In this document, we will discuss scenario where user is "Trying to setup the two different authorization profiles for two different WLAN SSID users".
But currently they found that since these two SSID users are all coming from the same NAS (WLC) to the same ACS, it is very hard to let ACS tell the different between them. These two profiles need to base on the SSID, but WLC does not send the SSID with user's credential to ACS.
We have two valid users: user1, user2, they both may use SSID 1 and SSID 2 which is broadcasted in all areas. (area 1, Area 2, area 3)
In area 1, only user1 allows to login SSID 1 and SSID 2.
In area2, only user2 can login SSID1 and SSID2.
In area 3 allows them all for SSID 1 and SSID2.
Cisco Wireless LAN Controller (WLAN)
Cisco ACS (Access Control Server)
WLC running 7.x
Wireless LAN - WLC-5500
WLC can send the SSID as part of the Called station ID attribute:
This is known bug, fixed on 126.96.36.199: CSCti02734 J-MR-Radius CallStationIdType show undefined for ap-macaddr-ssid
In this example setup, WLC is registered to the LAP. Two WLANs are used. One WLAN is for the Admin department users and the other WLAN is for the Sales department users. Wireless client A1 (Admin user) and S1 (Sales user) connect to the wireless network. You need to configure the WLC and the RADIUS server in such a way that the Admin user A1 is able to access only the WLAN Admin and is restricted access to the WLAN Sales and the Sales user S1 should be able to access the WLAN Sales and should have restricted access to the WLAN Admin. All users use LEAP authentication as a Layer 2 authentication method.
Information on NAR
Cisco Secure ACS supports two types of NAR filters:
IP-based filters—IP-based NAR filters limit access based upon the IP addresses of the end-user client and the AAA client. Refer to About IP-based NAR Filters for more information on this type of NAR filter.
Non-IP-based filters—Non-IP-based NAR filters limit access based upon simple string comparison of a value sent from the AAA client. The value can be the calling line ID (CLI) number, the Dialed Number Identification Service (DNIS) number, the MAC address, or other value that originates from the client. For this type of NAR to operate, the value in the NAR description must exactly match what is sent from the client, including whatever format is used. For example, (217) 555-4534 does not match 217-555-4534. Refer to About Non-IP-based NAR Filters for more information on this type of NAR filter.
If you use RADIUS, the NAR fields listed here use these values:
AAA client—The NAS-IP-address (attribute 4) or, if NAS-IP-address does not exist, NAS-identifier (RADIUS attribute 32) is used.
Port—The NAS-port (attribute 5) or, if NAS-port does not exist, NAS-port-ID (attribute 87) is used.
CLI—The calling-station-ID (attribute 31) is used.
DNIS—The called-station-ID (attribute 30) is used.
for more information on the usage of NAR.Since the WLC sends in the DNIS attribute and the SSID name, you can create per-user SSID restrictions. In the case of the WLC, the NAR fields have these values:
Hi Everyone,From last few day I have seen this issue all the user are getting IP address on this Guest Network and after that redirected to Guest portal which is hosted on ISE.But two Android Phone, Iphone and IPad are not getting ip address on the Guest ...
Wanting to see if anyone knows if we can still get perpetual licensing for new 1815w Access Points attaching to a 3504 WLC. Getting feedback from my Cisco Reseller that it's only available with DNA subscriptions now. If we have perpetual licens...
I just found out that you can do profiling and policy classification on Cisco WLC to assign session timeouts, ACLs, and VLANs regardless of what those settings are set to on the WLAN. For it to work though, it looks like you need an external RADIUS s...
Just wondering what the best practice is on using DHCP proxy mode vs DHCP bridging mode for roaming clients (L2 / L3 roam)? Does the DHCP proxy feature add significant time to the DHCP handshake and cause roaming clients to lose packets when they go ...
Hi all, I am having issues setting up a few Aironet 1262s (AIR-LAP1262N-E-K9) They are powered from a 3560 PoE-8 (only one at a time) and they power up...The power comes on and the light flashes green for bit (I assume booting)The light then is ...