<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks Ric. I was thinking in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/guest-wireless-multiple-authentication-methods/m-p/2999018#M18985</link>
    <description>&lt;P&gt;Thanks Ric. I was thinking that would work, but I really don't want my employees to have to go the web-auth portal page.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is it possible to do the same without the web-auth portal page, maybe using WPA2 Enterprise? Have local database and if not successful, send it to radius?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wouldn't want to do this, as it would be annoying for my visitors to setup, just wondering if it's possible&lt;/P&gt;</description>
    <pubDate>Wed, 12 Oct 2016 02:34:17 GMT</pubDate>
    <dc:creator>CC Estelle</dc:creator>
    <dc:date>2016-10-12T02:34:17Z</dc:date>
    <item>
      <title>Guest Wireless - Multiple Authentication Methods</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-multiple-authentication-methods/m-p/2999016#M18983</link>
      <description>&lt;P&gt;Today, I have a guest network, which is set to authenticate via web-auth. &amp;nbsp;Is it possible to have 1 SSID for both Guest (external users) and Internal users? &amp;nbsp;Meaning, for the guest/external users, they'll connect via web-auth using a local account that lobby admin sets up for them. &amp;nbsp;For internal users, I'd have them authenticate via radius which ties to active directory.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm thinking I'll need two separate SSIDs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any other suggestions on how to make it work with one SSID would be helpful&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 12:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-multiple-authentication-methods/m-p/2999016#M18983</guid>
      <dc:creator>CC Estelle</dc:creator>
      <dc:date>2021-07-05T12:57:19Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-multiple-authentication-methods/m-p/2999017#M18984</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You can have that setup as long as you are ok using the same web-auth portal to do your internal users. You can tell the WLC to authenticate against its local db where the guest accounts are stored and, if that is not successful, it will send the request to your RADIUS server.&lt;/P&gt;
&lt;P&gt;That will require you to use the same security as the web-auth portal however, meaning at best it will be a pre-shared key or at worst it will be open authentication.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Ric&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 01:57:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-multiple-authentication-methods/m-p/2999017#M18984</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2016-10-12T01:57:25Z</dc:date>
    </item>
    <item>
      <title>Thanks Ric. I was thinking</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-multiple-authentication-methods/m-p/2999018#M18985</link>
      <description>&lt;P&gt;Thanks Ric. I was thinking that would work, but I really don't want my employees to have to go the web-auth portal page.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is it possible to do the same without the web-auth portal page, maybe using WPA2 Enterprise? Have local database and if not successful, send it to radius?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wouldn't want to do this, as it would be annoying for my visitors to setup, just wondering if it's possible&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 02:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-multiple-authentication-methods/m-p/2999018#M18985</guid>
      <dc:creator>CC Estelle</dc:creator>
      <dc:date>2016-10-12T02:34:17Z</dc:date>
    </item>
    <item>
      <title>This is something I've also</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-multiple-authentication-methods/m-p/2999019#M18986</link>
      <description>&lt;P&gt;This is something I've also had issues with&amp;nbsp;too.The only way I can see it working is instead of having a web-auth portal, you instead create your guest accounts in AD and hand the usernames/passwords out to your guests. You can't have WPA2-Enterprise running with web-auth because&amp;nbsp;there's nowhere for the clients/server to negotiate that 802.1X component.&lt;/P&gt;
&lt;P&gt;One other option I was toying with which I'm not 100% on is having WPA2-Enterprise doing EAP-FAST to the local WLC which could then do the same thing, a local db lookup with AD fallback.&lt;/P&gt;
&lt;P&gt;I haven't tested that first part to see if it is feasible so it's just an idea at this point!&lt;/P&gt;
&lt;P&gt;Ric&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 02:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-multiple-authentication-methods/m-p/2999019#M18986</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2016-10-12T02:41:12Z</dc:date>
    </item>
    <item>
      <title>exactly what I was thinking.</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-multiple-authentication-methods/m-p/2999020#M18987</link>
      <description>&lt;P&gt;exactly what I was thinking. WPA2-Enterprise with local db lookup with AD failback.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I'll probably just need to create a new SSID, as it's easiest for guests to not have to configure their clients.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 04:00:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-multiple-authentication-methods/m-p/2999020#M18987</guid>
      <dc:creator>CC Estelle</dc:creator>
      <dc:date>2016-10-12T04:00:01Z</dc:date>
    </item>
  </channel>
</rss>

