<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510829#M304588</link>
    <description>&lt;P&gt;Do you mean placing all the access points in a single VLAN and using the gateway IP address of that VLAN as the RADIUS client in NPS?&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jun 2025 15:48:17 GMT</pubDate>
    <dc:creator>Ajesh1</dc:creator>
    <dc:date>2025-06-02T15:48:17Z</dc:date>
    <item>
      <title>Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points</title>
      <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510827#M304586</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I have multiple wireless access points connected to the network that obtain their IP addresses via DHCP. As a result, their IP addresses change periodically.&lt;/P&gt;&lt;P&gt;I need to configure these APs as RADIUS clients in Windows NPS. However, since NPS requires an IP address or DNS name to identify RADIUS clients, using dynamic IPs directly is not feasible in this case.&lt;/P&gt;&lt;P&gt;Could you please advise if there is a way to configure these APs as RADIUS clients using their &lt;STRONG&gt;MAC addresses&lt;/STRONG&gt;, or is there any alternative method to handle this scenario without relying on static IPs?&lt;/P&gt;&lt;P&gt;Looking forward to your guidance.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 15:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510827#M304586</guid>
      <dc:creator>Ajesh1</dc:creator>
      <dc:date>2025-06-02T15:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points</title>
      <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510828#M304587</link>
      <description>&lt;P&gt;Put all AP's management in a single/same vlan&lt;/P&gt;&lt;P&gt;Then add the whole subnet used by that vlan to the radius &lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 15:42:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510828#M304587</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2025-06-02T15:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points</title>
      <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510829#M304588</link>
      <description>&lt;P&gt;Do you mean placing all the access points in a single VLAN and using the gateway IP address of that VLAN as the RADIUS client in NPS?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 15:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510829#M304588</guid>
      <dc:creator>Ajesh1</dc:creator>
      <dc:date>2025-06-02T15:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points</title>
      <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510830#M304589</link>
      <description>&lt;P&gt;Not the gateway. Just the whole subnet assigned to that vlan.&lt;/P&gt;&lt;P&gt;For example &lt;SPAN&gt;192.168.1.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;From ai:&lt;/P&gt;&lt;P&gt;Here's how to do it:&lt;/P&gt;&lt;P&gt;Open NPS Console: In Server Manager, click on "Tools," then "Network Policy Server". &lt;/P&gt;&lt;P&gt;Access RADIUS Clients: In the NPS console, expand "RADIUS Clients and Servers" and right-click on "RADIUS Clients". &lt;/P&gt;&lt;P&gt;Add a New Client: Choose "New". &lt;/P&gt;&lt;P&gt;Configure Client:&lt;/P&gt;&lt;P&gt;Enter a "Friendly name" for the client. &lt;/P&gt;&lt;P&gt;In the "Address (IP or DNS)" field, enter the subnet in CIDR notation (e.g., 192.168.1.0/24). &lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 15:49:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510830#M304589</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2025-06-02T15:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points</title>
      <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510831#M304590</link>
      <description>&lt;P&gt;You can just make an IP reservation for the APs on your DHCP server and the problem is solved.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 15:52:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510831#M304590</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2025-06-02T15:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points</title>
      <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510832#M304591</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Thanks, I'll try that approach.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Just one more question — if we place all the APs in a dedicated VLAN and use the subnet of that VLAN as the RADIUS client in NPS, &lt;STRONG&gt;can we still connect end-user devices (like laptops and phones) in the same subnet/VLAN&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;Will there be any &lt;STRONG&gt;impact or potential issues&lt;/STRONG&gt; with this setup?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 15:53:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510832#M304591</guid>
      <dc:creator>Ajesh1</dc:creator>
      <dc:date>2025-06-02T15:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points</title>
      <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510833#M304592</link>
      <description>&lt;P&gt;From a security and management perspective i would keep them separated. Otherwise it will not pose any issues having end users in the same vlan as APs and adding that subnet to the client list on the NPS server.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 17:13:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510833#M304592</guid>
      <dc:creator>martin-lystad</dc:creator>
      <dc:date>2025-06-02T17:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points</title>
      <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510834#M304593</link>
      <description>&lt;P&gt;^^ Do this ^^&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I always place my Meraki devices in their own Meraki Management VLAN.  That way you can add the whole subnet to your NPS&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 19:41:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510834#M304593</guid>
      <dc:creator>MerakiGnome</dc:creator>
      <dc:date>2025-06-02T19:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points</title>
      <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510835#M304594</link>
      <description>&lt;P&gt;Add it to NPS using the supernet if you like.  Like 192.168.0.0/16.  You should only need a single entry for all your APs.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 21:47:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510835#M304594</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2025-06-02T21:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points</title>
      <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510836#M304595</link>
      <description>&lt;P&gt;The only potential issue is it presents a security risk.&lt;/P&gt;&lt;P&gt;Any of the clients on that VLAN will be able to send RADIUS requests to the NPS server which can allow for malicious actions.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 02:01:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510836#M304595</guid>
      <dc:creator>Brash</dc:creator>
      <dc:date>2025-06-03T02:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: Query Regarding RADIUS Client Configuration for DHCP-Based Wireless Access Points</title>
      <link>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510837#M304596</link>
      <description>&lt;P&gt;Not sure about NPS but for Cisco ISE, one caveat with just adding the entire Management network in is that then using the Live Log for troubleshooting you will only see the NAD as the subnet, and not the device itself, as the NAD is created on the configured IP address. So if you need to determine which device it authenticating, you'll need to have added the NAD with it's host address, and not the entire network.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 19:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/query-regarding-radius-client-configuration-for-dhcp-based/m-p/5510837#M304596</guid>
      <dc:creator>Rasmus Hoffmann Birkelund</dc:creator>
      <dc:date>2025-06-03T19:03:25Z</dc:date>
    </item>
  </channel>
</rss>

