cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1915
Views
21
Helpful
3
Replies

Access Points Authentication for Plug n Play (PnP)

TH09
Level 1
Level 1

Hi experts,

 

Has anyone tried out this new feature in the DNAC? So we have an SDA environment and I wanted to onboard APs using PnP and dot1x, any guides or reference that can help me guide through the process?

 

Thanks.

3 Replies 3

Scott Fella
Hall of Fame
Hall of Fame

There are a lot of guides under the DNAc section.  Here is a link to some:

Cisco DNA Center User Guide, Release 2.2.2 - Provision Your Network [Cisco DNA Center] - Cisco

You can also search., "cisco DNAc access point PnP"

-Scott
*** Please rate helpful posts ***

ItsShowtime
Cisco Employee
Cisco Employee

Hi,

I'm just chiming in here because there seems to be an issue when deploying the access points through PnP with authentication through the TLS certificate.

Please take into account that currently behaviour seems to be misaligned between the WLC and AP onboarded through PnP for TLS, the AP will present the TLS certificate which is LSC and the WLC will put the AP in LSC fallback state which does not allow the AP to download the WLAN info through the CAPWAP. There might be a very easy manual workaround for that, but it could defeat the whole purpose of PnP (zero touch) automation.

I have not experienced any issues using the PEAP option with credentials though and this can also be leveraged efficiently in ISE Policy.

Engineering is looking into the issue with the TLS LSC certificate as we speak and I'm convinced we will see a fix on the DNAC side eventually, but for now PEAP seems the way to go if you want some added security enabling some form of AP authentication.

Bear in mind that I'm not a security expert and I advise you to go over this with your security team or a Cisco security expert before rolling this out in production.

choiwon
Cisco Employee
Cisco Employee

For anyone looking for the guide, here is one that has been put together by sandjose 

Secure AP onboarding- An Introduction to Enhanced Network Security

Review Cisco Networking for a $25 gift card