cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3385
Views
0
Helpful
1
Replies

ISE 2.2 Foreign and Anchor WLC Radius Auth and Accounting Configuration

choiwon
Cisco Employee
Cisco Employee

Hi All,

Just want to get some clarification around the requirements to add ISE under the Foreign and Anchor WLCs.

In short, below is the lab testing and research showing only t Foreign WLC is required to have ISE PSN nodes added and Anchor WLC does NOT communicate with ISE even when it has been added with the exception of Accounting Interim update 

Lab Testing:

  • LAB Test -Guest WLAN#1 with CoA and Contractor WLAN#2 with PEAP setup between Foreign and Anchor WLC 8.2.x and ISE 2.0
  • LAB Test  Result- Only Foreign WLC communicates to ISE

Research

State: Radius is done only by foreign wlc. The ACL should be configured on both WLC.

WLC Foreign-Anchor Configuration (1).jpg

  • [ISE Community]ISE Guest Access Prescriptive Deployment Guide
    • State: Page 10 - Accounting needs to be configured on the foreign controller (e.g remove Accounting on the Anchor)
  • [WLC Defect]CSCuz45986    CWA not working on Cisco 8500 Series WLC as Guest anchor with Accounting enabled 
    • State: Accounting on the Anchor WLC should be removed

In summary -

  1. Radius Accounting and Authentication on the Anchor WLC is not required
  2. Is there any reason why we should be adding ISE PSN on the Anchor WLC for Accounting or Authentication reason?
  3. Any other points will be great!

Cheers,

Won

1 Reply 1

howon
Cisco Employee
Cisco Employee

You summed them up nicely. To confirm, no RADIUS configuration is needed on auto-anchor for the specific WLAN. In fact having RADIUS accounting enabled for ISE on anchor will break the CWA. Also, even though redirect ACL needs to exists on both controller, the anchor controller is the one using it. The foreign just need to have the ACL name exist (Does not need ACL entries).

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: