Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
We are about to start to migration from 5520 AireOS to 9800-40 IOS-XETo test, I attempted to move couple of 2702I APs by blocking AP communication to old WLCs, because AP's just won't forget old controllers.With current clock time APs won't register ...
We got new 9800s and I am trying to configure radius for GUI. I followed this link to set it up but the authentication method in ISE shows as PAP. What steps or guide should I follow to change it to PEAP.https://www.cisco.com/c/en/us/support/docs/wir...
Management bought some Audio Visual devices that support bonjour/mdns and we are expected to make airplay work.In the below setup AP and A/V device may end up connecting to same switches but because of signal overlap, client can remain associated to...
As per this previous post, I can fix this error by matching authorization policy per ISE server . What dictionary attribute do i need to use to make this happen. And yes it works if I use the primary node only in domain but for failover we need both....
I am trying to setup single SSID BYOD with ISE as intermediate CA issuing certificates. With my configuration client is getting redirected appropriately for device registration and then is prompted for installing profile with network setup assistant....
@Rasika Nayanajith I upgraded WLC's to 17.9.3 and I am able to join APs to 9800 now, without having to change NTP. Thanks for pointing to that. Would there be any reason to still upgrade old WLCs to 8.10.183?
@Gaurav Kansal I can allow PAP on ISE but I don't want to use PAP as its not secure. I know my radius secret is still requiered for getting password out of it but I want to go secure from the start. I want to use PEAP and want requests that are comi...
@Greg Gibbs and @Mark Elsen Thanks for your suggestions. We don't have Default-First-Site and all DC's show under there relative site names. I however looked into SRV records and all our DC's for this site were set to default priority and weight. I l...
@MHM Cisco World For global area was changed to nssa a while ago. I was doing it now for vrf and i just spotted my mistake. I was doing 'no area 16' instead of 'no area 16 stub'. Thanks