03-21-2014 09:41 AM - edited 03-10-2019 09:33 PM
Hello,
I’m trying to setup following environment:
I’ve done the following configuration:
For the MAC Filter Setup I’m going to use an ACS 5.4 and an Active Directory. The ACS has successfully joined the Active Directory and at the active Directory I’ve create to groups:
CN=SSID1,OU=Authentication,DC=global,DC=lan
CN=SSID2,OU=Authentication,DC=global,DC=lan
These two groups I’ve selected after I joined the Active Directoy. I used the Active Directory (AD1) as an Identity group, which is used by a Network Access based Access Service. In my second step, I configured the WLC to use Radius authentication for MAC-Filter and everything works.
But now I’ve found my problem:
The ACS Server like work top down and first rule matches:
If a MAC is member of group SSID1 and the Client wants to join SSID 1 it works
If a MAC is member of group SSID2 and the Client wants to join SSID 1 it works, too. Because the rules are checkt top down first match. And the ACS will find the MAC in group SSID.
I would like to restrict the MACs from group SSID1 to SSID 1 and the MACs from group SSID to SSID 2.
Thanks and kind regards
Kai
05-05-2014 11:37 AM
Problem is solved, the caller-station-id can be used, it transfers the SSID and "contains" can be used.
12-02-2014 11:11 AM
Hello, I am looking for this config as well. Is it possible to post screenshots of ACS showing how you created your Access Policies, and how you restricted authentication by SSID (Using end-station filters for calling-station-id, DNIS??)
Thanks.
12-02-2014 11:29 PM
Hello,
I hope this will help you. The username and password will be the MAC-Address of your client wirelss device, e.g.
Username: aabbccddeeff
Password: aabbccddeeff
You've to check, in which kind you have to send the MAC Address (aa:bb:cc:dd:ee:ff, aabbcc-ddeeff, AA:BB:CC:DD:EE:FF, and so on)
The attachments will show you a sample ACS Access Policy and the "caller-station-id" configuration and the configuration of a SSID from a Cico WLC 5508.
05-27-2015 03:06 AM
Hi Onken,
Is your problem solved only basis on ACS configuration SSID "contains" , in which corporate user connect only corporate ssid and staff users connects only staff ssid?
Regards,
Kamlesh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide