<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic restriction base on ssid in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755271#M32766</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should i use the command "radius-server vsa send authentication" in order to enable av-pairs in access points requests? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 06 Aug 2011 12:14:38 GMT</pubDate>
    <dc:creator>Christos Stefaneskou</dc:creator>
    <dc:date>2011-08-06T12:14:38Z</dc:date>
    <item>
      <title>restriction base on ssid</title>
      <link>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755267#M32762</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 4 autonomous AP 1142 with 2 ssids : SSID10,vlan10 &amp;amp; SSID20,vlan 20.&lt;/P&gt;&lt;P&gt;I use ACS 4.2 in order to authenticate users (EAP-FAST).How can i restrict access base on ssid&amp;nbsp; or on vlan?&lt;/P&gt;&lt;P&gt;I want users that connect to SSID 10 to not have access to SSID 20 and the opposite.&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 03:31:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755267#M32762</guid>
      <dc:creator>Christos Stefaneskou</dc:creator>
      <dc:date>2021-07-04T03:31:50Z</dc:date>
    </item>
    <item>
      <title>restriction base on ssid</title>
      <link>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755268#M32763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Broadcast 1 SSID and do not broadcast another.. or you can block them on the L3 device by configuring ACLs..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please dont forget to rate the usefull posts!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Surendra&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Aug 2011 00:35:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755268#M32763</guid>
      <dc:creator>Surendra BG</dc:creator>
      <dc:date>2011-08-06T00:35:11Z</dc:date>
    </item>
    <item>
      <title>restriction base on ssid</title>
      <link>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755269#M32764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Christos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also leverage cisco av-pairs to restrict users/groups based on ssid on the ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ACS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;Go into the user or group and check 'cisco-av-pair' and then put in &lt;BR /&gt;'ssid=SSID10' (without quotes) to restrict the user. If this attribute &lt;BR /&gt;does not appear on the user or group you want to test, please be sure &lt;BR /&gt;you it turned on under Interface Config --&amp;gt; Radius (Cisco IOS/PIX &lt;BR /&gt;6.x)--&amp;gt; cisco-av-pair is checked on user/group. If it is still not &lt;BR /&gt;showing up under a user, please be sure that you have 'Per-user &lt;BR /&gt;TACACS+/RADIUS Attributes' turned on under Interface Config --&amp;gt; Advanced &lt;BR /&gt;Options.&lt;BR /&gt;&lt;BR /&gt;-Patrick Croak&lt;BR /&gt;Wireless TAC&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Aug 2011 00:39:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755269#M32764</guid>
      <dc:creator>pcroak</dc:creator>
      <dc:date>2011-08-06T00:39:50Z</dc:date>
    </item>
    <item>
      <title>restriction base on ssid</title>
      <link>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755270#M32765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; tried to restrict access using NARs without success.&lt;/P&gt;&lt;P&gt;I'will try the solution that you suggested (cisco av-pairs) and i'll inform you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Aug 2011 11:45:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755270#M32765</guid>
      <dc:creator>Christos Stefaneskou</dc:creator>
      <dc:date>2011-08-06T11:45:27Z</dc:date>
    </item>
    <item>
      <title>restriction base on ssid</title>
      <link>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755271#M32766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should i use the command "radius-server vsa send authentication" in order to enable av-pairs in access points requests? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Aug 2011 12:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755271#M32766</guid>
      <dc:creator>Christos Stefaneskou</dc:creator>
      <dc:date>2011-08-06T12:14:38Z</dc:date>
    </item>
    <item>
      <title>restriction base on ssid</title>
      <link>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755272#M32767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Christos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you should have radius-server vsa send authentication configured to send the av-pairs to your server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can see if the ssid is being sent by capturing the following debugs when trying to connect:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;debug aaa authentication&lt;BR /&gt;debug aaa authorization&lt;BR /&gt;debug radius&lt;BR /&gt;debug dot1x all&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Aug 2011 16:28:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755272#M32767</guid>
      <dc:creator>pcroak</dc:creator>
      <dc:date>2011-08-06T16:28:50Z</dc:date>
    </item>
    <item>
      <title>restriction base on ssid</title>
      <link>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755273#M32768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One more question Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my case, should i enable the vendor proprietary attributes with the command " radius-server host xxx.xxx.xxx nonstandard "? Is any other configuration exept the above that i should use on the AP?&lt;/P&gt;&lt;P&gt;Have you tryied this scenario using NAR?&lt;/P&gt;&lt;P&gt;I will test it probably in 3 days so i'll let you know about the result..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Aug 2011 16:48:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755273#M32768</guid>
      <dc:creator>Christos Stefaneskou</dc:creator>
      <dc:date>2011-08-07T16:48:29Z</dc:date>
    </item>
    <item>
      <title>restriction base on ssid</title>
      <link>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755274#M32769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;5 stars for your answer Patrick!&lt;/P&gt;&lt;P&gt;Your solution works perfect...&lt;/P&gt;&lt;P&gt;The problem i have now is that the clients doesn't get valid DNS server..We are using ACS to act as DHCP and serve ips for the 2 ssids.The clients get a valid ip but the DNS on client appears in HEX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2011 18:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/restriction-base-on-ssid/m-p/1755274#M32769</guid>
      <dc:creator>Christos Stefaneskou</dc:creator>
      <dc:date>2011-08-12T18:46:09Z</dc:date>
    </item>
  </channel>
</rss>

