04-16-2013 08:20 AM - edited 03-10-2019 08:19 PM
Hello guys,
Is it possible to integrate a WLC with a NAC 4.9(1) L3 OOB???? I can't find any documentation that says that it is possible or not.
Thanks in advance for your comments.
04-19-2013 10:54 PM
Hello Alfonso:
I suggeest that you move your thread to Security forums -> AAA, Identity and NAC subforums. They'll possibly help you better.
You can move the thread from the right pane.
Regards,
Amjad
Rating useful replies is more useful than saying "Thank you"
04-20-2013 09:15 AM
Thank's Amjad
04-20-2013 04:00 PM
It is possible and your right the documents don't exist. Handle it like a switch in L3 and just enable nac on the wlc, you can test snmp once your settings are set from the cam
Sent from Cisco Technical Support iPad App
04-20-2013 04:09 PM
Hi,
How did you do it?? just the same configuration that is documented for the L2???
04-20-2013 04:15 PM
No, its simpler. Add the needed snmp like for l3 sw and enable nac on the controller. You do not need to specify any networks like quarintine, add the cntroller like a switch; snmp will work at that point. Make sure your dhcp is setup, i used a separate sever not the wcl and the cas as a forwarder.
Sent from Cisco Technical Support iPad App
04-20-2013 04:34 PM
Hi,
You said not to configure a quarantine vlan, but by the time the users get connected how is gonna be the process for authentication (quarantine) and access vlan??? I mean how is it going to perform the nac process and how to control what happens if it fails (not in compliance) or if it suceed??
It seems that the version 4.9(1) has the integration, but is not so clear:
What versions were you running in your deployment.
04-20-2013 04:39 PM
You specfiy the q vlan but not as a separate network in the other tabs. Stick to the nac enable function tab in the wcl do not try to define the q network like in the l2 doc.
Sent from Cisco Technical Support iPad App
04-20-2013 04:49 PM
That doc is pretty good and should get you there, just remember the wcl is just another swich in a l3 model, you can use existing profiles for testing, the second half is duplicative. It is really all about the wcl.
Sent from Cisco Technical Support iPad App
04-20-2013 04:52 PM
Thanks for the comments Mark!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide