02-05-2007 05:44 AM - edited 07-03-2021 01:34 PM
We currently have a 4402 Controller with several AP's configured and working great. We have 2 SSID's mapped to 2 different VLAN's as well. 1 SSID is for Internal use and has EAP-FAST, ACS Auth, etc configure. The Guest SSID is using the local net usernames as expected, however, it is also using the ACS server as well. We would prefer to prevent internal employees from even being able to authenticate to the Guest SSID. Any ideas?
02-07-2007 03:19 PM
ACS can impose rules on groups, simply set your Staff groups allowed NDIS value to "*ESSID" (for example) and that should do the trick. It's important to put the * infront of your ESSID name.
HTH,
Rich A
02-13-2007 02:19 PM
This doesn't seem to do it for me.
Here's what I have on the ACS Server for the Default Group:
Define IP-based access restrictions (checked)
Denied Calling/ Point of Access Locations
NDG:TACACS (For our switches/ routers
Port: *
Address *
Define CLI/DNIS-baswed access restrictions
Permitted Calling/ Point of Access Locations
Controller
Port: *
CLI: *
DNIS: *Internal
Thanks in advance
02-25-2007 12:53 PM
hi ,
Check this link
Regards
Seema
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide