<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WDS &amp; PEAP in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wds-peap/m-p/700427#M75883</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problem fixed. All SSID configured in the Infrastructure APs must be specified under the "wlccp authentication-server client" config in the WDS. Otherwise, the WDS will not contact ACS; instead it will pick the "Permanant Local" list and hence the authentication will fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Jan 2007 03:31:54 GMT</pubDate>
    <dc:creator>andrew_ho</dc:creator>
    <dc:date>2007-01-30T03:31:54Z</dc:date>
    <item>
      <title>WDS &amp; PEAP</title>
      <link>https://community.cisco.com/t5/wireless/wds-peap/m-p/700424#M75880</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using Cisco ACS and Cisco AP AIR-AP1231G-A-K9. They are configured so that client can be authenticated using PEAP. However, as soon as join the AP to WDS. It stops working and no clients can now be authenticated by PEAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;000066: *Mar  1 00:52:26.875 UTC: %WLCCP_AP-6-INFRA: WLCCP Infrastructure Authenticated&lt;/P&gt;&lt;P&gt;000067: *Mar  1 00:52:34.468 UTC: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station 0013.ce55.7876 Reason: Previous authentication no longer valid &lt;/P&gt;&lt;P&gt;000068: *Mar  1 00:52:35.077 UTC: %DOT11-7-AUTH_FAILED: Station 0013.ce55.7876 Authentication failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions? Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 20:32:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wds-peap/m-p/700424#M75880</guid>
      <dc:creator>andrew_ho</dc:creator>
      <dc:date>2021-07-03T20:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: WDS &amp; PEAP</title>
      <link>https://community.cisco.com/t5/wireless/wds-peap/m-p/700425#M75881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This certainly looks like a problem between the WDS and the ACS Server. Have a look at the following;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wireless Domain Services Configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to use WDS, you must designate one AP or the WLSM as the WDS. A WDS AP must use a WDS user name and password to establish a relationship with an authentication server. The authentication server can be either an external RADIUS server or the Local RADIUS Server feature in the WDS AP. The WLSM must have a relationship with the authentication server, even though WLSM does not need to authenticate to the server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other APs, called infrastructure APs, communicate with the WDS. Before registration occurs, the infrastructure APs must authenticate themselves to the WDS. An infrastructure server group on the WDS defines this infrastructure authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One or more client server groups on the WDS define client authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a client attempts to associate to an infrastructure AP, the infrastructure AP passes the credentials of the user to the WDS for validation. If the WDS sees the credentials for the first time, WDS turns to the authentication server to validate the credentials. The WDS then caches the credentials, in order to eliminate the need to return to the authentication server when the same user attempts authentication again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From this doc;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_configuration_example09186a00801c951f.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_configuration_example09186a00801c951f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2007 13:46:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wds-peap/m-p/700425#M75881</guid>
      <dc:creator>Rob Huffman</dc:creator>
      <dc:date>2007-01-29T13:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: WDS &amp; PEAP</title>
      <link>https://community.cisco.com/t5/wireless/wds-peap/m-p/700426#M75882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually in my production environment, I have WDS with ACS for LEAP authentication working for a long time. When I recently want to migrate LEAP users to use PEAP, I couldn't get it to work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS is configured with PEAP support. As soon as change the client to PEAP, the authentication fails but I can't see any "Failed Attempt" in ACS. But if I remove the WDS config from the AP, PEAP works and I can see the "Passed Attempt" in ACS. The AP IOS is also the latest. I wonder if PEAP can actually work with WDS? Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jan 2007 00:03:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wds-peap/m-p/700426#M75882</guid>
      <dc:creator>andrew_ho</dc:creator>
      <dc:date>2007-01-30T00:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: WDS &amp; PEAP</title>
      <link>https://community.cisco.com/t5/wireless/wds-peap/m-p/700427#M75883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problem fixed. All SSID configured in the Infrastructure APs must be specified under the "wlccp authentication-server client" config in the WDS. Otherwise, the WDS will not contact ACS; instead it will pick the "Permanant Local" list and hence the authentication will fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jan 2007 03:31:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wds-peap/m-p/700427#M75883</guid>
      <dc:creator>andrew_ho</dc:creator>
      <dc:date>2007-01-30T03:31:54Z</dc:date>
    </item>
  </channel>
</rss>

