<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WCS/WLC read-only access in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/5040777#M268312</link>
    <description>&lt;P&gt;Here is a document for the 9800 series controllers using TACACS / ISE:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214490-configure-radius-and-tacacs-for-gui-and.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214490-configure-radius-and-tacacs-for-gui-and.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Mar 2024 12:34:26 GMT</pubDate>
    <dc:creator>divanko</dc:creator>
    <dc:date>2024-03-15T12:34:26Z</dc:date>
    <item>
      <title>WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222969#M9406</link>
      <description>&lt;P&gt;We use WCS and AAA in our wireless environment. Reading through the WCS user guide (&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/wireless/wcs/5.2/configuration/guide/5_2manag.html#wp1089936" target="_blank"&gt;http://www.cisco.com/en/US/docs/wireless/wcs/5.2/configuration/guide/5_2manag.html#wp1089936&lt;/A&gt;) , authorization seems awfully course grained. Is there a way to provide a security group with login and read-only rights to all aspects of all wireless components (or at least to WCS and all WLC)? Ideally, the security group would be able to login to any WLC at any time and verify settings, etc.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 00:19:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222969#M9406</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2021-07-04T00:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222970#M9407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure you can. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the WLC, go to Management -&amp;gt; Local Management User -&amp;gt; New -&amp;gt; under User Access Mode, choose ReadOnly. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this help?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Mar 2009 01:21:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222970#M9407</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2009-03-17T01:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222971#M9408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, not really.  We're using WCS to manage the infrastructure and we're using AAA authentication. Manually adding local users on a bunch of WLC's isn't really enterprise management.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Mar 2009 12:48:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222971#M9408</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2009-03-17T12:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222972#M9409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you want a script that will add Guest users, perhaps?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Mar 2009 21:29:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222972#M9409</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2009-03-17T21:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222973#M9410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no, we use a NAC guest server for that.  This is about "management" access to the infrastructure.  One group needs full read only access. I'll have to ask our local engineers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Mar 2009 17:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222973#M9410</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2009-03-18T17:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222974#M9411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may have already solved this but there is the information I use.  I have only setup the WCS and WLC to use TACACS but you should be able to use Radius as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Unified Wireless Network TACACS+ Configuration&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_tech_note09186a0080851f7c.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_tech_note09186a0080851f7c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS Server Authentication of Management Users on the Controller Configuration Example&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080782507.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080782507.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Understanding RADIUS and TACACS+ Authentication on WCS&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6305/products_tech_note09186a00809038e6.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6305/products_tech_note09186a00809038e6.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Dan Laden&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Apr 2009 00:11:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222974#M9411</guid>
      <dc:creator>Daniel Laden</dc:creator>
      <dc:date>2009-04-03T00:11:09Z</dc:date>
    </item>
    <item>
      <title>Re: WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222975#M9412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here's where I'm struggling. In that doc it says:&lt;/P&gt;&lt;P&gt;-----------&lt;/P&gt;&lt;P&gt;In the text box below Custom attributes, enter this text if the user created needs access only to WLAN, SECURITY and CONTROLLER: role1=WLAN role2=SECURITY role3=CONTROLLER.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the user needs access only to the SECURITY tab, enter this text: role1=SECURITY. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The role corresponds to the seven menu bar items in the controller web GUI. The menu bar items are MONITOR, WLAN, CONTROLLER, WIRELESS, SECURITY, MANAGEMENT and COMMAND.&lt;/P&gt;&lt;P&gt;-----------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems to imply that I can't grant READ-ONLY access to the MANAGEMENT tab...that it's an all or nothing thing.  That's not enterprise thinking.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Apr 2009 13:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222975#M9412</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2009-04-03T13:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222976#M9413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jamal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you ever find a solution?&lt;/P&gt;&lt;P&gt;I am in the same situation. I need to set up tacacs accounts that have read only access to WLC's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Sero&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jan 2010 16:19:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222976#M9413</guid>
      <dc:creator>serotonin888</dc:creator>
      <dc:date>2010-01-20T16:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222977#M9414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can achieve this with Radius with WCS. WCS uses the HTTP protocol with ACS remember. From the config guide check out : &lt;SPAN class="content"&gt; Figure 18-11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Export Task List Window:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small active_link" href="http://www.cisco.com/en/US/docs/wireless/wcs/6.0/configuration/guide/6_0admin.html#wpmkr1064294"&gt;http://www.cisco.com/en/US/docs/wireless/wcs/6.0/configuration/guide/6_0admin.html#wpmkr1064294&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Jan 2010 20:28:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222977#M9414</guid>
      <dc:creator>Lucien Avramov</dc:creator>
      <dc:date>2010-01-23T20:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222978#M9415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;We need to follow following document to ensure that user with which we are logging in has the appropriate attributes assigned,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_tech_note09186a0080851f7c.shtml"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_tech_note09186a0080851f7c.shtml&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt; What different roles means, please go through following document,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/wireless/controller/4.1/configuration/guide/c41sol.html#wp1208657"&gt;http://www.cisco.com/en/US/docs/wireless/controller/4.1/configuration/guide/c41sol.html#wp1208657&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Plz rate helpful posts-&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jan 2010 16:10:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222978#M9415</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2010-01-24T16:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222979#M9416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For WLCs, by using ROLE1=MONITOR in ACS, you effectively give the user Read Only access to the system. All menu items and settings can be seen, but cannot be changed. They look like they can be changed, but a message "Authorization Failed. Insufficient Privileges" message is returned. Your security group could audit the WLC without being able to change anything.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jan 2010 22:56:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222979#M9416</guid>
      <dc:creator>rtanner</dc:creator>
      <dc:date>2010-01-28T22:56:13Z</dc:date>
    </item>
    <item>
      <title>rtannerThanks a lot, it is</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222980#M9417</link>
      <description>&lt;P&gt;&lt;SPAN class="fullname" style="color: rgb(153, 153, 153); background-color: rgb(249, 249, 249);"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A about="/users/rtanner" class="username" datatype="" href="https://supportforums.cisco.com/users/rtanner" property="foaf:name" title="View user profile." typeof="sioc:UserAccount" lang=""&gt;rtanner&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="fullname" style="color: rgb(153, 153, 153); background-color: rgb(249, 249, 249);"&gt;&lt;SPAN rel="sioc:has_creator"&gt;Thanks a lot, it is working for me.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="fullname" style="color: rgb(153, 153, 153); background-color: rgb(249, 249, 249);"&gt;&lt;SPAN rel="sioc:has_creator"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="fullname" style="color: rgb(153, 153, 153); background-color: rgb(249, 249, 249);"&gt;&lt;SPAN rel="sioc:has_creator"&gt;Rizvan&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2014 08:13:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/1222980#M9417</guid>
      <dc:creator>RYBayramov</dc:creator>
      <dc:date>2014-10-27T08:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: WCS/WLC read-only access</title>
      <link>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/5040777#M268312</link>
      <description>&lt;P&gt;Here is a document for the 9800 series controllers using TACACS / ISE:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214490-configure-radius-and-tacacs-for-gui-and.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214490-configure-radius-and-tacacs-for-gui-and.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 12:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wcs-wlc-read-only-access/m-p/5040777#M268312</guid>
      <dc:creator>divanko</dc:creator>
      <dc:date>2024-03-15T12:34:26Z</dc:date>
    </item>
  </channel>
</rss>

