04-13-2012 05:35 AM - edited 07-03-2021 09:59 PM
Hi Guys,
I have a cisco wlc 5508 fixed at one of my remote head office and 3 (AIR-CAP3502I-E-K9) APs at remote branch office connect via flex connect mode (IPLC link).I have created a single SSID and added all three APs to that. What i want to know is, i got 4 different subnets in my LAN (branch office) and the authentication is done by the nps server in branch office, also there is a dhcp server which lease IP addresses to the client, how can I configure to lease the IP address for the correct subnet/VLAN base on the AD membership of the user? Because now it leases IP from the native VLAN which I have given on the WLC.If any one can help me on this,its great.
BR
Jana
04-13-2012 05:57 AM
You would need to be running 7.2 code to take advantage of this feature. With 7.2, you define what VLAN that the FCAP has access to. Then from AAA return 64/65/81 attributes to set the VLAN.
Steve
04-13-2012 05:59 AM
Didn't know that was possible, but I guess in 7.2:)
Sent from Cisco Technical Support iPhone App
04-13-2012 06:01 AM
Yeah, 7.2 added AAA Override, and ACL for FlexConnect.
04-13-2012 06:03 AM
I'm going to have to test that out to see how well it works:)
Thanks,
Scott Fella
Sent from my iPhone
04-13-2012 05:57 AM
Vlan changing on FlexConnect APs are not supported. Only when an ap is in local mode can you force the wlc to change the vlan.
Sent from Cisco Technical Support iPhone App
04-13-2012 06:01 AM
Even when the WLC is in the local mode, how can you push the vlan information when the user is in AD.
Thanks
NikhiL
04-13-2012 06:02 AM
Based on the group, and what attributes you return for the user. YOu can do forced vlan assignment/AAA Override via an AAA server.
Steve
04-13-2012 06:08 AM
Just like what Steve mentioned, you can send radius attributes back to the wlc to make vlan change, QoS and even session timeout. Just need to make sure AAA override is enabled on the WLAN.
Thanks,
Scott Fella
Sent from my iPhone
04-13-2012 06:20 AM
I was wondering how to do it when the user is not there in ACS. With the Groups getting mapped to Authentication Profile, it is cool
04-13-2012 06:23 AM
You can also use radius sequence to first look at AD then internal ACS group too.
Thanks,
Scott Fella
Sent from my iPhone
04-18-2012 03:57 AM
Hi Guys,
Thank you for the reply.Ya my WLC is 7.2
Hi
Scott Fella did you test this ?? did it work?
BR
Jana
04-18-2012 04:00 AM
I did not test this out yet. I might be able to today.
Sent from Cisco Technical Support iPhone App
04-18-2012 04:46 AM
Hi scott fella,
Ok great,please let me know your out come.
BR
Jana.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide