01-19-2011 08:18 AM - edited 03-10-2019 05:43 PM
hello
Using ACS 5.2 to authenticate wireless users (wireless setup is Cisco LWAPP APs and WLC). An ACS Service Policy authenticates/authorizes wireless users and sends the following RADIUS-IETF attributes back to the WLC:
Tunnel-Type: VLAN
Tunnel-Medium-Type: 802
Tunnel-Private-Group-ID: VLAN_NAME
The WLC SSID has "Allow AAA Override" enabled and places authenticated users into the VLAN specified by the ACS attributes - this works ok.
If i have a WLC SSID with "Allow AAA Override" disabled (ie i want the WLC to set the VLAN) - i configure the ACS Service Policy authorization profile to simply "Permit Access". The user is authenticated ok but isn't placed in the VLAN specified by the WCS. If i configure the authorization policy to send the 3 "Tunnel" attributes shown above, the WLC 'ignores' these attributes and successfully places users into the correct VLAN.
Question is - if i have an SSID with "Allow AAA Override" disabled, should i still configure the ACS to return the 3 "Tunnel" attributes even though the WLC will ignore them?
thanks
andy
01-24-2011 04:11 AM
Allow AAA Override gives the AAA Override precedence over the parameters set in the controller; if there are no AAA Overrides available for a given parameter, the operating system uses the parameters already in the controller. This AAA (RADIUS or other) Override can be used as a finer version of AAA Override, but only takes precedence over parameters when Allow AAA Override is enabled. When its disabled, it should always the parameters defined on the controller itself.
Rgds,
Jatin
Do rate helpful posts~
01-24-2011 05:58 AM
hello Jatin
thanks for the reply - yes, that was my understanding of how AAA override worked. the problem i was having was due to the ssid - i ended up deleting and recreating it (cisco wlc4404 running ver 7.0.98.0). after that, the aaa override worked perfectly.
cheers
andy
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide