<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic local authentication, local in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862036#M67216</link>
    <description>&lt;P class="pBu1_Bullet1"&gt;local authentication, local switching—In this state, the FlexConnect access point handles client authentication and switches client data packets locally. This state is valid in standalone mode and connected mode.&lt;/P&gt;
&lt;P&gt;In connected mode, the access point provides minimal information about the locally authenticated client to the controller. The following information is not available to the controller:&lt;/P&gt;
&lt;P&gt;–&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" height="2" border="0" width="17" /&gt;Policy type&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" height="2" border="0" width="17" /&gt;Access VLAN&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" height="2" border="0" width="17" /&gt;VLAN name&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" height="2" border="0" width="17" /&gt;Supported rates&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" height="2" border="0" width="17" /&gt;Encryption cipher&lt;/P&gt;
&lt;P class="pB2_Body2"&gt;Local authentication is useful where you cannot maintain a remote office setup of a minimum bandwidth of 128 kbps with the round-trip latency no greater than 100 ms and the maximum transmission unit (MTU) no smaller than 500 bytes. In local authentication, the authentication capabilities are present in the access point itself. Local authentication reduces the latency requirements of the branch office.&lt;/P&gt;
&lt;P class="pB2_Body2"&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 May 2016 01:29:09 GMT</pubDate>
    <dc:creator>mohanak</dc:creator>
    <dc:date>2016-05-04T01:29:09Z</dc:date>
    <item>
      <title>Flexconnect local authentication (PSK) - Is it really local or not?</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862032#M67212</link>
      <description>&lt;P&gt;I am a bit unclear about the Local Authentication feature of Flexconnect.&lt;/P&gt;
&lt;P&gt;According to the documentation, if local authentication is selected on a flex-connect AP, as long as the WLC is reachable, the authentication will be forwarded to the WLC. However, if the WLC becomes unreachable, then authentication is handled locally by the AP.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;This doesn't make sense. Isn't the whole point of local authentication to ensure that traffic between the WLC and AP is reduced so it doesn't have to travel up the WAN if the WLC is located in a datacentre somewhere?&lt;/P&gt;
&lt;P&gt;Also, does anyone know how often the PSK is synched between the WLC and the APs?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 11:59:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862032#M67212</guid>
      <dc:creator>ldeoliveira</dc:creator>
      <dc:date>2021-07-05T11:59:26Z</dc:date>
    </item>
    <item>
      <title>It is a bit convoluted to</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862033#M67213</link>
      <description>&lt;P&gt;It is a bit convoluted to begin with!&lt;/P&gt;
&lt;P&gt;If you want to do only local authentication without having to auth across the WAN to your WLC then&amp;nbsp;select FlexConnect Local Auth under the WLAN ID settings.&lt;/P&gt;
&lt;P&gt;If you want to do both then it will centrally auth by default and switch to Local Auth if the WAN goes down and the AP enters standalone mode. This is only if local switching is also enabled.&lt;/P&gt;
&lt;P&gt;For synching of PSKs - as soon as you make a change to the PSK that will cause the WLC to synch with any APs requiring it so effectively it is instantaneous.&lt;/P&gt;
&lt;P&gt;Ric&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 09:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862033#M67213</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2016-05-03T09:25:19Z</dc:date>
    </item>
    <item>
      <title>Hi Ric,</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862034#M67214</link>
      <description>&lt;P&gt;Hi Ric,&lt;/P&gt;
&lt;P&gt;Thanks for stepping in and trying to clarify. To be honest, I still don't get it.&lt;/P&gt;
&lt;P&gt;The requirement is for local switching. We don't want the Wi-Fi traffic to travel up the WAN link to the controller (this is for a small branch office that doesn't have a controller, just APs).&lt;/P&gt;
&lt;P&gt;So what you're saying is that if local switching is enabled, then authentication will first go via WLC then via the local APs when these enter standby mode (ie. cannot reach any WLC)? What is the advantage of authenticating through the WLC if the AP can do that locally?&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;
&lt;P&gt;Leo&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 23:49:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862034#M67214</guid>
      <dc:creator>ldeoliveira</dc:creator>
      <dc:date>2016-05-03T23:49:23Z</dc:date>
    </item>
    <item>
      <title>In your scenario the AP will</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862035#M67215</link>
      <description>&lt;P&gt;In your scenario the AP will always handle authentication. However if you change the PSK under the WLAN Settings on the WLC this will then propagate out to those APs.&lt;/P&gt;
&lt;P&gt;So the only traffic you should&amp;nbsp;see across your WAN will be CAPWAP Control traffic.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Ric&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 00:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862035#M67215</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2016-05-04T00:50:03Z</dc:date>
    </item>
    <item>
      <title>local authentication, local</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862036#M67216</link>
      <description>&lt;P class="pBu1_Bullet1"&gt;local authentication, local switching—In this state, the FlexConnect access point handles client authentication and switches client data packets locally. This state is valid in standalone mode and connected mode.&lt;/P&gt;
&lt;P&gt;In connected mode, the access point provides minimal information about the locally authenticated client to the controller. The following information is not available to the controller:&lt;/P&gt;
&lt;P&gt;–&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" height="2" border="0" width="17" /&gt;Policy type&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" height="2" border="0" width="17" /&gt;Access VLAN&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" height="2" border="0" width="17" /&gt;VLAN name&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" height="2" border="0" width="17" /&gt;Supported rates&lt;/P&gt;
&lt;P class="pBu2_Bullet2"&gt;–&lt;IMG src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" alt="" height="2" border="0" width="17" /&gt;Encryption cipher&lt;/P&gt;
&lt;P class="pB2_Body2"&gt;Local authentication is useful where you cannot maintain a remote office setup of a minimum bandwidth of 128 kbps with the round-trip latency no greater than 100 ms and the maximum transmission unit (MTU) no smaller than 500 bytes. In local authentication, the authentication capabilities are present in the access point itself. Local authentication reduces the latency requirements of the branch office.&lt;/P&gt;
&lt;P class="pB2_Body2"&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 01:29:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862036#M67216</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2016-05-04T01:29:09Z</dc:date>
    </item>
    <item>
      <title>My Wireless Structure is same</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862037#M67218</link>
      <description>&lt;P&gt;My Wireless Structure is same SSID (For example: Internal_Staff ) for all location and office.&lt;/P&gt;
&lt;P&gt;We had 2 x 2504 HA, setup on DataCenter. And all Branch office through VPN to connect the DataCenter WLC. Branch office APs use flexconnect using same SSID with local network address. Also we using Radius Server for authentication.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My question is: Can I use the " Local Authentication " on primary rather than " Central Authen ".&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 03:19:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862037#M67218</guid>
      <dc:creator>rayho2000</dc:creator>
      <dc:date>2017-08-03T03:19:22Z</dc:date>
    </item>
    <item>
      <title>If your aps are flexconnect</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862038#M67219</link>
      <description>&lt;P&gt;If your &lt;G class="gr_ gr_8 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="8" data-gr-id="8"&gt;aps&lt;/G&gt; are &lt;G class="gr_ gr_12 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="12" data-gr-id="12"&gt;flexconnect&lt;/G&gt; and you have radius server on local side for authenticating wireless clients, then yes, you can use local authentication.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 07:47:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-local-authentication-psk-is-it-really-local-or-not/m-p/2862038#M67219</guid>
      <dc:creator>sremk</dc:creator>
      <dc:date>2017-08-03T07:47:41Z</dc:date>
    </item>
  </channel>
</rss>

