<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA with Anchor WLC in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/aaa-with-anchor-wlc/m-p/2051958#M7640</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First, are you doing an EAP type, or just using the AAA server to validate the name a user places into a splash page?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the anchoring to work, the WLAN configs need to match exactly, so if you added AAA servers to the Anchor, you need to add them to the foregin as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for whom will send the AAA request, it depends on what you are doing.&amp;nbsp; If you are doing EAP, then that will come from the Foreign, as L2 security has to be completed prior to anchoring.&amp;nbsp; If it's just the webauth, then it will come from the Anchor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Oct 2012 16:20:00 GMT</pubDate>
    <dc:creator>Stephen Rodriguez</dc:creator>
    <dc:date>2012-10-24T16:20:00Z</dc:date>
    <item>
      <title>AAA with Anchor WLC</title>
      <link>https://community.cisco.com/t5/wireless/aaa-with-anchor-wlc/m-p/2051957#M7639</link>
      <description>&lt;P&gt;Hi Folks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a pair of WiSM modules in our Core switches and a pair of 5508's in our DMZ.&amp;nbsp; We can successfully tunnel clients to the Anchor controllers in the DMZ when there's no AAA specified, however, when I add AAA servers for Authentication and Accounting the mobility handshake does not complete. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I can see the association of the client in the console 'debug client &amp;lt;mac&amp;gt;' output but I'm unsure which of the controllers is attempting to send the AAA request to the specified RADIUS servers.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the AAA request sent by the Foreign controller (in our cores) or is the request tunnelled to the Anchor controller (in the DMZ)?&amp;nbsp; If the AAA request is forwarded out of the Anchor controller's Management interface why then isn't the mobility handshake completing?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to specify the AAA servers on the Foreign controller too, or just the Anchor?.. I'm lokoing to associate the clients with a specific interface on the Anchor but accept that the AAA request will originate from the management interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could it be that because I have the AAA servers specified on the Foreign, this WLC is attempting to authenticate before beginning Mobility handshake?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help/advise greatly appreaciated. &lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 05:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aaa-with-anchor-wlc/m-p/2051957#M7639</guid>
      <dc:creator>Dave Row</dc:creator>
      <dc:date>2021-07-04T05:55:03Z</dc:date>
    </item>
    <item>
      <title>AAA with Anchor WLC</title>
      <link>https://community.cisco.com/t5/wireless/aaa-with-anchor-wlc/m-p/2051958#M7640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First, are you doing an EAP type, or just using the AAA server to validate the name a user places into a splash page?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the anchoring to work, the WLAN configs need to match exactly, so if you added AAA servers to the Anchor, you need to add them to the foregin as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for whom will send the AAA request, it depends on what you are doing.&amp;nbsp; If you are doing EAP, then that will come from the Foreign, as L2 security has to be completed prior to anchoring.&amp;nbsp; If it's just the webauth, then it will come from the Anchor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;BR /&gt;Steve &lt;BR /&gt; &lt;BR /&gt;------------------------------------------------------------------------------------------------ &lt;BR /&gt;Please remember to rate useful posts, and mark questions as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 16:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aaa-with-anchor-wlc/m-p/2051958#M7640</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2012-10-24T16:20:00Z</dc:date>
    </item>
    <item>
      <title>AAA with Anchor WLC</title>
      <link>https://community.cisco.com/t5/wireless/aaa-with-anchor-wlc/m-p/2051959#M7641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick response Stephen.&amp;nbsp; I read the following info on the Wireless Guest Access FAQ that seems to contradict what you're saying.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;&lt;A name="qa8a"&gt;Q. In an Anchor - Foreign WLC scenario, which WLC sends out the RADIUS accounting?&lt;/A&gt;&lt;/H3&gt;&lt;P&gt; &lt;A name="qa8a"&gt; &lt;BR /&gt; &lt;BR /&gt; &lt;/A&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;A name="qa8a"&gt;&lt;P&gt;&lt;STRONG&gt;A.&lt;/STRONG&gt; In this scenario, authentication is always done by the anchor WLC. Therefore, RADIUS accounting is sent by the anchor WLC.&lt;/P&gt;&lt;/A&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;A name="qa8a"&gt; &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're running a WPA+WPA2 - AES with 802.1x Auth Key Mgmt.&amp;nbsp; In this config, does the Foreign still send the Auth requests?..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2012 10:12:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aaa-with-anchor-wlc/m-p/2051959#M7641</guid>
      <dc:creator>Dave Row</dc:creator>
      <dc:date>2012-10-25T10:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: AAA with Anchor WLC</title>
      <link>https://community.cisco.com/t5/wireless/aaa-with-anchor-wlc/m-p/2051960#M7642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is the accounting message not the auth traffic. Layer2 authentication needs to happen prior to the anchoring happening. So the internal should be the one sending the authentication to AAA.&lt;BR /&gt;&lt;BR /&gt;Steve&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2012 11:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aaa-with-anchor-wlc/m-p/2051960#M7642</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2012-10-25T11:00:41Z</dc:date>
    </item>
    <item>
      <title>AAA with Anchor WLC</title>
      <link>https://community.cisco.com/t5/wireless/aaa-with-anchor-wlc/m-p/2051961#M7643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why would you want to use EAP if the sole purpose is to provide Guest services? I don't you would expect all guests to turn up at your premises with EAP configured devices. If the clients are solely corporate devices, then Stephen is correct that EAP requests would be forwarded to the AAA server by the Foreign controller and not the Anchor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also not that as your Anchor is on the DMZ, you would have to allow radius protocols between the DMZ controllers and the AAA server through the FW, and that is if you have Web authentication enabled.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2012 11:37:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/aaa-with-anchor-wlc/m-p/2051961#M7643</guid>
      <dc:creator>grabonlee</dc:creator>
      <dc:date>2012-10-25T11:37:44Z</dc:date>
    </item>
  </channel>
</rss>

