cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1704
Views
15
Helpful
8
Replies

Integrating Management Login for WLC's Through ISE Radius with AD

Dan Man
Level 1
Level 1

Does anyone have any good documentation on how to integrate management login, for all WLC's through the ISE appliance, using RADIUS?   I'm currently doing that through ACS, but can't find any documentation on how to do that through the ISE.  Any help would be appreciated.  Thanks!

8 Replies 8

__Beth__
Level 1
Level 1

I was having this problem as well.  The trick for me was creating an authentication rule to check AD.  I am not sure it's the best method so if anyone has any other ideas, I would appreciate hearing them.  Check my attachment for the auth rule that worked for me.

There is no documentation regarding this use case. Below is an snapshot of a policy set I've created for managing network devices via CLI. If you have ISE 1.2 is always better to create different policy sets to separate your device management policy from your network device policy

.

Thank you for your post.  I am only seeing a black box with an X in it.  Can you please try to post the snapshot again?

Thank you! :)

Jatin Katyal
Cisco Employee
Cisco Employee

On Cisco ISE:


1. Create an authorization profile that pushes the correct cisco-avpair

Policy > Policy Elements > Results > Authorization > Authorization Profiles

Under Advanced attribute settings, Radius:Service-Type = Administrative

2. Assign the authorization profile to an authorization policy 

 

Regards,

Jatin Katyal

** Do rate helpful posts **

~Jatin

Trent Hurt
Level 1
Level 1

Here is great guide I used with screenshots

 

http://mrncciew.com/2014/05/11/wlc-access-via-radius-ise/