:creator>hrios</dc:creator>
      <dc:date>2007-08-01T16:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Radius Credentials Caching</title>
      <link>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757116#M10153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah I would imagine machine authentication would be a better approach but that require issuing a cert to the machine. We are trying keep the hands on time with the laptops to a minimum and not to add yet another server for wireless security. We are not running any CA other than the ACS (self-signed cert). Even with that we are not adding the cert to the client list. I guess I will hit TAC up on the radius cache functionality. Also reconsider the security method we are using.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2007 23:50:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757116#M10153</guid>
      <dc:creator>Mike Lydick</dc:creator>
      <dc:date>2007-08-02T23:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Radius Credentials Caching</title>
      <link>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757117#M10154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PEAP requires server-side certificates only. No certificates on the client side&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2007 23:59:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757117#M10154</guid>
      <dc:creator>hrios</dc:creator>
      <dc:date>2007-08-02T23:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Radius Credentials Caching</title>
      <link>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757118#M10155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Machine authentication? Do you have a White-paper on that (how-to)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2007 00:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757118#M10155</guid>
      <dc:creator>Mike Lydick</dc:creator>
      <dc:date>2007-08-03T00:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Radius Credentials Caching</title>
      <link>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757119#M10156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check these two documents:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/sw/secursw/ps2086/products_configuration_example09186a00801df0e4.shtml" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/sw/secursw/ps2086/products_configuration_example09186a00801df0e4.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/docs/wireless/technology/peap/technical/reference/PEAP_D.html#wp1008130" target="_blank"&gt;http://www.cisco.com/en/US/customer/docs/wireless/technology/peap/technical/reference/PEAP_D.html#wp1008130&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2007 00:07:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757119#M10156</guid>
      <dc:creator>hrios</dc:creator>
      <dc:date>2007-08-03T00:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Radius Credentials Caching</title>
      <link>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757120#M10157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both of these show using (client-side certificate validation)certificates. Did you choose not to validate on the clients or how did you address this part of the client config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Btw thanks for your response.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2007 00:15:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757120#M10157</guid>
      <dc:creator>Mike Lydick</dc:creator>
      <dc:date>2007-08-03T00:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: WLC Radius Credentials Caching</title>
      <link>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757121#M10158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming your clients are Windows and/or Mac,the root CA certificates of many third-party CAs are already included in the OS. If your Radius server certificate is from a third-party CA that corresponds to an included root CA certificate, no additional wireless client configuration is required. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2007 00:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-radius-credentials-caching/m-p/757121#M10158</guid>
      <dc:creator>hrios</dc:creator>
      <dc:date>2007-08-03T00:29:15Z</dc:date>
    </item>
  </channel>
</rss>

