<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can you do wireless device profiling and policy classification on Cisco WLC without external RADIUS server? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/can-you-do-wireless-device-profiling-and-policy-classification/m-p/3911192#M170598</link>
    <description>&lt;P&gt;I don't think you can do by role string for local auth, however your matching criteria can be EAP-TYPE (I think device type also works but I have not used it myself), then you can allocate any of the values in Action field.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2019 00:58:17 GMT</pubDate>
    <dc:creator>Ambuj M</dc:creator>
    <dc:date>2019-08-21T00:58:17Z</dc:date>
    <item>
      <title>Can you do wireless device profiling and policy classification on Cisco WLC without external RADIUS server?</title>
      <link>https://community.cisco.com/t5/wireless/can-you-do-wireless-device-profiling-and-policy-classification/m-p/3909944#M170596</link>
      <description>&lt;P&gt;I just found out that you can do &lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/7-5/NativeProfiling75.html#pgfId-55504" target="_self"&gt;profiling and policy classification&lt;/A&gt; on Cisco WLC to assign session timeouts, ACLs, and VLANs regardless of what those settings are set to on the WLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For it to work though, it looks like you need an external RADIUS server to return the Cisco-AV-Pair setting and "role=role_value" so that the correct policy can be picked up (I can't match on device type or EAP type for my specific scenario).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know how to use local authentication on the Cisco WLC to point the clients to the correct role string so that I do not have to use an external RADIUS server? My WLAN has layer 2 security enabled, and is using LOCAL EAP authentication.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 17:52:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/can-you-do-wireless-device-profiling-and-policy-classification/m-p/3909944#M170596</guid>
      <dc:creator>Sam Brynes</dc:creator>
      <dc:date>2021-07-05T17:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can you do wireless device profiling and policy classification on Cisco WLC without external RADIUS server?</title>
      <link>https://community.cisco.com/t5/wireless/can-you-do-wireless-device-profiling-and-policy-classification/m-p/3910121#M170597</link>
      <description>&lt;P&gt;Hi Sam,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I know, the role string is the only thing that should be provided by the well-known cisco-av-pair in a local policy. The Radius engine on the WLC is light. When you configure your local policy there are only 3 conditions that you can match to trigger the policy :&lt;/P&gt;&lt;P&gt;- Role (should be provided by a Radius)&lt;/P&gt;&lt;P&gt;- EAP Type (the WLC can snoop that)&lt;/P&gt;&lt;P&gt;- Device Type (the WLC can use its local profiling table assuming that you configured local profiling on the WLAN)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you can't match the role because this attribute has not been sent by the Radius, you can only trigger your policy with the EAP type and the device type.&lt;/P&gt;&lt;P&gt;As you can see, the role is a MATCH criteria and not an action that will apply something to the client session.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 11:04:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/can-you-do-wireless-device-profiling-and-policy-classification/m-p/3910121#M170597</guid>
      <dc:creator>MTOMASSINI</dc:creator>
      <dc:date>2019-08-19T11:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can you do wireless device profiling and policy classification on Cisco WLC without external RADIUS server?</title>
      <link>https://community.cisco.com/t5/wireless/can-you-do-wireless-device-profiling-and-policy-classification/m-p/3911192#M170598</link>
      <description>&lt;P&gt;I don't think you can do by role string for local auth, however your matching criteria can be EAP-TYPE (I think device type also works but I have not used it myself), then you can allocate any of the values in Action field.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 00:58:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/can-you-do-wireless-device-profiling-and-policy-classification/m-p/3911192#M170598</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2019-08-21T00:58:17Z</dc:date>
    </item>
  </channel>
</rss>

