<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Scoot is correct. This is in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/801-x-wlans-authenticated-via-radius-and-active-directory-permit/m-p/2577715#M51581</link>
    <description>&lt;P&gt;Scoot is correct. This is also assumimh your other wlans are all dot1x&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Dec 2014 20:21:55 GMT</pubDate>
    <dc:creator>George Stefanick</dc:creator>
    <dc:date>2014-12-26T20:21:55Z</dc:date>
    <item>
      <title>801.x WLANs authenticated via Radius and Active Directory permit any user access any WLAN</title>
      <link>https://community.cisco.com/t5/wireless/801-x-wlans-authenticated-via-radius-and-active-directory-permit/m-p/2577713#M51578</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have configured several WLANs with WPA2 and 8021.x which authenticate users &lt;SPAN class="short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps"&gt;through Radius server (Windows Internet authentication service) that conects with an Active Directory, into the AD exists one user group for each WLAN but the problem is that any user that was added to some group can get access to any WLAN, does anyboby know if I need some configuraion on the WLC to restric that?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" lang="en"&gt;&lt;SPAN class="hps"&gt;thanks for your help.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/801-x-wlans-authenticated-via-radius-and-active-directory-permit/m-p/2577713#M51578</guid>
      <dc:creator>Alejandro.Angon</dc:creator>
      <dc:date>2021-07-05T09:11:07Z</dc:date>
    </item>
    <item>
      <title>The WLC doesn't prevent that,</title>
      <link>https://community.cisco.com/t5/wireless/801-x-wlans-authenticated-via-radius-and-active-directory-permit/m-p/2577714#M51579</link>
      <description>&lt;P&gt;The WLC doesn't prevent that, it's your radius policies that you need to look at. Maybe creating a new User Group for specific SSIDs and place users in one of those specific groups and then have a radius policy look at the called station id since the SSID will be present there and then create a policy that points to that specific User Group for that SSID.&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;</description>
      <pubDate>Fri, 26 Dec 2014 19:19:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/801-x-wlans-authenticated-via-radius-and-active-directory-permit/m-p/2577714#M51579</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2014-12-26T19:19:36Z</dc:date>
    </item>
    <item>
      <title>Scoot is correct. This is</title>
      <link>https://community.cisco.com/t5/wireless/801-x-wlans-authenticated-via-radius-and-active-directory-permit/m-p/2577715#M51581</link>
      <description>&lt;P&gt;Scoot is correct. This is also assumimh your other wlans are all dot1x&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Dec 2014 20:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/801-x-wlans-authenticated-via-radius-and-active-directory-permit/m-p/2577715#M51581</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2014-12-26T20:21:55Z</dc:date>
    </item>
    <item>
      <title>Hi Scott,I have done some</title>
      <link>https://community.cisco.com/t5/wireless/801-x-wlans-authenticated-via-radius-and-active-directory-permit/m-p/2577716#M51582</link>
      <description>&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;I have done some test modifying the Radius Policy to look at called station ID and test too looking at the NAS-ID, In the first case, I change the Call Station ID Type into WLC RADIUS Authentication Servers configuration to &lt;STRONG&gt;AP MAC Address:SSID&lt;/STRONG&gt; and AP &lt;STRONG&gt;Name:SSID&lt;/STRONG&gt; and into the Radius Server using &lt;STRONG&gt;.*:SSID-NAME$&lt;/STRONG&gt; and &lt;STRONG&gt;SSID-NAME$&lt;/STRONG&gt; ,but it blocks access for any user. In the second case, I change the NAS-ID into WLC WLAN and interface confguration and into the radius server Policy to match all, but it doesn´t have any impact, what other test could I try?&lt;/P&gt;&lt;P&gt;thanks for your help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 18:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/801-x-wlans-authenticated-via-radius-and-active-directory-permit/m-p/2577716#M51582</guid>
      <dc:creator>Alejandro.Angon</dc:creator>
      <dc:date>2015-01-07T18:18:21Z</dc:date>
    </item>
    <item>
      <title>Hi,I have done some test</title>
      <link>https://community.cisco.com/t5/wireless/801-x-wlans-authenticated-via-radius-and-active-directory-permit/m-p/2577717#M51584</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have done some test installing a new Radius Server (Windows NPS) and adding a condition that evaluates the called station ID into the Network Policy and keeping the default IP address option into the WLC Radius server configuration and now user group restricctions works&lt;/P&gt;&lt;P&gt;ragards.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Feb 2015 23:28:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/801-x-wlans-authenticated-via-radius-and-active-directory-permit/m-p/2577717#M51584</guid>
      <dc:creator>Alejandro.Angon</dc:creator>
      <dc:date>2015-02-01T23:28:48Z</dc:date>
    </item>
  </channel>
</rss>

