<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC and AD integration without using external AAA server. in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830458#M216045</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I agree with you but he is testing the network and try to find out the root cause. If it will uncheck then we will get the root cause after that we can suggest him to push certificate on client's using the GPO.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Deepak Kumar&lt;/P&gt;</description>
    <pubDate>Tue, 02 Apr 2019 08:33:08 GMT</pubDate>
    <dc:creator>Deepak Kumar</dc:creator>
    <dc:date>2019-04-02T08:33:08Z</dc:date>
    <item>
      <title>WLC and AD integration without using external AAA server.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3826892#M216037</link>
      <description>&lt;P&gt;Hi Fellows ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have deployed WLC 3504 and Customer wants to give SSID access via&amp;nbsp; AD credentials for employees . We have configured WLC for getting users authenticated via LDAP integration.&amp;nbsp; But domain end user&amp;nbsp; getting certificate&amp;nbsp; errors.&lt;/P&gt;&lt;P&gt;Customer is not interested in installing&amp;nbsp; Cisco PEAP across the organization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to get user authenticated via WLC and LDAP integration without Cisco PEAP&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;Or&amp;nbsp; MS NPS or some external RADIUS is must for this ?&amp;nbsp;&amp;nbsp; Has WLC some limitations in this integration ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in anticipation .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adnan&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 17:08:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3826892#M216037</guid>
      <dc:creator>Adnan_Siddiqi</dc:creator>
      <dc:date>2021-07-05T17:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and AD integration without using external AAA server.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3826907#M216038</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Certificate error means you are using "&lt;SPAN&gt;LDAPS". Is it correct?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Follow this documents:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010101100.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010101100.pdf&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Meanwhile, you can do it with NPS as well.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Deepak Kumar&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 09:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3826907#M216038</guid>
      <dc:creator>Deepak Kumar</dc:creator>
      <dc:date>2019-03-27T09:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and AD integration without using external AAA server.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3829754#M216039</link>
      <description>&lt;P&gt;Hi , Deepak&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal is : &amp;nbsp;end user to connect &amp;nbsp;&amp;nbsp;the&amp;nbsp; SSID &amp;nbsp;using&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="mailto:user@domain.com" target="_blank"&gt;user@domain.com&lt;/A&gt;&amp;nbsp; and AD Password &amp;nbsp;( Both Domain connected Systems &amp;nbsp;and BYOD ) &amp;nbsp;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At start we don't want to add another Network Element like external AAA server &amp;nbsp;and &amp;nbsp;wanted to use&amp;nbsp; WLC 's LDAP integration option to achieve the goal .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By Certificate error the connection gives digital certificate error&amp;nbsp; I think this can be over by using PEAP&amp;nbsp; ? Is there any limitation on WLC for using Only Cisco PEAP ?&amp;nbsp;&amp;nbsp; Can't we use default MS -PEAP&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 08:12:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3829754#M216039</guid>
      <dc:creator>Adnan_Siddiqi</dc:creator>
      <dc:date>2019-04-01T08:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and AD integration without using external AAA server.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3829867#M216040</link>
      <description>&lt;P&gt;PFA&amp;nbsp; error image&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 11:29:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3829867#M216040</guid>
      <dc:creator>Adnan_Siddiqi</dc:creator>
      <dc:date>2019-04-01T11:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and AD integration without using external AAA server.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830044#M216041</link>
      <description>This is a completely normal message and is always shown if you aren't already trusting this certificate on the client. You'd need an MDM solution for the client, where you first install the certificate in the trust store and assign it to the client-wireless profile and then connect.</description>
      <pubDate>Mon, 01 Apr 2019 15:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830044#M216041</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-04-01T15:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and AD integration without using external AAA server.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830409#M216042</link>
      <description>&lt;P&gt;&amp;nbsp; I think&amp;nbsp; PEAP&amp;nbsp; is used to avoid Client side installation of Certificates.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to work with MS PEAP which is available with normal installation of&amp;nbsp; Wireless adapter ( Cisco PEAP is to be additionally&amp;nbsp; installed again organization wide) , Authentication from WLC using AD as back end DB without any external RADIUS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or&amp;nbsp; using MS PEAP at wireless client to get authenticated from AD&amp;nbsp; requires ( mandatory )&amp;nbsp; NPS or Other External RADIUS ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in anticipation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 07:20:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830409#M216042</guid>
      <dc:creator>Adnan_Siddiqi</dc:creator>
      <dc:date>2019-04-02T07:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and AD integration without using external AAA server.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830440#M216043</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thanks for making more clear. I think your certificate is not published on the AD group policies so it didn't push to the client. Try with making some changes in the client 's network interface as showing in below pic:&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Certificate.jpg" style="width: 200px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33389iBCD5E86461EE466D/image-size/small?v=v2&amp;amp;px=200" role="button" title="Certificate.jpg" alt="Certificate.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Uncheck the option: Verify the server identity by validating the certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Deepak Kumar&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 07:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830440#M216043</guid>
      <dc:creator>Deepak Kumar</dc:creator>
      <dc:date>2019-04-02T07:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and AD integration without using external AAA server.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830449#M216044</link>
      <description>I suggest to NOT uncheck this option, otherwise somebody else can create a copy of the SSID and phish the cleartext username+password of your domain users. &lt;BR /&gt;If the clients are managed, you can push a group policy containing the correct certificate to the Windows clients. If they are not managed, you can either program an installer that creates the profile and installs the certificate, or have the users click on Connect (after having verified that the certificate checksum matches the correct checksum, which you have documented somewhere.</description>
      <pubDate>Tue, 02 Apr 2019 08:12:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830449#M216044</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-04-02T08:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and AD integration without using external AAA server.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830458#M216045</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I agree with you but he is testing the network and try to find out the root cause. If it will uncheck then we will get the root cause after that we can suggest him to push certificate on client's using the GPO.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Deepak Kumar&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 08:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830458#M216045</guid>
      <dc:creator>Deepak Kumar</dc:creator>
      <dc:date>2019-04-02T08:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and AD integration without using external AAA server.</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830525#M216046</link>
      <description>&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Collaborator lia-component-message-view-widget-author-username"&gt;Dear&amp;nbsp; Deepak and &lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/323352" target="_self"&gt;&lt;SPAN class=""&gt;patoberli :&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Collaborator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Thanks for your continued support .&amp;nbsp;&amp;nbsp; We&amp;nbsp; have to come to following understanding. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Collaborator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;If we select&amp;nbsp; Cisco PEAP on Client we don't need to push any certificate to end user and that's what we need . For MS-PEAP we would require certificates on the client side .&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Collaborator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;As Found on this link &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Collaborator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;A href="https://community.cisco.com/t5/wireless-security-and-network/cisco-peap-vs-ms-peap/td-p/342607?attachment-id=105929" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/wireless-security-and-network/cisco-peap-vs-ms-peap/td-p/342607?attachment-id=105929&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Collaborator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Combining with &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Collaborator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/211277-WLC-with-LDAP-Authentication-Configurati.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/211277-WLC-with-LDAP-Authentication-Configurati.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Collaborator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;I think we got the answer why MS PEAP won't work .&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Collaborator lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Now we have to test using Cisco PEAP only client side and using&amp;nbsp; WLC as authentication server with AD as back end DB . &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 10:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-ad-integration-without-using-external-aaa-server/m-p/3830525#M216046</guid>
      <dc:creator>Adnan_Siddiqi</dc:creator>
      <dc:date>2019-04-02T10:07:40Z</dc:date>
    </item>
  </channel>
</rss>

