<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Anonymous AP as local RADIUS server with Web Authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/anonymous-ap-as-local-radius-server-with-web-authentication/m-p/3770576#M13933</link>
    <description>&lt;P&gt;I've been asked to set up user credentials for a network I've recently acquired. I don't have access to a WLC, but I have managed to set up a local RADUIS server on one of the 1600 series AAP's.&amp;nbsp; For all of this I'm using the web interface.&amp;nbsp; On the local &lt;SPAN&gt;authenticator, I've entered each AP as a NAS and created a test user and a few MAC authentication only users.&amp;nbsp; On the other AP's, I've entered the local authenticator as a RADIUS server with Authentication Port as 1812 and Accounting Port as 1813.&amp;nbsp; I have the SSID set to Open Authentication with MAC Authentication or EAP and I have Web Authentication checked.&amp;nbsp; The encryption is set for Mandatory WEP.&amp;nbsp; The issue is I can't get a client device to connect to the network and route to the web authentication&amp;nbsp;page.&amp;nbsp; I know the AP has communication with the local RADIUS server because my MAC Authentication only users are authenticating with out issue, their state under the association tab is MAC-Associated.&amp;nbsp; The client device's (a laptop in this case) state is Association processing.&amp;nbsp; Any thoughts?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 16:38:55 GMT</pubDate>
    <dc:creator>independencebridge</dc:creator>
    <dc:date>2021-07-05T16:38:55Z</dc:date>
    <item>
      <title>Anonymous AP as local RADIUS server with Web Authentication</title>
      <link>https://community.cisco.com/t5/wireless/anonymous-ap-as-local-radius-server-with-web-authentication/m-p/3770576#M13933</link>
      <description>&lt;P&gt;I've been asked to set up user credentials for a network I've recently acquired. I don't have access to a WLC, but I have managed to set up a local RADUIS server on one of the 1600 series AAP's.&amp;nbsp; For all of this I'm using the web interface.&amp;nbsp; On the local &lt;SPAN&gt;authenticator, I've entered each AP as a NAS and created a test user and a few MAC authentication only users.&amp;nbsp; On the other AP's, I've entered the local authenticator as a RADIUS server with Authentication Port as 1812 and Accounting Port as 1813.&amp;nbsp; I have the SSID set to Open Authentication with MAC Authentication or EAP and I have Web Authentication checked.&amp;nbsp; The encryption is set for Mandatory WEP.&amp;nbsp; The issue is I can't get a client device to connect to the network and route to the web authentication&amp;nbsp;page.&amp;nbsp; I know the AP has communication with the local RADIUS server because my MAC Authentication only users are authenticating with out issue, their state under the association tab is MAC-Associated.&amp;nbsp; The client device's (a laptop in this case) state is Association processing.&amp;nbsp; Any thoughts?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 16:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anonymous-ap-as-local-radius-server-with-web-authentication/m-p/3770576#M13933</guid>
      <dc:creator>independencebridge</dc:creator>
      <dc:date>2021-07-05T16:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymous AP as local RADIUS server with Web Authentication</title>
      <link>https://community.cisco.com/t5/wireless/anonymous-ap-as-local-radius-server-with-web-authentication/m-p/3772141#M13934</link>
      <description>First of all, don't use WEP. WEP is completely cracked and everybody can decrypt within seconds the traffic.&lt;BR /&gt;Use WPA2 with AES encryption only. &lt;BR /&gt;&lt;BR /&gt;Now to you problem, I've never heard about (ab)using an access point as a radius server, I'm not even sure that this is supported. &lt;BR /&gt;My suggestion is to use a Linux Server with Freeradius or a Windows Server with the Radius feature as a radius server. Then you'd also have logging functionality and troubleshooting features.</description>
      <pubDate>Thu, 03 Jan 2019 12:02:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anonymous-ap-as-local-radius-server-with-web-authentication/m-p/3772141#M13934</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-01-03T12:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymous AP as local RADIUS server with Web Authentication</title>
      <link>https://community.cisco.com/t5/wireless/anonymous-ap-as-local-radius-server-with-web-authentication/m-p/3772196#M13935</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used this guide,&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/access_point/15-3-3/configuration/guide/cg15-3-3/cg15-3-3-chap9-localauth.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/access_point/15-3-3/configuration/guide/cg15-3-3/cg15-3-3-chap9-localauth.html&lt;/A&gt;, to set up the RADUIS server on the ap.&amp;nbsp; I'm by no means an IT professional, but it seems to be working based on the MAC only authentications working.&amp;nbsp; My real issue seems to be figuring out how to set up web authentication via the ap.&amp;nbsp; I will look into using an actual server for RADIUS, though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2019 13:07:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anonymous-ap-as-local-radius-server-with-web-authentication/m-p/3772196#M13935</guid>
      <dc:creator>independencebridge</dc:creator>
      <dc:date>2019-01-03T13:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Anonymous AP as local RADIUS server with Web Authentication</title>
      <link>https://community.cisco.com/t5/wireless/anonymous-ap-as-local-radius-server-with-web-authentication/m-p/3772208#M13936</link>
      <description>I'm not anymore 100% sure, but I think Web authentication is not using Radius. So you can't use this.&lt;BR /&gt;What you could do, would be an SSID with enabled 802.1x and there you'd point to the Radius AP and use EAP-FAST for username/password authentication. I've never done that though and I think this is also not anymore secure.&lt;BR /&gt;I suggest to use EAP-PEAP for authentication with MSCHAPv2, if you want to use username/password. This requires a valid certificate to function without issues on the radius server.</description>
      <pubDate>Thu, 03 Jan 2019 13:23:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/anonymous-ap-as-local-radius-server-with-web-authentication/m-p/3772208#M13936</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-01-03T13:23:51Z</dc:date>
    </item>
  </channel>
</rss>

