<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC 2504 Layer 2 Security in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3795872#M5220</link>
    <description>&lt;P&gt;Hey!&lt;/P&gt;&lt;P&gt;can someone tell me the difference between these two configurations:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wlan1.JPG" style="width: 513px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29403iC6C104FCBB2D15BB/image-size/large?v=v2&amp;amp;px=999" role="button" title="wlan1.JPG" alt="wlan1.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wlan2.JPG" style="width: 561px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29404i0A86E55A55B71ACB/image-size/large?v=v2&amp;amp;px=999" role="button" title="wlan2.JPG" alt="wlan2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 16:48:36 GMT</pubDate>
    <dc:creator>as00001111</dc:creator>
    <dc:date>2021-07-05T16:48:36Z</dc:date>
    <item>
      <title>WLC 2504 Layer 2 Security</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3795872#M5220</link>
      <description>&lt;P&gt;Hey!&lt;/P&gt;&lt;P&gt;can someone tell me the difference between these two configurations:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wlan1.JPG" style="width: 513px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29403iC6C104FCBB2D15BB/image-size/large?v=v2&amp;amp;px=999" role="button" title="wlan1.JPG" alt="wlan1.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wlan2.JPG" style="width: 561px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29404i0A86E55A55B71ACB/image-size/large?v=v2&amp;amp;px=999" role="button" title="wlan2.JPG" alt="wlan2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 16:48:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3795872#M5220</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2021-07-05T16:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504 Layer 2 Security</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3795971#M5221</link>
      <description>First one is using the unsafe WEP protocol, while the second one is using the safe and state of the art WPA2 with AES. Only use the second.</description>
      <pubDate>Wed, 06 Feb 2019 14:42:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3795971#M5221</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-02-06T14:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504 Layer 2 Security</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3795998#M5222</link>
      <description>&lt;P&gt;I wanted to ask regarding the 802.1X Auth.&lt;/P&gt;&lt;P&gt;What is the difference regarding 802.1X ?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 15:18:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3795998#M5222</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2019-02-06T15:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504 Layer 2 Security</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3796016#M5223</link>
      <description>That one I don't know for sure. &lt;BR /&gt;In any case, if you enable 802.1x, you can use a RADIUS server for authentication, something that would not work if you'd use PSK.&lt;BR /&gt;The same is valid for both variants, just that the first one will use WEP, while the second one will use WPA2-AES for data encryption in the air. &lt;BR /&gt;</description>
      <pubDate>Wed, 06 Feb 2019 15:30:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3796016#M5223</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-02-06T15:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504 Layer 2 Security</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3796336#M5224</link>
      <description>&lt;P&gt;The First one is using &lt;SPAN&gt;using 802.1x is when using Cisco LEAP authentication, it&amp;nbsp;doesn't use any WPA or WPA2 encryption but instead uses WEP encryption.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;You will more than likely find that with the introduction of WPA3 that this option will be remove to enable the AP/ Controllers to gain WPA3 certification from the WIFI Alliance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The second one is using the WPA2 AES encryption with 802.1x authentication. If you require a PSK network untick the 802.1X box and tick the PSK box and enter the PSK to the box that pops up&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Layer 2 security there are really only 2 options that you would use:&lt;/P&gt;
&lt;P&gt;WPA+WPA2 or none&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 21:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3796336#M5224</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2019-02-06T21:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504 Layer 2 Security</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3796538#M5225</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/332987"&gt;@Haydn Andrews&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;I understand!&lt;/P&gt;&lt;P&gt;Additionally, I would like to do 802.1X Mac Authentication/Mac Filtering with a Microsoft Network Policy Radius Server.&lt;/P&gt;&lt;P&gt;I followed that manual:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/91901-mac-filters-wlcs-config.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/91901-mac-filters-wlcs-config.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It says:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Click &lt;STRONG&gt;Security &amp;gt; MAC Filtering&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the MAC Filtering window, choose the type of RADIUS server under RADIUS Compatibility Mode.&lt;/P&gt;&lt;P&gt;This example uses Cisco ACS.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;From the MAC Delimiter pull down menu, choose the MAC delimiter.&lt;/P&gt;&lt;P&gt;This example uses Colon.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I want to do that with the Microsoft NPS, which RADIUS Compatibility Mode and MAC Delimiter is correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 08:24:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3796538#M5225</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2019-02-07T08:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504 Layer 2 Security</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3796551#M5226</link>
      <description>Under the WLAN select you NPS server under the AAA servers.&lt;BR /&gt;&lt;BR /&gt;For NPS I believe that Cisco ACS and colon delimiter is correct.&lt;BR /&gt;&lt;BR /&gt;To determine which mode you need to know what the NPS RADIUS server is expecting for the password for the mac auth. &lt;BR /&gt;ACS expects to see the username and password to both be the mac address for mac authentication. &lt;BR /&gt;Free Radius uses a shared secret for a password. &lt;BR /&gt;And other Radius servers don't require any password for mac auths sent to the server.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 07 Feb 2019 08:36:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3796551#M5226</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2019-02-07T08:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504 Layer 2 Security</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3797584#M5227</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/332987"&gt;@Haydn Andrews&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I also have to check the "Mac Filtering" box under Layer 2 Security, don't I?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you mean with password for the mac auth?&lt;/P&gt;&lt;P&gt;My NPS Server is installed on my domain controller with Active Directory. So my intention is to create a user that has the mac address as username and password, without colons, for example: 00a24455d223.&lt;/P&gt;&lt;P&gt;Then I want to add that user to a domain group. In the NPS I want to create a network policy with the condition "windows group". I then choose the group that contains the mac address users. (as I said before).&lt;/P&gt;&lt;P&gt;Do you think that works?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 10:04:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3797584#M5227</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2019-02-08T10:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504 Layer 2 Security</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3797611#M5228</link>
      <description>&lt;P&gt;When your doing MAC auth with radius, the WLC sends a username and password to the RADIUS server.&lt;/P&gt;
&lt;P&gt;If you select mode Cisco ACS it uses the client MAC address for both the username and password. If your configuring this on AD and having NPS check this then that will work.&lt;/P&gt;
&lt;P&gt;Check the delimiter matches how you plan to enter these.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is your plan to also look at user Auth? or only consumed with the mac auth?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your looking at both, you could use RADIUS rules (now i cant talk for NPS as my RADIUS experience is limited to ISE) and the auth is against the users credentials but you also use the client MAC address to define the authorisation policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;
&lt;P&gt;Haydn&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 10:40:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3797611#M5228</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2019-02-08T10:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504 Layer 2 Security</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3797636#M5229</link>
      <description>&lt;P&gt;And I need to check that box, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wlan.JPG" style="width: 495px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/29675i72AFF80FFD8D778D/image-size/large?v=v2&amp;amp;px=999" role="button" title="wlan.JPG" alt="wlan.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 11:16:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3797636#M5229</guid>
      <dc:creator>as00001111</dc:creator>
      <dc:date>2019-02-08T11:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504 Layer 2 Security</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3797637#M5230</link>
      <description>&lt;P&gt;correct&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 11:18:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-layer-2-security/m-p/3797637#M5230</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2019-02-08T11:18:11Z</dc:date>
    </item>
  </channel>
</rss>

