<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello Florin, in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435345#M140148</link>
    <description>&lt;P&gt;Hello Florin,&lt;/P&gt;
&lt;P&gt;I want to know how you declare the access point on the radius server in order to enable the authentication request send directly by the access point?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Mon, 21 Mar 2016 15:14:35 GMT</pubDate>
    <dc:creator>Aret Avedis SET</dc:creator>
    <dc:date>2016-03-21T15:14:35Z</dc:date>
    <item>
      <title>FlexConnect Groups 802.1x Authentication</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435333#M140136</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I have a vWLC running 7.5 and several locations running FlexConnect.&lt;/P&gt;&lt;P&gt;One SSID is using 802.1x with PEAP on Windows 2008. I have started the config with Local Switching and Central Authentication.&lt;/P&gt;&lt;P&gt;I defined on Security Radius the right server, setup PSK and authentication works fine, from all over the sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also setup FlexConnect groups so each site's APs belong to a specific&amp;nbsp;FlexConnect group. As we speak I used only the newest tab: Wlan Vlan mapping, which worked pretty fine (I found out the hard way, it's dependant of AP Groups setup).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I want to enable FlexConnect Local Auth and for that I configured one primary server on the&amp;nbsp;FlexConnect group General Tab: I added the IP and the PSK in use. But auth now, doesn't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read the documentation, still I find it pretty vague, what am I missing here? Do I still need to define each AP as Radius client on the Win_Radius_Server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Florin.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 07:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435333#M140136</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2021-07-05T07:31:44Z</dc:date>
    </item>
    <item>
      <title>If you are testing WAN link</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435334#M140137</link>
      <description>&lt;P&gt;If you are testing WAN link down scenario (where AP operate as standalone mode) then your local radius server should knows APs as it will forward the RADIUS request to server.&lt;/P&gt;&lt;P&gt;Do you have local RADIUS server ?&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Rasika&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2014 19:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435334#M140137</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2014-03-25T19:18:48Z</dc:date>
    </item>
    <item>
      <title>Hi Rasika,FlexConnect is</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435335#M140138</link>
      <description>&lt;P&gt;Hi Rasika,&lt;/P&gt;&lt;P&gt;FlexConnect is configured for local switching and central authentication; Radius servers are configured on Security Radius. There are two: one Radius server in the same subnet with vWLC and APs and one at 4 hops away. All works fine.&lt;/P&gt;&lt;P&gt;But when I go to Wlan and tick Local Authentication, no client can get access to that Wlan.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously I am missing some configuration, but what? To mention that both APs and vWLC are in the same subnet, and I didn't stop the vWLC yet.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2014 19:25:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435335#M140138</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2014-03-25T19:25:46Z</dc:date>
    </item>
    <item>
      <title>When you enable this "Local</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435336#M140139</link>
      <description>&lt;P&gt;When you enable this "Local Auth" option, any of your RADIUS gets any hits from client request ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do "debug client &amp;lt;client-mac&amp;gt;" you would get some clue what's going on. Which state client get stuck dot1X-REQD or DHCP-REQD, etc ?&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Rasika&lt;/P&gt;&lt;P&gt;*** Pls rate all useful responses ****&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2014 20:26:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435336#M140139</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2014-03-25T20:26:03Z</dc:date>
    </item>
    <item>
      <title>I honestly didn't check. I</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435337#M140140</link>
      <description>&lt;P&gt;I honestly didn't check. I will have a look tomorrow, but meanwhile back to my original question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;- when using FlexConnect Groups do I still need to define each of the AP group member as a Radius Client on the RADIUS Server?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2014 20:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435337#M140140</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2014-03-25T20:30:18Z</dc:date>
    </item>
    <item>
      <title>YES, if you want this setup</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435338#M140141</link>
      <description>&lt;P&gt;YES, if you want this setup to work even WLC is not reachable scenarios.&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Rasika&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2014 20:40:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435338#M140141</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2014-03-25T20:40:50Z</dc:date>
    </item>
    <item>
      <title>Ok, so this is needed for</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435339#M140142</link>
      <description>&lt;P&gt;Ok, so this is needed for Standalone mode.&lt;/P&gt;&lt;P&gt;What if the WLC is still available? What are then the requirements?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2014 01:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435339#M140142</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2014-03-26T01:47:26Z</dc:date>
    </item>
    <item>
      <title>If WLC availabe in your</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435340#M140143</link>
      <description>&lt;P&gt;If WLC availabe in your branch &amp;amp; APs are in "connected mode" &amp;nbsp;then RADIUS Auth requrest coming from clients are handled by WLC. So your RADIUS server should see the request coming from WLC management &amp;amp; not from APs directly.&lt;/P&gt;&lt;P&gt;In "standalone mode" APs will directly forwarded those to RADIUS server as WLC is no longer in the picture.&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Rasika&lt;/P&gt;&lt;P&gt;**** Pls rate all useful responses ***&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2014 05:17:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435340#M140143</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2014-03-26T05:17:35Z</dc:date>
    </item>
    <item>
      <title>Thanks for the explanation</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435341#M140144</link>
      <description>&lt;P&gt;Thanks for the explanation Rasika, it makes sense.&lt;/P&gt;&lt;P&gt;Now back to my scenario, my first round of tests is keeping APs in connected mode. Furthermore I am using the same identical Radius Server.&lt;/P&gt;&lt;P&gt;It's just when I tick Local Authentication, it stops working; removing that option and switching back, it all works. From this I assume enabling Local Authentication requires additional configuration, but what am I missing?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2014 08:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435341#M140144</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2014-03-26T08:20:03Z</dc:date>
    </item>
    <item>
      <title>Hi guys,2 months later and I</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435342#M140145</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;2 months later and I made some steps close to this. For anyone that wants to use FlexConnect&amp;nbsp;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;Local Authentication&amp;nbsp;&lt;/SPAN&gt;here are the steps:&lt;/P&gt;&lt;P&gt;1. Use FlexConnect Groups (General tab\AAA) and add at least one primary Radius server.&lt;/P&gt;&lt;P&gt;2. Make sure you add all your APs from that FlexConnect Group as Radius Clients on your Radius Server.&lt;/P&gt;&lt;P&gt;3. Tick&amp;nbsp;FlexConnect Local Authentication in WLAN (Advanced tab)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And now it works. The question is: if one WLAN uses FlexConnect CentralAuthentication and either&amp;nbsp;WLC fails or APs simply cannot access the WLC is there any method/option that all APs would automatically transition to&amp;nbsp;FlexConnect LocalAuthentication?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2014 20:31:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435342#M140145</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2014-05-13T20:31:24Z</dc:date>
    </item>
    <item>
      <title>HI Florin, Probably you have</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435343#M140146</link>
      <description>&lt;P&gt;HI Florin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Probably you have already received answer for last question but in case someone else has the same question,&amp;nbsp;I would say there is no way to do that automatic transition.&lt;/P&gt;&lt;P&gt;Jaime&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2015 13:15:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435343#M140146</guid>
      <dc:creator>Jaime Gonzalez Gomez</dc:creator>
      <dc:date>2015-04-15T13:15:58Z</dc:date>
    </item>
    <item>
      <title>Hi mate, Thanks for dropping</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435344#M140147</link>
      <description>&lt;P&gt;Hi mate,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for dropping by; as we speak I got the same answer: no possibility for the switch over.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2015 13:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435344#M140147</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2015-04-15T13:18:51Z</dc:date>
    </item>
    <item>
      <title>Hello Florin,</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435345#M140148</link>
      <description>&lt;P&gt;Hello Florin,&lt;/P&gt;
&lt;P&gt;I want to know how you declare the access point on the radius server in order to enable the authentication request send directly by the access point?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 15:14:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435345#M140148</guid>
      <dc:creator>Aret Avedis SET</dc:creator>
      <dc:date>2016-03-21T15:14:35Z</dc:date>
    </item>
    <item>
      <title>Hi All, </title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435346#M140149</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to configure flexgroup radius server which points to local ISE PSN in branch thinking that it will override global radius server which is configured under corporate ssid on a centralized controller but it does not seems to be working.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;users are still being authenticated from global radius server. I know this flexconnect group radius should work for ap in standalone and connected mode. My aps are in connected mode currently.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;hope to see some help on this.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jun 2017 18:25:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-groups-802-1x-authentication/m-p/2435346#M140149</guid>
      <dc:creator>jain.nitin</dc:creator>
      <dc:date>2017-06-11T18:25:04Z</dc:date>
    </item>
  </channel>
</rss>

