<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Autonomous AP for EAP in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/autonomous-ap-for-eap/m-p/1998348#M10668</link>
    <description>&lt;P&gt;We've got an ACS 5.1 virtual appliance for device administration&amp;nbsp; tasks and now we want to authenticate wireless domain users, but only by&amp;nbsp; it's username/password, without trusting any CA certificates from the&amp;nbsp; AD (is it required an ACS certificate too?).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe there are some steps I have missed but I cant' locate where is the problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the configuration of the AP that I have but, is it correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server radius rad_eap&lt;/P&gt;&lt;P&gt; server a.b.c.d auth-port 1812 acct-port 1646&lt;/P&gt;&lt;P&gt; server a.b.c.d auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login eap_methods group rad_eap&lt;/P&gt;&lt;P&gt;aaa authentication login mac_methods local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group rad_eap local&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 vlan-name WPA vlan 199&lt;/P&gt;&lt;P&gt;dot11 ssid LABREDES_CERT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; vlan 199&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; authentication open eap eap_methods &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; authentication network-eap eap_methods &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; guest-mode&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; mbssid guest-mode dtim-period 75&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0&lt;/P&gt;&lt;P&gt;&amp;nbsp; encryption vlan 199 mode ciphers tkip&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We&amp;nbsp; have spent some days and nothing seems to work but nothing appears in&amp;nbsp; the ACS log, there are no messages in the log, and a debug (radius, aaa authentication) in the AP only&amp;nbsp; shows (AAA/BIND(0000014E): Bind i/f&amp;nbsp; )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Any help would be appreciated&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 05:21:16 GMT</pubDate>
    <dc:creator>JPavonM</dc:creator>
    <dc:date>2021-07-04T05:21:16Z</dc:date>
    <item>
      <title>Autonomous AP for EAP</title>
      <link>https://community.cisco.com/t5/wireless/autonomous-ap-for-eap/m-p/1998348#M10668</link>
      <description>&lt;P&gt;We've got an ACS 5.1 virtual appliance for device administration&amp;nbsp; tasks and now we want to authenticate wireless domain users, but only by&amp;nbsp; it's username/password, without trusting any CA certificates from the&amp;nbsp; AD (is it required an ACS certificate too?).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe there are some steps I have missed but I cant' locate where is the problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the configuration of the AP that I have but, is it correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server radius rad_eap&lt;/P&gt;&lt;P&gt; server a.b.c.d auth-port 1812 acct-port 1646&lt;/P&gt;&lt;P&gt; server a.b.c.d auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login eap_methods group rad_eap&lt;/P&gt;&lt;P&gt;aaa authentication login mac_methods local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group rad_eap local&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 vlan-name WPA vlan 199&lt;/P&gt;&lt;P&gt;dot11 ssid LABREDES_CERT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; vlan 199&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; authentication open eap eap_methods &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; authentication network-eap eap_methods &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; guest-mode&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; mbssid guest-mode dtim-period 75&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0&lt;/P&gt;&lt;P&gt;&amp;nbsp; encryption vlan 199 mode ciphers tkip&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We&amp;nbsp; have spent some days and nothing seems to work but nothing appears in&amp;nbsp; the ACS log, there are no messages in the log, and a debug (radius, aaa authentication) in the AP only&amp;nbsp; shows (AAA/BIND(0000014E): Bind i/f&amp;nbsp; )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Any help would be appreciated&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 05:21:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/autonomous-ap-for-eap/m-p/1998348#M10668</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2021-07-04T05:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: Autonomous AP for EAP</title>
      <link>https://community.cisco.com/t5/wireless/autonomous-ap-for-eap/m-p/1998349#M10669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need to globally configure your radius servers too!&lt;/P&gt;&lt;P&gt;e.g.: radius-server host a.b.c.d auth 1812 acc 1646 secret &lt;SHAREDSECRETALSODEFINEDONACS&gt;&lt;/SHAREDSECRETALSODEFINEDONACS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also you need to change your SSID config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dot11 ssid LABREDES_CERT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication key-management wpa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the certificate: you can use PEAP with MSCHAPv2, and leave the selfsigned certificate on the ACS (so you simply disable certificate validation on your clients), but I would definitely not recommend this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope that helps!&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 14:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/autonomous-ap-for-eap/m-p/1998349#M10669</guid>
      <dc:creator>stefan.angerer</dc:creator>
      <dc:date>2012-06-27T14:32:54Z</dc:date>
    </item>
  </channel>
</rss>

