cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1782
Views
2
Helpful
3
Replies

C9800 radsec-encrypted Management Access

ciscoprolin
Level 1
Level 1

Hi everyone,
we're planning to implement RADIUS Authentication for Management Access to our 17.9.4a C9800 SSO-HA WLC Pair and would like to secure the connection between the C9800 WLC and the FreeRadius Server using radsec.
As I didn't find any useful information I wonder if that's possible and if yes could you be so kind so as to share the instruction guide with us ? Is TLS which is based on mutual Certificate authentication required for radsec or can we also just go with a RADIUS Server Certificate for radsec ?
Thanks very much guys. 

Cheers,
Thorsten

1 Accepted Solution

Accepted Solutions

Mark Elsen
Hall of Fame
Hall of Fame

 

 - Radius with radsec is not possible for securing management access , only for authenticating schemes with wireless clients  , 

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

View solution in original post

3 Replies 3

Mark Elsen
Hall of Fame
Hall of Fame

 

 - Radius with radsec is not possible for securing management access , only for authenticating schemes with wireless clients  , 

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Hello,

Any idea where I can find documentation for configuring radsec for client authentication? I can understand that I need a ca certificate from the 9800 wlc but don’t know how to get that ?

 

 - Perhaps parts of this documentation can help : https://www.wiresandwi.fi/blog/cisco-radsec-part-6-cisco-device-switch-configuration

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)
Review Cisco Networking for a $25 gift card