cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2090
Views
15
Helpful
4
Replies

limit admin access to specific AP group

phuoc.nt
Level 1
Level 1

Dear everyone,

My system has WLC, ISE, PI. My operator IT want to manage themselves all the APs that are installed inside their building. 

On the WLC, we have AP group based on location but I don't know how to limit admin access to a specific AP group.

Could you please share your experience on this issue?

Thank you so much!

1 Accepted Solution

Accepted Solutions

phuoc.nt
Level 1
Level 1

Thank you everyone for the clear explanation.

 

View solution in original post

4 Replies 4

Hi,

The list of roles in WLC doesn't allow to limit access to single group of
APs. You cannot create custom roles like in other products such as CUCM for
example.

**** please remember to rate useful posts

Panos Bouras
Level 1
Level 1

HI @phuoc.nt


As @Mohammed al Baqari mentioned ISE controls access to WLC in the form of the vertical menus at WLC, so there's no way to limit access to specific AP group or any other sub-menu.

Check this guide also (Device Administration of Cisco WLC using TACACS+)

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-24/215125-device-administration-of-cisco-wlc-using.html

Thank you,Panos.
Please Rate Posts (by clicking on Star) and/or Mark Solutions as Accepted, when applies

thomas
Cisco Employee
Cisco Employee

I assume you are talking about Device Administration with TACACS and not RADIUS for network access.

See https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-24/215125-device-administration-of-cisco-wlc-using.html where it shows you can only control access to the individual tabs in the WLC. The WLC does not have options for finer control than the tabs in the web GUI.

image.png

phuoc.nt
Level 1
Level 1

Thank you everyone for the clear explanation.