In this document, we will discuss scenario where user is "Trying to setup the two different authorization profiles for two different WLAN SSID users".
But currently they found that since these two SSID users are all coming from the same NAS (WLC) to the same ACS, it is very hard to let ACS tell the different between them. These two profiles need to base on the SSID, but WLC does not send the SSID with user's credential to ACS.
We have two valid users: user1, user2, they both may use SSID 1 and SSID 2 which is broadcasted in all areas. (area 1, Area 2, area 3)
In area 1, only user1 allows to login SSID 1 and SSID 2.
In area2, only user2 can login SSID1 and SSID2.
In area 3 allows them all for SSID 1 and SSID2.
Cisco Wireless LAN Controller (WLAN)
Cisco ACS (Access Control Server)
WLC running 7.x
Wireless LAN - WLC-5500
WLC can send the SSID as part of the Called station ID attribute:
This is known bug, fixed on 188.8.131.52: CSCti02734 J-MR-Radius CallStationIdType show undefined for ap-macaddr-ssid
In this example setup, WLC is registered to the LAP. Two WLANs are used. One WLAN is for the Admin department users and the other WLAN is for the Sales department users. Wireless client A1 (Admin user) and S1 (Sales user) connect to the wireless network. You need to configure the WLC and the RADIUS server in such a way that the Admin user A1 is able to access only the WLAN Admin and is restricted access to the WLAN Sales and the Sales user S1 should be able to access the WLAN Sales and should have restricted access to the WLAN Admin. All users use LEAP authentication as a Layer 2 authentication method.
Information on NAR
Cisco Secure ACS supports two types of NAR filters:
IP-based filters—IP-based NAR filters limit access based upon the IP addresses of the end-user client and the AAA client. Refer to About IP-based NAR Filters for more information on this type of NAR filter.
Non-IP-based filters—Non-IP-based NAR filters limit access based upon simple string comparison of a value sent from the AAA client. The value can be the calling line ID (CLI) number, the Dialed Number Identification Service (DNIS) number, the MAC address, or other value that originates from the client. For this type of NAR to operate, the value in the NAR description must exactly match what is sent from the client, including whatever format is used. For example, (217) 555-4534 does not match 217-555-4534. Refer to About Non-IP-based NAR Filters for more information on this type of NAR filter.
If you use RADIUS, the NAR fields listed here use these values:
AAA client—The NAS-IP-address (attribute 4) or, if NAS-IP-address does not exist, NAS-identifier (RADIUS attribute 32) is used.
Port—The NAS-port (attribute 5) or, if NAS-port does not exist, NAS-port-ID (attribute 87) is used.
CLI—The calling-station-ID (attribute 31) is used.
DNIS—The called-station-ID (attribute 30) is used.
for more information on the usage of NAR.Since the WLC sends in the DNIS attribute and the SSID name, you can create per-user SSID restrictions. In the case of the WLC, the NAR fields have these values:
Hiwe have three offices all running with their own 5508's. I plan on replacing those WLC's with newer ones. Is there a design were I can replace they with a pair in our CoLo data center and have all the AP's talk back to them? I used to do this with HREAP...
Hi,We have 5520 wlc and we are using RTU license.Currently we are using 100 license and trying to add some more licenses , while trying add more license getting an error like "licenses cannot added/removed on secondary HA /SKU cont...
Hello,I have a AIR-AP1852I-E-K9 set up as a Primary Controller and I'm having trouble connecting the other AP which is an AIr-AP1832I-E-K9 to the network. I can't see the other AP in Rogue APs or anywhere else.Both of them have Mobility Express insta...
Hello i have acces point 1130AG and i want to configure " Security: Global SSID Manager" but i can't save cpnfigure from interface web ap .. so i can allow AP accept paramter " Security: Global SSID Manager" that i can se...