<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP vs PSK in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ldap-vs-psk/m-p/5494470#M299801</link>
    <description>&lt;P&gt;Take a look at the post that I made.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.meraki.com/t5/Wireless/FreeRadius-Integration-with-OpenLDAP-and-Dynamic-Vlan-Assignment/td-p/171440" target="_blank"&gt;https://community.meraki.com/t5/Wireless/FreeRadius-Integration-with-OpenLDAP-and-Dynamic-Vlan-Assignment/td-p/171440&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jun 2024 02:15:49 GMT</pubDate>
    <dc:creator>aleabrahao</dc:creator>
    <dc:date>2024-06-14T02:15:49Z</dc:date>
    <item>
      <title>LDAP vs PSK</title>
      <link>https://community.cisco.com/t5/wireless/ldap-vs-psk/m-p/5494467#M299798</link>
      <description>&lt;P&gt;I am setting up a new wifi ssid. This will be for our office computers. I only want company owned,  domain joined computers to be on this wifi. I don't have budget for ISE or anything like that. I need it to be reliable, but not complicated. I would be fine with saying that anyone with domain credentials should be able to get on this wifi.&lt;/P&gt;&lt;P&gt;I am trying to decide what authentication scheme I want to use. I have it narrowed down to LDAP or pre-shared key.&lt;/P&gt;&lt;P&gt;I like LDAP because it seems to be more scalable / manageable to use domain credentials. That way, everything is per-user. And, if they user is disabled, then those devices can't get on the wifi. And, I worry about the preshared key being given out.&lt;/P&gt;&lt;P&gt;On the other hand, I could do a preshared key and publish it through group policy.The users wouldn't have to know the key.&lt;/P&gt;&lt;P&gt;And, this might be the deal breaker... I want to use Wifi6 and Wifi6 requires WPA3 and it looks like I can't use LDAP and WPA3.&lt;/P&gt;&lt;P&gt;Anyway, is there something that I missing? Is there future support for WPA3 under LDAP?&lt;/P&gt;&lt;P&gt;Also, is there another protocol that talks straight to active directory other than LDAP? I thought there was, but I don't see it in the options.&lt;/P&gt;&lt;P&gt;Thanks everyone&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 22:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-vs-psk/m-p/5494467#M299798</guid>
      <dc:creator>exadmin</dc:creator>
      <dc:date>2024-06-13T22:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP vs PSK</title>
      <link>https://community.cisco.com/t5/wireless/ldap-vs-psk/m-p/5494468#M299799</link>
      <description>&lt;P&gt;You could use 802.1X with the Microsoft NPS as a RADIUS server. This comes at no monetary cost but is also not very usable. There are open-source RADIUS servers like FreeRadiusthat could be used or PacketFence.&lt;/P&gt;&lt;P&gt;But you will not reach your initial goal that only domain joined PCs can join the network. Every user with an account can join from any device he wants.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 23:44:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-vs-psk/m-p/5494468#M299799</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2024-06-13T23:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP vs PSK</title>
      <link>https://community.cisco.com/t5/wireless/ldap-vs-psk/m-p/5494469#M299800</link>
      <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/17472"&gt;@Karsten Iwen&lt;/A&gt; is bang on.&lt;/P&gt;&lt;P&gt;To meet your requirements of domain joined computers and user auth, a RADIUS server is the way to go.&lt;BR /&gt;&lt;BR /&gt;Microsoft NPS is free and works well enough but it's a bit like diving back into the early 2000's with regard to usability. You may have to spend a little bit to invest in a log viewer/interpreter to actually troubleshoot auth failures (Eg. IAS Log Viewer).&lt;BR /&gt;That said, it's so widely used that there's heaps of online resources.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 00:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-vs-psk/m-p/5494469#M299800</guid>
      <dc:creator>Brash</dc:creator>
      <dc:date>2024-06-14T00:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP vs PSK</title>
      <link>https://community.cisco.com/t5/wireless/ldap-vs-psk/m-p/5494470#M299801</link>
      <description>&lt;P&gt;Take a look at the post that I made.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.meraki.com/t5/Wireless/FreeRadius-Integration-with-OpenLDAP-and-Dynamic-Vlan-Assignment/td-p/171440" target="_blank"&gt;https://community.meraki.com/t5/Wireless/FreeRadius-Integration-with-OpenLDAP-and-Dynamic-Vlan-Assignment/td-p/171440&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 02:15:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-vs-psk/m-p/5494470#M299801</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2024-06-14T02:15:49Z</dc:date>
    </item>
  </channel>
</rss>

