cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
951
Views
5
Helpful
5
Replies
Highlighted
Beginner

Next RADIUS if fail authentication

Hello everyone,

I try to configure a kind of Fallback RADIUS, I explain :

Il want two radius server in my WLAN :

- In one RADIUS, we have serveral users (first AD)

- In the other one, we have the rest of our users (second AD)

Is it possible to switch to RADIUS n°2 if we have a fail with the server one. If I understand, the fallback option is use when the server is down (unrecheable) but if we have a fail authentication ?

Thank's

Adrien Dupont

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
VIP Mentor

NO,

You get Access-Reject from first RADIUS server & that's pretty much it. Only first sever fails WLC use backup server.

HTH

Rasika

View solution in original post

5 REPLIES 5
Highlighted
VIP Mentor

NO,

You get Access-Reject from first RADIUS server & that's pretty much it. Only first sever fails WLC use backup server.

HTH

Rasika

View solution in original post

Highlighted

Hi,

So it's not possible on Cisco WLC. I just want to compare with a another manufacturer, we have this option :

fail-over: Fail-over is always enabled. Fail-over means is that if the first auth-server is not reachable (time-out), the second server will be checked. That is the difference between fail-over and fail-through

But not this one :

allow-fail-through: When this option is configured, an authentication failure with the first server in the group causes the controller to attempt authentication with the next server in the list. The controller attempts authentication with each server in the ordered list until either an authentication is successful or the list of servers in the group is exhausted.

Thank you for your reply !!

Regards

Adrien Dupont

Highlighted

Yes, in Cisco WLC, fail over works  when primary RADIUS is not reachable/ or responding.

HTH

Rasika

Highlighted

Hi Can you please check the following and assist?

https://supportforums.cisco.com/discussion/13326296/configuring-radius-server-authenticating-specific-ssid

Highlighted
VIP Advocate

See here for some tuning parameters:

http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/118703-technote-wlc-00.html

Content for Community-Ad