Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi AllI'm struggeling with a AP issue. I have attach my anonymized config. In short the issue is that I have a Arionet AP with VLANs setup into multiple SSIDs. The main net is VLAN 1 where the radius server receives authentication requests. I have te...
I did disable TKIP, since this protocol has a bad security level compared to AES-CCMP. My clients still connected just fine. On the radius and client EAP setup I used EAP-TTLS with MS-Chapv2 which to me seems to be the only common supported by both A...
Yesterday evening I finally got it working with VLANs. As always it isn't difficult as long as you know what is possible and not. I ended up with VLAN5 as native VLAN on the AP. This is possibly not optimal, but works. I configured VLAN5 as I would i...
Is it a bug in the firmware that makes AES+TKIP a bad match or is it a bad decision of Cisco to put that choice into the menues of their APs? Could you give some more background on why the AES+TKIP is a bad couple?
Thanks for your answer Scott Fella! I did start over again yesterday evening and I got it to work with radius as long as I did not mix in VLANs. Native VLAN is automatically said to have VLAN #1(untagged), but if I configure(tagged) native VLAN 1 (on...
Thanks for your answer Rasika! I got it to work yesterday evening with encryption AES-CCMP+TKIP. I guess it would have worked without TKIP also, but as I understand it TKIP is not added security, but rather less security and more options for the radi...