<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: check this out in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/accesspoint-as-802-1x-supplicant-port-security-with-flexconnect/m-p/3337190#M14281</link>
    <description>&lt;P&gt;Any idea how this can be done when you are using IBNS2.0 config syntax for 802.1x (like "service-policy type control subscriber xxxyyyzzzz"), not the "old" syntax ??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rgs&lt;/P&gt;
&lt;P&gt;Frank&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 24 Feb 2018 17:04:55 GMT</pubDate>
    <dc:creator>Frank Lothar Weber</dc:creator>
    <dc:date>2018-02-24T17:04:55Z</dc:date>
    <item>
      <title>Accesspoint as 802.1x Supplicant - Port Security with Flexconnect APs</title>
      <link>https://community.cisco.com/t5/wireless/accesspoint-as-802-1x-supplicant-port-security-with-flexconnect/m-p/2724602#M14277</link>
      <description>&lt;P&gt;Hey Guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do you secure your switch ports when you operate access points in Flexconnect mode?&lt;/P&gt;&lt;P&gt;I've read that 802.1x authentication is not supported on trunk ports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to use PEAP or another EAP-Type instead of EAP-Fast to authenticate the APs?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 10:50:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/accesspoint-as-802-1x-supplicant-port-security-with-flexconnect/m-p/2724602#M14277</guid>
      <dc:creator>Tony Rosolek</dc:creator>
      <dc:date>2021-07-05T10:50:56Z</dc:date>
    </item>
    <item>
      <title>Hi,Configure LAN Switch Ports</title>
      <link>https://community.cisco.com/t5/wireless/accesspoint-as-802-1x-supplicant-port-security-with-flexconnect/m-p/2724603#M14278</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;Hi,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H3&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;Configure LAN Switch Ports for 802.1X&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;The first step consists into implementing 802.1X authentication on the authenticator side or LAN switches. Here is a sample configuration:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;STRONG&gt;aaa new-model&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;STRONG&gt;aaa authentication dot1x default group radius&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;STRONG&gt;radius-server host 10.199.200.71 auth-port 1812 acct-port 1813 key &amp;lt;yourkey&amp;gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic; min-height: 16.0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;STRONG&gt;dot1x system-auth-control&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic; min-height: 16.0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;interface FastEthernet0/3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;description WiFi Access Point with 802.1X Auth&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;switchport access vlan 200&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;switchport mode access&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;STRONG&gt;dot1x pae authenticator&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;STRONG&gt;authentication port-control auto&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;spanning-tree portfast&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic; min-height: 16.0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;NOTE:&amp;nbsp; The port-control auto option says that once a device logs off, that switchport reverts to an unauthorized state&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;The above example only shows one LAN port. You need to repeat this for all ports in the switch.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;Configure your RADIUS Server&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;SPAN style="font-style: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; font-feature-settings: normal; font-language-override: normal; font-kerning: auto; font-synthesis: weight style; font-variant: normal;"&gt;Configure your RADIUS server with the &lt;/SPAN&gt;&lt;STRONG&gt;user name&lt;/STRONG&gt; and &lt;STRONG&gt;password&lt;/STRONG&gt; you will specify in your WLC controller (Wireless &amp;gt; Radios &amp;gt; Global Configuration &amp;gt; 802.1X Supplicant Credentials)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;Configure the Cisco WLC with the 802.1X Supplicant Credentials&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;From the following menu, configure your global 802.1X supplicant credentials&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;Wireless &amp;gt; Radios &amp;gt; Global Configuration &amp;gt; 802.1X Supplicant Credentials&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;IMG alt="NewImage" border="0" height="390" src="http://www.swilliamsgroup.com/wp-content/uploads/2013/04/NewImage52.png" style="display: block; margin-left: auto; margin-right: auto;" title="NewImage.png" width="600" /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;Check &lt;EM&gt;802.1x Authentication&lt;/EM&gt;, then fill both the 802.1X username and password. These have a global significance and all LAPs that already joined that WLC will inherit these credentials. In the LAP’s config, you will find a config snippet similar to this:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic; min-height: 16.0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;EM&gt;dot1x credentials lwapp_credentials&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;EM&gt;username 8021xglobal&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 15px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;&lt;EM&gt;password 010203040506070809&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;Please note that you can also implement per-AP credentials instead of global credentials.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H3&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;Provisioning new LAPs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 13.0px Century Gothic;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;New LAPs will not be able to join the WLC if their wired switch port is configured for 802.1X. The easiest way to have them join that WLC is to disable 802.1X authentication on one switch port and let the LAP reboot. It will then inherit its new configuration, including the 802.1X credentials. Next, enable 802.1X authentication on the switch port. Another way is to ‘prime’ your LAPs in a lab with these 802.1X credentials.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H3 style="font-size: 1.17em;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;Conclusion&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;&lt;H3 style="font-size: 1.17em;"&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family: times new roman,times,serif;"&gt;Implementing 802.1X on the wired side of your network reinforces your overall network security. With a few mouse clicks, you can configure 802.1X supplicant credentials for all your Cisco lightweight access points from a central location.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;</description>
      <pubDate>Mon, 31 Aug 2015 08:57:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/accesspoint-as-802-1x-supplicant-port-security-with-flexconnect/m-p/2724603#M14278</guid>
      <dc:creator>abwahid</dc:creator>
      <dc:date>2015-08-31T08:57:26Z</dc:date>
    </item>
    <item>
      <title>Thanks for your reply, but</title>
      <link>https://community.cisco.com/t5/wireless/accesspoint-as-802-1x-supplicant-port-security-with-flexconnect/m-p/2724604#M14279</link>
      <description>&lt;P&gt;Thanks for your reply, but the flex connect access points are not connected to access port but to trunk mode ports. As far as I know, dot1x is not supported on trunk ports.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 09:08:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/accesspoint-as-802-1x-supplicant-port-security-with-flexconnect/m-p/2724604#M14279</guid>
      <dc:creator>Tony Rosolek</dc:creator>
      <dc:date>2015-08-31T09:08:35Z</dc:date>
    </item>
    <item>
      <title>check this out </title>
      <link>https://community.cisco.com/t5/wireless/accesspoint-as-802-1x-supplicant-port-security-with-flexconnect/m-p/2724605#M14280</link>
      <description>&lt;P&gt;check this out&amp;nbsp;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200492-Securing-a-flexconnect-AP-switchport-wit.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;you'll need to boot the AP on an access-port and the NEAT response from the ISE will change the port from access to trunk&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 11:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/accesspoint-as-802-1x-supplicant-port-security-with-flexconnect/m-p/2724605#M14280</guid>
      <dc:creator>maarten_dhooghe</dc:creator>
      <dc:date>2017-02-02T11:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: check this out</title>
      <link>https://community.cisco.com/t5/wireless/accesspoint-as-802-1x-supplicant-port-security-with-flexconnect/m-p/3337190#M14281</link>
      <description>&lt;P&gt;Any idea how this can be done when you are using IBNS2.0 config syntax for 802.1x (like "service-policy type control subscriber xxxyyyzzzz"), not the "old" syntax ??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rgs&lt;/P&gt;
&lt;P&gt;Frank&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2018 17:04:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/accesspoint-as-802-1x-supplicant-port-security-with-flexconnect/m-p/3337190#M14281</guid>
      <dc:creator>Frank Lothar Weber</dc:creator>
      <dc:date>2018-02-24T17:04:55Z</dc:date>
    </item>
  </channel>
</rss>

