<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LEAP Authentication using 2 usernames for 80 devices - Any problems? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/leap-authentication-using-2-usernames-for-80-devices-any/m-p/202831#M20809</link>
    <description>&lt;P&gt;Here is the setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LEAP Authentication for two VLAN's using 4 1100 Aironet AP's.  The IOS is the latest, 12.2(11)JA1.   60 of the devices are student workstation laptops at a school.  The other 20 devices are teacher laptops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Against my security opinions, the decision was made to configure all the student laptops with one LEAP username and password and put them into one VLAN/SSID.  The same idea for all teacher laptops but with a different VLAN/SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;None of the students or teachers know what the passwords are as the IT folks configured every device manually.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS 3.2 is configured to allow the single teacher and single student LEAP username to authenticate unlimited times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When more than 2 or 3 student laptops are authenticated with an AP, the other laptops have a difficult time getting on at all and sometimes causes us to reboot the AP which might get the situation resolved temporarily or might not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Needless to say, the teachers are not happy with the situation as it has almost become useless.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using LEAP before I have never done this type of setup.  I have always used single unique username per LEAP client for corporate wireless logins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the problems being caused by using this single username configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has been confirmed that using no WEP/LEAP and only SSID authentication configuration allows 20+ laptops to authenticate for long periods of time with no issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 16:03:22 GMT</pubDate>
    <dc:creator>woodsbc</dc:creator>
    <dc:date>2021-07-04T16:03:22Z</dc:date>
    <item>
      <title>LEAP Authentication using 2 usernames for 80 devices - Any problems?</title>
      <link>https://community.cisco.com/t5/wireless/leap-authentication-using-2-usernames-for-80-devices-any/m-p/202831#M20809</link>
      <description>&lt;P&gt;Here is the setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LEAP Authentication for two VLAN's using 4 1100 Aironet AP's.  The IOS is the latest, 12.2(11)JA1.   60 of the devices are student workstation laptops at a school.  The other 20 devices are teacher laptops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Against my security opinions, the decision was made to configure all the student laptops with one LEAP username and password and put them into one VLAN/SSID.  The same idea for all teacher laptops but with a different VLAN/SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;None of the students or teachers know what the passwords are as the IT folks configured every device manually.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS 3.2 is configured to allow the single teacher and single student LEAP username to authenticate unlimited times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When more than 2 or 3 student laptops are authenticated with an AP, the other laptops have a difficult time getting on at all and sometimes causes us to reboot the AP which might get the situation resolved temporarily or might not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Needless to say, the teachers are not happy with the situation as it has almost become useless.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using LEAP before I have never done this type of setup.  I have always used single unique username per LEAP client for corporate wireless logins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the problems being caused by using this single username configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has been confirmed that using no WEP/LEAP and only SSID authentication configuration allows 20+ laptops to authenticate for long periods of time with no issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 16:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/leap-authentication-using-2-usernames-for-80-devices-any/m-p/202831#M20809</guid>
      <dc:creator>woodsbc</dc:creator>
      <dc:date>2021-07-04T16:03:22Z</dc:date>
    </item>
  </channel>
</rss>

