cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
983
Views
25
Helpful
9
Replies

WLC integration with NAC 4.9(1) L3 OOB

alfonso.cornejo
Level 3
Level 3

Hello guys,

Is it possible to integrate a WLC with a NAC 4.9(1) L3 OOB???? I can't find any documentation that says that it is possible or not.

Thanks in advance for your comments.

9 Replies 9

Amjad Abdullah
VIP Alumni
VIP Alumni

Hello Alfonso:

I suggeest that you move your thread to Security forums -> AAA, Identity and NAC subforums. They'll possibly help you better.

You can move the thread from the right pane.

Regards,

Amjad

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"

Thank's Amjad

mlezerkiewicz
Level 1
Level 1

It is possible and your right the documents don't exist. Handle it like a switch in L3 and just enable nac on the wlc, you can test snmp once your settings are set from the cam

Sent from Cisco Technical Support iPad App

Hi,

How did you do it?? just the same configuration that is documented for the L2???

No, its simpler. Add the needed snmp like for l3 sw and enable nac on the controller. You do not need to specify any networks like quarintine, add the cntroller like a switch; snmp will work at that point. Make sure your dhcp is setup, i used a separate sever not the wcl and the cas as a forwarder.

Sent from Cisco Technical Support iPad App

Hi,

You said not to configure a quarantine vlan, but by the time the users get connected how is gonna be the process for authentication (quarantine) and access vlan??? I mean how is it going to perform the nac process and how to control what happens if it fails (not in compliance) or if it suceed??

It seems that the version 4.9(1) has the integration, but is not so clear:

http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/49/cam/m_woob.html#wp1139585

What versions were you running in your deployment.

You specfiy the q vlan but not as a separate network in the other tabs. Stick to the nac enable function tab in the wcl do not try to define the q network like in the l2 doc.

Sent from Cisco Technical Support iPad App

That doc is pretty good and should get you there, just remember the wcl is just another swich in a l3 model, you can use existing profiles for testing, the second half is duplicative. It is really all about the wcl.

Sent from Cisco Technical Support iPad App

Thanks for the comments Mark!