<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BYOD Wireless authentication help in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188530#M69103</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Joe: you have configured the clients to use only user authentication?&lt;/P&gt;&lt;P&gt;What is the failure reason you see under the failed attemtps logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you can do is configure a group to which users fail machine auth will fail to.&lt;/P&gt;&lt;P&gt;Or&lt;/P&gt;&lt;P&gt;you can excempt specific groups from passing machine auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is configurable under &lt;/P&gt;&lt;P&gt;External User Databases -&amp;gt; Database configuration -&amp;gt; Windows Database -&amp;gt; press configure button -&amp;gt; Windows Auth configuration.&lt;/P&gt;&lt;P&gt;Go to (Windows EAP Settings) area.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Mar 2013 13:28:05 GMT</pubDate>
    <dc:creator>Amjad Abdullah</dc:creator>
    <dc:date>2013-03-19T13:28:05Z</dc:date>
    <item>
      <title>BYOD Wireless authentication help</title>
      <link>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188529#M69102</link>
      <description>&lt;P&gt;Our company is going to have some contractors on site for a long term project.&amp;nbsp; They are bringing their own laptops and will not be on our domain.&amp;nbsp; We want to set up a separate SSID for this group of people.&amp;nbsp; Our IT Security department wants us to have certificate authentication.&amp;nbsp; We currently do this with our Corporate users using EAP-TLS with user and machine certs via ACS and Active Directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The contractors will only have user accounts/certs, no machine certs.&amp;nbsp; I tried testing a new group in ACS but wasn't able to get that working.&amp;nbsp; We have also tried LDAP auth without interaction with ACS unsuccesfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been testing these on a test SSID on our corporate WiSM but in the end, this network will live on a 5508 guest controller.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our environment we have the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two WiSM controllers in separate data centers&lt;/P&gt;&lt;P&gt;4402 guest controller (in production now)&lt;/P&gt;&lt;P&gt;5508 guest controller (being installed now)&lt;/P&gt;&lt;P&gt;All controllers running 7.0.235.3&lt;/P&gt;&lt;P&gt;ACS 4.2&lt;/P&gt;&lt;P&gt;NCS 1.1.1.24&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188529#M69102</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2021-07-04T06:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Wireless authentication help</title>
      <link>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188530#M69103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Joe: you have configured the clients to use only user authentication?&lt;/P&gt;&lt;P&gt;What is the failure reason you see under the failed attemtps logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you can do is configure a group to which users fail machine auth will fail to.&lt;/P&gt;&lt;P&gt;Or&lt;/P&gt;&lt;P&gt;you can excempt specific groups from passing machine auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is configurable under &lt;/P&gt;&lt;P&gt;External User Databases -&amp;gt; Database configuration -&amp;gt; Windows Database -&amp;gt; press configure button -&amp;gt; Windows Auth configuration.&lt;/P&gt;&lt;P&gt;Go to (Windows EAP Settings) area.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 13:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188530#M69103</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-03-19T13:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Wireless authentication help</title>
      <link>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188531#M69104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, if we are to use ACS for this do you know how I can get the users dynamically mapped to a new group?&amp;nbsp; Corporate users are put into the default group right now.&amp;nbsp; Is there an attribute in Active Directory or something we need to specify to put these contractors into their own dynamic group?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 13:42:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188531#M69104</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2013-03-19T13:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Wireless authentication help</title>
      <link>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188532#M69105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Joe:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;If only those contractors use user auth only (and all others use machine and user auth) then you can map those who do only a user auth (not machine auth) to specific AD group.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those users are on the AD?? You mentnioned that they are not before? or they are? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 13:49:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188532#M69105</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-03-19T13:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Wireless authentication help</title>
      <link>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188533#M69106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The users are in AD but not the machines.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 13:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188533#M69106</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2013-03-19T13:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Wireless authentication help</title>
      <link>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188534#M69107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is even easier. If they are in same AD gropu you can map the AD group to a specific local ACS group.&lt;/P&gt;&lt;P&gt;External User DB -&amp;gt; DB group mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 13:52:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188534#M69107</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-03-19T13:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Wireless authentication help</title>
      <link>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188535#M69108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's what I tried before but with no luck.&amp;nbsp; Right now, the mapping that appears to work for our corporate users is "All other combinations" under NT Groups.&amp;nbsp; Can you tell me how I would get these contractors to match up to another mapping?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not have access to Active Directory, that is another group here.&amp;nbsp; So if something needs to be added/changed for these users I will have to let them know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 13:56:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/byod-wireless-authentication-help/m-p/2188535#M69108</guid>
      <dc:creator>Joe Clark</dc:creator>
      <dc:date>2013-03-19T13:56:33Z</dc:date>
    </item>
  </channel>
</rss>

