<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AP Authentication via ACS. in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891787#M60357</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think he is referring to ap authorization&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tiny.cc/83s8bw"&gt;http://tiny.cc/83s8bw&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Apr 2012 13:32:11 GMT</pubDate>
    <dc:creator>Amjad Abdullah</dc:creator>
    <dc:date>2012-04-04T13:32:11Z</dc:date>
    <item>
      <title>AP Authentication via ACS.</title>
      <link>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891783#M60353</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hi All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Just a basic question regarding MAC based authenitcation of AP with ACS. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;The scenario is - If I have a ACS installed and I want all my Cisco 3502 APs to be authenticated on MAC basis via ACS. I know that AP mac is used as a username and password at ACS so that whenever we plugin the new AP in the network, it gets authenticated via ACS first and if the AP is authorised to be used in network then only it gets the IP address from DHCP. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;My question is&lt;/STRONG&gt; - What will happen, if the AP is connected in local mode on a remote location and the WLC, ACS &amp;amp; DHCP are in Datacenter. The traffic coming from remote location will pass through the Remote-site router and during that pass, it will remove the source mac address of AP and put the router interface MAC address as source, so how will the ACS authenticate the AP in that case. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;When working in a LAN I know its possible, but how will it work over the WAN. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Pls. suggest ASAP. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks in Advance. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Harish &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891783#M60353</guid>
      <dc:creator>chopra.harish1</dc:creator>
      <dc:date>2021-07-04T04:56:37Z</dc:date>
    </item>
    <item>
      <title>AP Authentication via ACS.</title>
      <link>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891784#M60354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct that the MAC of the packet is changed in every subnet that you pass from the remote to the central site but the message in the packet didn't change - and the message includes the question could MAC XX-AP-XX get in or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2012 08:12:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891784#M60354</guid>
      <dc:creator>rdvorak</dc:creator>
      <dc:date>2012-04-04T08:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: AP Authentication via ACS.</title>
      <link>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891785#M60355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Harish:&lt;BR /&gt;As you may know that traffic between WLC and APs is encapsulated in CAPWAP tunnel.&lt;BR /&gt;The information insdie the CAPWAP should tell the WLC what MAC address the AP uses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CAPWAP RFC metniones that you can do AP authorization by two ways:&lt;/P&gt;&lt;P&gt;- with certificates&lt;/P&gt;&lt;P&gt;- with PSK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The standards does no imply what the PSK should be, however, Cisco seems to use it to be the mac address of the AP when the ap authorization is enabled. RFC recommends to use mac address of AP as PSK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;2.4.4.4.&amp;nbsp; PSK Usage
&amp;nbsp;&amp;nbsp; When DTLS uses PSK Ciphersuites, the ServerKeyExchange message MUST
&amp;nbsp;&amp;nbsp; contain the "PSK identity hint" field and the ClientKeyExchange
&amp;nbsp;&amp;nbsp; message MUST contain the "PSK identity" field.&amp;nbsp; These fields are used
&amp;nbsp;&amp;nbsp; to help the WTP select the appropriate PSK for use with the AC, and
&amp;nbsp;&amp;nbsp; then indicate to the AC which key is being used.&amp;nbsp; When PSKs are
&amp;nbsp;&amp;nbsp; provisioned to WTPs and ACs, both the PSK Hint and PSK Identity for
&amp;nbsp;&amp;nbsp; the key MUST be specified.
&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; The PSK Hint SHOULD uniquely identify the AC and the PSK Identity
&amp;nbsp;&amp;nbsp; SHOULD uniquely identify the WTP.&amp;nbsp; It is RECOMMENDED that these hints
&amp;nbsp;&amp;nbsp; and identities be the ASCII HEX-formatted MAC addresses of the
&amp;nbsp;&amp;nbsp; respective devices, since each pairwise combination of WTP and AC
&amp;nbsp;&amp;nbsp; SHOULD have a unique PSK.&lt;/STRONG&gt;&amp;nbsp; The PSK Hint and Identity SHOULD be
&amp;nbsp;&amp;nbsp; sufficient to perform authorization, as simply having knowledge of a
&amp;nbsp;&amp;nbsp; PSK does not necessarily imply authorization.

&amp;nbsp;&amp;nbsp; If a single PSK is being used for multiple devices on a CAPWAP
&amp;nbsp;&amp;nbsp; network, which is NOT RECOMMENDED, the PSK Hint and Identity can no
&amp;nbsp;&amp;nbsp; longer be a MAC address, so appropriate hints and identities SHOULD
&amp;nbsp;&amp;nbsp; be selected to identify the group of devices to which the PSK is
&amp;nbsp;&amp;nbsp; provisioned&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you may spend more time reading the CAPWAP RFC if you are interested &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CAPWAP RFC: &lt;A href="http://www.ietf.org/rfc/rfc5415.txt"&gt;http://www.ietf.org/rfc/rfc5415.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this answers your concern.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2012 12:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891785#M60355</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-04-04T12:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: AP Authentication via ACS.</title>
      <link>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891786#M60356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'd be wrong but I assume that the author of this thread likes to enable 802.1X authentication for the AP MAC on the LAN port of the remote switch.&lt;/P&gt;&lt;P&gt;So in case someone disconnect the AP he is not able to connect to the network with onther device on this port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The message is send from the AAA client (=the LAN switch/authenticator) to the ACS (auth server).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2012 13:17:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891786#M60356</guid>
      <dc:creator>rdvorak</dc:creator>
      <dc:date>2012-04-04T13:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: AP Authentication via ACS.</title>
      <link>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891787#M60357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think he is referring to ap authorization&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tiny.cc/83s8bw"&gt;http://tiny.cc/83s8bw&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2012 13:32:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891787#M60357</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-04-04T13:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: AP Authentication via ACS.</title>
      <link>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891788#M60358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would work the same. When you do ap authorization the packet sent ti the AAA is sent from the WLC. So the AP needs to attempt to join the WLC for it to work. So long as you have reachability from the AP subnet to the WLC management it won't matter where the AP is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2012 14:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891788#M60358</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2012-04-04T14:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: AP Authentication via ACS.</title>
      <link>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891789#M60359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amjad,&lt;/P&gt;&lt;P&gt;Thanks for your reply. &lt;/P&gt;&lt;P&gt;But I am still confused about this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the AP is new and just started booting up. The First thing it should do is - Going to the ACS and get itself verified and authenicated to join the controller. After the successful Authentication, the CAPWAP tunnel establishes. Post that, all the traffic goes to WLC for processing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, What exactly happens after the AP boots up and initiates the WLC hunting processing. Prior to this, it has to get itself validated from ACS. &lt;/P&gt;&lt;P&gt;Pls. suggest, if my understanding to this is correct. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks everyone for your time and replying to posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2012 16:19:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891789#M60359</guid>
      <dc:creator>chopra.harish1</dc:creator>
      <dc:date>2012-04-04T16:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: AP Authentication via ACS.</title>
      <link>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891790#M60360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;Can you pls. shed some more light on this. Thanks !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2012 16:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891790#M60360</guid>
      <dc:creator>chopra.harish1</dc:creator>
      <dc:date>2012-04-04T16:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: AP Authentication via ACS.</title>
      <link>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891791#M60361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What are you asking for specifically?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The AP boots finds the WLC. The WLC in turn sends a auth request to the AAA. if AAA sends accept the Ap is allowed to join. If AAA sends a reject the AP is not allowed to join. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So for a new AP you would need to know the Mac address to build the account in AAA prior to it coming online. Or I suppose you oils pull it from the logs and add it after rd in the network, but IMO is get the Mac upfront&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2012 16:35:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891791#M60361</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2012-04-04T16:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: AP Authentication via ACS.</title>
      <link>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891792#M60362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Steve. That was simple one liner answer to my question. It clears my confussion now. &lt;/P&gt;&lt;P&gt;Earlier I was thinking that AP MAC will be verfied first by ACS and then only it will be allowed to talk to WCL. I was wrong in that. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2012 03:09:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-authentication-via-acs/m-p/1891792#M60362</guid>
      <dc:creator>chopra.harish1</dc:creator>
      <dc:date>2012-04-05T03:09:04Z</dc:date>
    </item>
  </channel>
</rss>

