<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting Started: PEAP w/ SecureACS in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/getting-started-peap-w-secureacs/m-p/838366#M144625</link>
    <description>&lt;P&gt;Kind of new to the more advanced Wireless stuff, and must making sure I'm on the right track.  We have the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4400 series WLCs w/ 4.1 software&lt;/P&gt;&lt;P&gt;1242 APs&lt;/P&gt;&lt;P&gt;SecureACS 4.0 servers&lt;/P&gt;&lt;P&gt;Unix LDAP servers&lt;/P&gt;&lt;P&gt;Windows 2000 servers running AD&lt;/P&gt;&lt;P&gt;Mix of Windows, Linux, and Mac clients&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Given the above list, we'd like to have secure (encrypted + authenticated) wireless access for users.  I'm thinking PEAP with the SecureACS servers is the way to go.  Does this sound right, and where should I look for configuration documentation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 03 Jul 2021 22:08:18 GMT</pubDate>
    <dc:creator>johnnylingo</dc:creator>
    <dc:date>2021-07-03T22:08:18Z</dc:date>
    <item>
      <title>Getting Started: PEAP w/ SecureACS</title>
      <link>https://community.cisco.com/t5/wireless/getting-started-peap-w-secureacs/m-p/838366#M144625</link>
      <description>&lt;P&gt;Kind of new to the more advanced Wireless stuff, and must making sure I'm on the right track.  We have the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4400 series WLCs w/ 4.1 software&lt;/P&gt;&lt;P&gt;1242 APs&lt;/P&gt;&lt;P&gt;SecureACS 4.0 servers&lt;/P&gt;&lt;P&gt;Unix LDAP servers&lt;/P&gt;&lt;P&gt;Windows 2000 servers running AD&lt;/P&gt;&lt;P&gt;Mix of Windows, Linux, and Mac clients&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Given the above list, we'd like to have secure (encrypted + authenticated) wireless access for users.  I'm thinking PEAP with the SecureACS servers is the way to go.  Does this sound right, and where should I look for configuration documentation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 22:08:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/getting-started-peap-w-secureacs/m-p/838366#M144625</guid>
      <dc:creator>johnnylingo</dc:creator>
      <dc:date>2021-07-03T22:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started: PEAP w/ SecureACS</title>
      <link>https://community.cisco.com/t5/wireless/getting-started-peap-w-secureacs/m-p/838367#M144626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PEAP would work fine with that setup.  Here's a link to the doc on setting up the controllers and ACS to use PEAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00807917aa.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00807917aa.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jan 2008 14:17:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/getting-started-peap-w-secureacs/m-p/838367#M144626</guid>
      <dc:creator>dancampb</dc:creator>
      <dc:date>2008-01-01T14:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started: PEAP w/ SecureACS</title>
      <link>https://community.cisco.com/t5/wireless/getting-started-peap-w-secureacs/m-p/838368#M144627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Stuff. Thanks for the link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I'm curious about is the CA setup.  If we already have a CA, can't we just generate, sign, and install a cert for each ACS server and then be good to go?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or, could we even use self-signed certs, assuming that the PEAP client allows it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2008 08:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/getting-started-peap-w-secureacs/m-p/838368#M144627</guid>
      <dc:creator>johnnylingo</dc:creator>
      <dc:date>2008-01-05T08:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Started: PEAP w/ SecureACS</title>
      <link>https://community.cisco.com/t5/wireless/getting-started-peap-w-secureacs/m-p/838369#M144628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't use self signed certs. I've gotten them to work, but it can be spotty depending on the supplicant.  Even on the same PC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you have a PKI infrastructure you should use that. The exception would be if you had a lot of user that are not members of your domain (at least the PCs). In that case you would have to import the root CA cert into the PCs. Given the low cost of commercial certs it we be worth it to loose the hassle factor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also use IAS on the DC's as this is an AD environment. It is a simpler configuration and I find authentication to be faster using IAS. The exception would be if the users access the network are not members of AD. In that case ACS makes more sense. You can add the users to AD, but you would have to purchase a CAL to be legal, whereas ACS wouldn't care. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2008 23:21:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/getting-started-peap-w-secureacs/m-p/838369#M144628</guid>
      <dc:creator>SHANNON WYATT</dc:creator>
      <dc:date>2008-01-09T23:21:15Z</dc:date>
    </item>
  </channel>
</rss>

