<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with WLC 2500 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/help-with-wlc-2500/m-p/2006930#M7734</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think you will find any one guide on this... This can help you get started, but its for PEAP, which is just requires minor changes on the NPS and the cleint side configuration.&amp;nbsp; IAS and NPS are very similar in the configuration also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://pcloadletter.co.uk/2011/07/11/cisco-wifi-active-directory-auth/" rel="nofollow"&gt;http://pcloadletter.co.uk/2011/07/11/cisco-wifi-active-directory-auth/&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://araihan.wordpress.com/2010/04/30/complete-guide-to-build-a-cisco-wireless-infrastructure-using-cisco-wlc-5500-cisco-1142-ap-and-microsoft-radius-server/" rel="nofollow"&gt;http://araihan.wordpress.com/2010/04/30/complete-guide-to-build-a-cisco-wireless-infrastructure-using-cisco-wlc-5500-cisco-1142-ap-and-microsoft-radius-server/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 23 Jul 2012 20:15:37 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2012-07-23T20:15:37Z</dc:date>
    <item>
      <title>Help with WLC 2500</title>
      <link>https://community.cisco.com/t5/wireless/help-with-wlc-2500/m-p/2006929#M7733</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for a decent guide on how to configure the following to all work together&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco wireless lan controller 2500 - (which is already configured and working with the LAP's), I just need to get authentication working for our coporate lan.&lt;/P&gt;&lt;P&gt; It needs to use 802.1x wireless authentication with with a windows 2008 R2 NPS server that links into active directory. We also have a CA installed on our network.&lt;/P&gt;&lt;P&gt;I need to use EAP-TLS which I believe uses both client and server side certificates and is more tricky than PEAP.&lt;/P&gt;&lt;P&gt;I also need the windows 7 client settings for EAP-TLS to work with NPS and the controller/AP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Getting everything to work together if proving rather difficult.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There must be an upto guide out there, all the ones I have read include some cisco client side software which we wont be using and normally a older IAS server not NPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the config of my WLAN, should this work for EAP-TLS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WLAN Identifier.................................. 1&lt;/P&gt;&lt;P&gt;Profile Name..................................... &lt;/P&gt;&lt;P&gt;Network Name (SSID).............................. &lt;/P&gt;&lt;P&gt;Status........................................... Enabled&lt;/P&gt;&lt;P&gt;MAC Filtering.................................... Disabled&lt;/P&gt;&lt;P&gt;Broadcast SSID................................... Enabled&lt;/P&gt;&lt;P&gt;AAA Policy Override.............................. Disabled&lt;/P&gt;&lt;P&gt;Network Admission Control&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Radius-NAC State............................... Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; SNMP-NAC State................................. Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; Quarantine VLAN................................ 0&lt;/P&gt;&lt;P&gt;Maximum number of Associated Clients............. 0&lt;/P&gt;&lt;P&gt;Number of Active Clients......................... 0&lt;/P&gt;&lt;P&gt;Exclusionlist Timeout............................ 10 seconds&lt;/P&gt;&lt;P&gt;Session Timeout.................................. 1800 seconds&lt;/P&gt;&lt;P&gt;CHD per WLAN..................................... Enabled&lt;/P&gt;&lt;P&gt;Webauth DHCP exclusion........................... Disabled&lt;/P&gt;&lt;P&gt;Interface........................................ vlan xx&lt;/P&gt;&lt;P&gt;Multicast Interface.............................. Not Configured&lt;/P&gt;&lt;P&gt;WLAN ACL......................................... unconfigured&lt;/P&gt;&lt;P&gt;DHCP Server...................................... Default&lt;/P&gt;&lt;P&gt;DHCP Address Assignment Required................. Disabled&lt;/P&gt;&lt;P&gt;Static IP client tunneling....................... Disabled&lt;/P&gt;&lt;P&gt;Quality of Service............................... Silver (best effort)&lt;/P&gt;&lt;P&gt;Scan Defer Priority.............................. 4,5,6&lt;/P&gt;&lt;P&gt;Scan Defer Time.................................. 100 milliseconds&lt;/P&gt;&lt;P&gt;WMM.............................................. Allowed&lt;/P&gt;&lt;P&gt;WMM UAPSD Compliant Client Support............... Disabled&lt;/P&gt;&lt;P&gt;Media Stream Multicast-direct.................... Disabled&lt;/P&gt;&lt;P&gt;CCX - AironetIe Support.......................... Enabled&lt;/P&gt;&lt;P&gt;CCX - Gratuitous ProbeResponse (GPR)............. Disabled&lt;/P&gt;&lt;P&gt;CCX - Diagnostics Channel Capability............. Disabled&lt;/P&gt;&lt;P&gt;Dot11-Phone Mode (7920).......................... Disabled&lt;/P&gt;&lt;P&gt;Wired Protocol................................... None&lt;/P&gt;&lt;P&gt;IPv6 Support..................................... Disabled&lt;/P&gt;&lt;P&gt;Passive Client Feature........................... Disabled&lt;/P&gt;&lt;P&gt;Peer-to-Peer Blocking Action..................... Disabled&lt;/P&gt;&lt;P&gt;Radio Policy..................................... All&lt;/P&gt;&lt;P&gt;DTIM period for 802.11a radio.................... 1&lt;/P&gt;&lt;P&gt;DTIM period for 802.11b radio.................... 1&lt;/P&gt;&lt;P&gt;Radius Servers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Authentication................................ x.x.x.x 1812&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Accounting.................................... x.x.x.x 1813&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Dynamic Interface............................. Enabled&lt;/P&gt;&lt;P&gt;Local EAP Authentication......................... Disabled&lt;/P&gt;&lt;P&gt;Security&lt;/P&gt;&lt;P&gt; 802.11 Authentication:........................ Open System&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Static WEP Keys............................... Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 802.1X........................................ Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Wi-Fi Protected Access (WPA/WPA2)............. Enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WPA (SSN IE)............................... Enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TKIP Cipher............................. Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AES Cipher.............................. Enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WPA2 (RSN IE).............................. Enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TKIP Cipher............................. Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AES Cipher.............................. Enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Auth Key Management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1x.................................. Enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PSK..................................... Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CCKM.................................... Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FT(802.11r)............................. Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FT-PSK(802.11r)......................... Disabled&lt;/P&gt;&lt;P&gt;FT Reassociation Timeout......................... 20&lt;/P&gt;&lt;P&gt;FT Over-The-Air mode............................. Enabled&lt;/P&gt;&lt;P&gt;FT Over-The-Ds mode.............................. Enabled&lt;/P&gt;&lt;P&gt;CCKM tsf Tolerance............................... 1000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; CKIP ......................................... Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Web Based Authentication...................... Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Web-Passthrough............................... Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Conditional Web Redirect...................... Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Splash-Page Web Redirect...................... Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Auto Anchor................................... Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; H-REAP Local Switching........................ Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; H-REAP Local Authentication................... Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; H-REAP Learn IP Address....................... Enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Client MFP.................................... Optional&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Tkip MIC Countermeasure Hold-down Timer....... 60&lt;/P&gt;&lt;P&gt;Call Snooping.................................... Disabled&lt;/P&gt;&lt;P&gt;Roamed Call Re-Anchor Policy..................... Disabled&lt;/P&gt;&lt;P&gt;SIP CAC Fail Send-486-Busy Policy................ Enabled&lt;/P&gt;&lt;P&gt;SIP CAC Fail Send Dis-Association Policy......... Disabled&lt;/P&gt;&lt;P&gt;Band Select...................................... Disabled&lt;/P&gt;&lt;P&gt;Load Balancing................................... Disabled&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 05:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/help-with-wlc-2500/m-p/2006929#M7733</guid>
      <dc:creator>philip.gathercole</dc:creator>
      <dc:date>2021-07-04T05:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Help with WLC 2500</title>
      <link>https://community.cisco.com/t5/wireless/help-with-wlc-2500/m-p/2006930#M7734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think you will find any one guide on this... This can help you get started, but its for PEAP, which is just requires minor changes on the NPS and the cleint side configuration.&amp;nbsp; IAS and NPS are very similar in the configuration also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://pcloadletter.co.uk/2011/07/11/cisco-wifi-active-directory-auth/" rel="nofollow"&gt;http://pcloadletter.co.uk/2011/07/11/cisco-wifi-active-directory-auth/&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://araihan.wordpress.com/2010/04/30/complete-guide-to-build-a-cisco-wireless-infrastructure-using-cisco-wlc-5500-cisco-1142-ap-and-microsoft-radius-server/" rel="nofollow"&gt;http://araihan.wordpress.com/2010/04/30/complete-guide-to-build-a-cisco-wireless-infrastructure-using-cisco-wlc-5500-cisco-1142-ap-and-microsoft-radius-server/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2012 20:15:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/help-with-wlc-2500/m-p/2006930#M7734</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-07-23T20:15:37Z</dc:date>
    </item>
  </channel>
</rss>

