<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to use multiple SSID with ACS and  AD authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/how-to-use-multiple-ssid-with-acs-and-ad-authentication/m-p/1681804#M69334</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please clarify what you want to achieve.&lt;/P&gt;&lt;P&gt;I understand that you currently have:&lt;/P&gt;&lt;P&gt;- "employee" SSID, with (EAP?) authentication using AD as the Identity store; can you confirm that you do EAP/RADIUS auth for this SSID? What RADIUS server do you use here?&lt;/P&gt;&lt;P&gt;- "guest" SSID, with Web-Auth using Cisco NAC Guest server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to add a "showroom/test" SSID, using the same AD DB as for the employee SSID.&lt;/P&gt;&lt;P&gt;What is the security config you would use in this case?&lt;/P&gt;&lt;P&gt;802.1x/EAP, or Web-Auth?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For 802.1x/EAP, it's not a problem to point this new SSID to the same RADIUS server.&lt;/P&gt;&lt;P&gt;For Web-Auth, you can consider using either RADIUS again (PAP auth, not EAP) or configuring the WLC to poll the AD using LDAP:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a0080a03e09.shtml"&gt;http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a0080a03e09.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Federico&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If this answers your question please mark the question as "answered" and rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 11 Jun 2011 11:48:12 GMT</pubDate>
    <dc:creator>Federico Lovison</dc:creator>
    <dc:date>2011-06-11T11:48:12Z</dc:date>
    <item>
      <title>How to use multiple SSID with ACS and  AD authentication</title>
      <link>https://community.cisco.com/t5/wireless/how-to-use-multiple-ssid-with-acs-and-ad-authentication/m-p/1681803#M69333</link>
      <description>&lt;P&gt;I'm looking to deploy a showroom/test SSID using the WLCs, light weight APs and ACS, I'd like to use AD authentication as we currently do for our standard employee SSID. We also have Guest NAC for the guest SSID but I don't think this is an option as I don't want guests to use the &lt;/P&gt;&lt;P&gt;showroom/test SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 03:17:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-use-multiple-ssid-with-acs-and-ad-authentication/m-p/1681803#M69333</guid>
      <dc:creator>patrickdonlon</dc:creator>
      <dc:date>2021-07-04T03:17:28Z</dc:date>
    </item>
    <item>
      <title>How to use multiple SSID with ACS and  AD authentication</title>
      <link>https://community.cisco.com/t5/wireless/how-to-use-multiple-ssid-with-acs-and-ad-authentication/m-p/1681804#M69334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please clarify what you want to achieve.&lt;/P&gt;&lt;P&gt;I understand that you currently have:&lt;/P&gt;&lt;P&gt;- "employee" SSID, with (EAP?) authentication using AD as the Identity store; can you confirm that you do EAP/RADIUS auth for this SSID? What RADIUS server do you use here?&lt;/P&gt;&lt;P&gt;- "guest" SSID, with Web-Auth using Cisco NAC Guest server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to add a "showroom/test" SSID, using the same AD DB as for the employee SSID.&lt;/P&gt;&lt;P&gt;What is the security config you would use in this case?&lt;/P&gt;&lt;P&gt;802.1x/EAP, or Web-Auth?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For 802.1x/EAP, it's not a problem to point this new SSID to the same RADIUS server.&lt;/P&gt;&lt;P&gt;For Web-Auth, you can consider using either RADIUS again (PAP auth, not EAP) or configuring the WLC to poll the AD using LDAP:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a0080a03e09.shtml"&gt;http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a0080a03e09.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Federico&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If this answers your question please mark the question as "answered" and rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Jun 2011 11:48:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/how-to-use-multiple-ssid-with-acs-and-ad-authentication/m-p/1681804#M69334</guid>
      <dc:creator>Federico Lovison</dc:creator>
      <dc:date>2011-06-11T11:48:12Z</dc:date>
    </item>
  </channel>
</rss>

