In this document, we will discuss scenario where user is "Trying to setup the two different authorization profiles for two different WLAN SSID users".
But currently they found that since these two SSID users are all coming from the same NAS (WLC) to the same ACS, it is very hard to let ACS tell the different between them. These two profiles need to base on the SSID, but WLC does not send the SSID with user's credential to ACS.
We have two valid users: user1, user2, they both may use SSID 1 and SSID 2 which is broadcasted in all areas. (area 1, Area 2, area 3)
In area 1, only user1 allows to login SSID 1 and SSID 2.
In area2, only user2 can login SSID1 and SSID2.
In area 3 allows them all for SSID 1 and SSID2.
Cisco Wireless LAN Controller (WLAN)
Cisco ACS (Access Control Server)
WLC running 7.x
Wireless LAN - WLC-5500
WLC can send the SSID as part of the Called station ID attribute:
This is known bug, fixed on 188.8.131.52: CSCti02734 J-MR-Radius CallStationIdType show undefined for ap-macaddr-ssid
In this example setup, WLC is registered to the LAP. Two WLANs are used. One WLAN is for the Admin department users and the other WLAN is for the Sales department users. Wireless client A1 (Admin user) and S1 (Sales user) connect to the wireless network. You need to configure the WLC and the RADIUS server in such a way that the Admin user A1 is able to access only the WLAN Admin and is restricted access to the WLAN Sales and the Sales user S1 should be able to access the WLAN Sales and should have restricted access to the WLAN Admin. All users use LEAP authentication as a Layer 2 authentication method.
Information on NAR
Cisco Secure ACS supports two types of NAR filters:
IP-based filters—IP-based NAR filters limit access based upon the IP addresses of the end-user client and the AAA client. Refer to About IP-based NAR Filters for more information on this type of NAR filter.
Non-IP-based filters—Non-IP-based NAR filters limit access based upon simple string comparison of a value sent from the AAA client. The value can be the calling line ID (CLI) number, the Dialed Number Identification Service (DNIS) number, the MAC address, or other value that originates from the client. For this type of NAR to operate, the value in the NAR description must exactly match what is sent from the client, including whatever format is used. For example, (217) 555-4534 does not match 217-555-4534. Refer to About Non-IP-based NAR Filters for more information on this type of NAR filter.
If you use RADIUS, the NAR fields listed here use these values:
AAA client—The NAS-IP-address (attribute 4) or, if NAS-IP-address does not exist, NAS-identifier (RADIUS attribute 32) is used.
Port—The NAS-port (attribute 5) or, if NAS-port does not exist, NAS-port-ID (attribute 87) is used.
CLI—The calling-station-ID (attribute 31) is used.
DNIS—The called-station-ID (attribute 30) is used.
for more information on the usage of NAR.Since the WLC sends in the DNIS attribute and the SSID name, you can create per-user SSID restrictions. In the case of the WLC, the NAR fields have these values:
It would be great if anyone explained why we get these errors on the Cisco Wireless controller. *dot1xMsgTask: May 31 00:04:14.261: %DOT1X-3-WPA_SEND_STATE_ERR: [PA]1x_kxsm.c:1718 Unable to send EAPOL-key msg - invalid WPA state (0) - client MA...
This is what Cisco book says about PAC phases:.....Phase 0: The PAC is generated or provisioned and installed on the client Phase 1: After they authenticate each other, they will negotiate a TLS tunnel....What will be installed on the client in phase...
I have checked the telnet / ssh function in the global settings. And global configuration is selected in the AP's advanced configuration page. Now I can ssh to all APs successfully , but I cannot telnet to all APs. The network between ...
So I have been given one of these after a store upgrade that I've been working on, Im quite IT literate and I can console into devices but without guidance this is where my knowledge stops, I want to use this AP for home use, when I plug it in, I get a co...