10-31-2013 02:15 PM - edited 07-04-2021 01:11 AM
We have been asked to extend an exiting wireless network utilising an ACS 1200 appliance for PEAP MSCHAPv2. The ACS is currently configured to check a single security group for membership and then grant/deny access.
The customer has supplied 26 OUs across their AD that they would like all members of to be granted access. Is there an easy, or relatively easy, way to configure this?
11-03-2013 07:49 AM
An easy way would be to create a Wireless Group and add all the OU's to that group, then you only have to lookup one group.
Thanks,
Scott
Help out other by using the rating system and marking answered questions as "Answered"
11-04-2013 08:11 PM
Scott,
Thanks for the reply.
I thought of using shadow groups with a PowerShell script to update the shadow groups but as my customer is a large multi-national running this type of script would not be acceptable. Is this what you were thinking or is there a better way to add the OUs a a Wireless group?
11-04-2013 08:48 PM
I believe that is the only way.
Sent from Cisco Technical Support iPhone App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide