Showing results for 
Search instead for 
Did you mean: 

AD connection and certificate

Level 1
Level 1



I'm trying to set up Radius authentication with one certificate per user all automatically.

I managed to set up Radius authentication but unfortunately I didn't manage to set up certificate authentication.

In my case I think the WLC configuration is correct.
How can I make sure that the only case where the connection is made is when the certificate and the AD account is correct?


Thank you for your help.
I appreciate it,


7 Replies 7

In the tutorials I don't see the steps to perform.
I would like to allow AD authentication coupled with certificate authentication.

To allow to certify the position but also the account.

If PC has a valid AD account but not the certificate then no connection.

If PC does not have AD account but has the certificate to install then no login

If PC has the AD account + certificate then the connection is made.


I only know the variants with radius server, but you haven't written which radius software you are using. What you want to do is EAP-TLS or EAP-TTLS. In any case, the radius is normally responsible to authenticate the user and either tell the WLC that the user has access or hasn't access.


For my part I use, Windows NPC for the radius server.

I just now realized that you want to do AD auth (username + password?) and additionally certificate?

Those are two separate authentications and for this, you need to use either, the brand new TEAP standard (only supported on Windows 10 build 2004 and newer) or EAP Chaining (requires a special client software on the client, like AnyConnect NAM plus ISE as Radius). Not sure if this is possible in another way.

The clean way to do it is to use Cisco ISE as RADIUS Server and use AnyConnect NAM from the client, this is called EAP Chaining

Note1: AnyConnect NAM is not supported on MAC OS

Note2: implementation this kind of Authentication does not supported “fast” roaming like 802.11r (FT) feature

For more info check "Understanding EAP-FAST and Chaining implementations on AnyConnect NAM and ISE"


The non-clean way to do is to use Cisco ISE as RADIUS Server and configure it to use Machine Access Restrictions (MAR)

Machine Access Restriction Pros and Cons:

The newer way to do it without MAR or using AnyConnect is by using ISE 2.7 "and after" and client that support TEAP (Tunnel Extensible Authentication Protocol) this is so far supported on Windows 10 build 2004 but i don't see Apple support it yet. for more info check EAP Chaining with TEAP



So you're telling me that it is not possible to implement radius authentication plus certificate verification to allow SSID connection with an NPS server?

Review Cisco Networking for a $25 gift card