<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP client auth in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193027#M68625</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These will be contractors that are BYOD but do have AD login credentials.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Mar 2013 17:49:49 GMT</pubDate>
    <dc:creator>Joe Clark</dc:creator>
    <dc:date>2013-03-19T17:49:49Z</dc:date>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193025#M68623</link>
      <description>&lt;P&gt;I've searched the internet but the examples I've found use certificates or web auth.&amp;nbsp; I'm trying to get users to authenticate using their LDAP credentials on a new SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the LDAP server set up on the controller but I'm still having troubles getting authentication to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to bypass using ACS and have the controller talk directly to the LDAP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;In our environment we have the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Two WiSM controllers in separate data centers&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;4402 guest controller (in production now)&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;5508 guest controller (being installed now)&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;All controllers running 7.0.235.3&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;ACS 4.2&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;NCS 1.1.1.24&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:45:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193025#M68623</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2021-07-04T06:45:39Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193026#M68624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you are looking at the guides for Local EAP?&amp;nbsp; or is this for guest users?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 17:48:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193026#M68624</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2013-03-19T17:48:46Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193027#M68625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These will be contractors that are BYOD but do have AD login credentials.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 17:49:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193027#M68625</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2013-03-19T17:49:49Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193028#M68626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you have the WLC configured for Local EAP/PEAP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 17:58:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193028#M68626</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2013-03-19T17:58:02Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193029#M68627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the LEAP profile set up and chosen on the WLAN tab.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 18:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193029#M68627</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2013-03-19T18:57:34Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193030#M68628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would set it for PEAP vs LEAP.&amp;nbsp; Not all supplicants support LEAP and it's vulnerable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 19:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193030#M68628</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2013-03-19T19:02:52Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193031#M68629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have a link or anything about setting that up?&amp;nbsp; Does it require certs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 19:09:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193031#M68629</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2013-03-19T19:09:46Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193032#M68630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you should just need to check the PEAP box and not the LEAP box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as for certs, just on the WLC and it will be there already.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 19:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193032#M68630</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2013-03-19T19:16:42Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193033#M68631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So then I have to choose "&lt;LABEL for="local_cert"&gt;Local Certificate Required" or "&lt;LABEL for="client_cert"&gt;Client Certificate Required"?&lt;/LABEL&gt;&lt;/LABEL&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 19:18:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193033#M68631</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2013-03-19T19:18:28Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193034#M68632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;not required...those are for TLS.&amp;nbsp; so you shoudl be able to uncheck those boxes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 19:26:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193034#M68632</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2013-03-19T19:26:51Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193035#M68633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They were unchecked...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what I have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;L2 security&lt;/P&gt;&lt;P&gt;WPA+WPA2 selected.&lt;/P&gt;&lt;P&gt;Checkbox for WPA2 policy WPA2 encryption AES&lt;/P&gt;&lt;P&gt;Auth Key MGmT 802.1x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA Sever tab&lt;/P&gt;&lt;P&gt;LDAP server selected&lt;/P&gt;&lt;P&gt;Local EAP Authentication checked&lt;/P&gt;&lt;P&gt;EAP Profile Name - Test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Local EAP Profile - Test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PEAP checked, nothing else&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication Priority - LDAP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything else I'm missing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 19:31:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193035#M68633</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2013-03-19T19:31:36Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193036#M68634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that should do. on the client make sure you uncheck the box to 'validate server certificate' as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 19:35:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193036#M68634</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2013-03-19T19:35:23Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193037#M68635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I got it... had to set up the network profile in Windows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm a total n00b at this so thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 19:40:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193037#M68635</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2013-03-19T19:40:58Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193038#M68636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no worries, that's why we are here!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 19:42:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193038#M68636</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2013-03-19T19:42:21Z</dc:date>
    </item>
    <item>
      <title>LDAP client auth</title>
      <link>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193039#M68637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, so now the problem I ran into is that when I change priority order -&amp;gt; local auth to LDAP, it breaks our 7925 wifi phones.&amp;nbsp; Even if I have LDAP and Local in the box, if I change the order to LDAP/Local it breaks the phones but LDAP works.&amp;nbsp; If I change it to Local/LDAP the phones work again but LDAP doesn't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The phones are using EAP-Fast.&amp;nbsp; Any ideas?&amp;nbsp; Do I need to change the auth method of the phones?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 15:34:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ldap-client-auth/m-p/2193039#M68637</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2013-03-22T15:34:25Z</dc:date>
    </item>
  </channel>
</rss>

