<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Catalyst 9800 iPSK without RADIUS in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/catalyst-9800-ipsk-without-radius/m-p/5169128#M275129</link>
    <description>&lt;P&gt;you need ISE or radius for iPSK&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
    <pubDate>Sun, 01 Sep 2024 20:36:16 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-09-01T20:36:16Z</dc:date>
    <item>
      <title>Catalyst 9800 iPSK without RADIUS</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ipsk-without-radius/m-p/5167066#M274959</link>
      <description>&lt;P&gt;Does anyone know if it is possible yet to leverage iPSK on Catalyst 9800 without the need for ISE integration? The ask form one of our customers is:&lt;/P&gt;
&lt;P&gt;- To be able to leverage a single SSID with up to 10 separate iPSK groups, with the ability to assign each iPSK group to a different VLAN and apply a per VLAN based QoS policy. The end user devices should not leverage a http/https on boarding portal or usage policy splash screen as some devices will not support web interfaces i.e. they are IoT appliances. The end users will not have time to provide their devices MAC address in advance nor be burdened with the need to do so once on site.&lt;/P&gt;
&lt;P&gt;So the required access is effectively PSK based in the 2.4 and 5 Ghz spectrums, iPSK groups map to a VLAN/QoS policy. A Cisco UDN Plus solution is not practical.&lt;/P&gt;
&lt;P&gt;The customer has the latest series 91xx APs, 9800 WLC, Catalyst Centre with Advantage licensing.&lt;/P&gt;
&lt;P&gt;Is the above configuration possible, are there any scaling issues or dependencies?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 11:24:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ipsk-without-radius/m-p/5167066#M274959</guid>
      <dc:creator>steve.blunt</dc:creator>
      <dc:date>2024-08-28T11:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800 iPSK without RADIUS</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ipsk-without-radius/m-p/5167088#M274961</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Check if this can help you :&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh18572" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh18572&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; + This being for Meraki but perhaps it can contain useful elements :&amp;nbsp;&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/IPSK_Authentication_without_RADIUS" target="_blank"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/IPSK_Authentication_without_RADIUS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 12:03:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ipsk-without-radius/m-p/5167088#M274961</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-08-28T12:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800 iPSK without RADIUS</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ipsk-without-radius/m-p/5167099#M274962</link>
      <description>&lt;P&gt;The solutions currently supported in the 9800 rely upon Mac address.&lt;BR /&gt;If you have ISE, then a non-cisco supported tool such as ipsk manager can work with ise to simplify the Mac address overhead.&lt;BR /&gt;&lt;BR /&gt;But, yes, the iPSK feature can work with other radius servers, e.g. FreeRadius - if that is your question?&lt;BR /&gt;Your challenge remains though, with the overhead and management of the Mac addresses - you will need to create a list of MAC in the AAA server to authorise these devices. But then does give you the flexibility to assign vlan etc from the AAA server.&lt;BR /&gt;&lt;BR /&gt;Or were you asking if this can be natively done on the 9800 itself ?&lt;BR /&gt;MPSK allows upto x5 separate PSK to be enabled upon a single ssid - no need for any Mac address, and does not need AAA servers etc, but there is no ability to drop these clients into separate vlans using this method either.&lt;BR /&gt;&lt;BR /&gt;On the meraki side, they do have a solution call WPN that does not rely upon Mac addresses, but as you have catalyst, it is unlikely you can take advantage of this approach.&lt;BR /&gt;&lt;BR /&gt;9800 did have a solution called easy-psk that was only ever introduced as a beta in 17.6 code (info in the config guide for 17.6 only)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 12:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ipsk-without-radius/m-p/5167099#M274962</guid>
      <dc:creator>Jason Tyler</dc:creator>
      <dc:date>2024-08-28T12:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800 iPSK without RADIUS</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ipsk-without-radius/m-p/5169111#M275123</link>
      <description>&lt;P&gt;EasyPSK is still radius based, and only works when the AP is in Local Mode - not supported at all if the AP is in Flexconnect Mode.&lt;/P&gt;
&lt;P&gt;Nice guide for doing iPSK with FreeRadius:&amp;nbsp;&lt;A href="https://goodwi.fi/posts/2023/09/ipsk-no-ise-freeradius/" target="_blank" rel="noopener"&gt;https://goodwi.fi/posts/2023/09/ipsk-no-ise-freeradius/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;More discussion here&amp;nbsp;&lt;A href="https://www.reddit.com/r/Cisco/comments/1bznm8m/wifi_devices_without_wpa23_enterprise_mpsk_ipsk/" target="_blank" rel="noopener"&gt;https://www.reddit.com/r/Cisco/comments/1bznm8m/wifi_devices_without_wpa23_enterprise_mpsk_ipsk/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 18:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ipsk-without-radius/m-p/5169111#M275123</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-09-01T18:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800 iPSK without RADIUS</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ipsk-without-radius/m-p/5169128#M275129</link>
      <description>&lt;P&gt;you need ISE or radius for iPSK&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 20:36:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ipsk-without-radius/m-p/5169128#M275129</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-09-01T20:36:16Z</dc:date>
    </item>
  </channel>
</rss>

