cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
753
Views
2
Helpful
6
Replies

Cisco WLC 5520 AireOS - iPSK Internal

Agung1007
Level 1
Level 1

Hi team,

Just want to ask,

can we implement Wireless WLAN iPSK without ISE ?

*like in the Meraki?

I already search the documentation but seems like it need ISE to "seperate" the PSK and need to register the MAC Address of the client 

*i think it's not possible when the environment is a lot of client (>1000 client) if we need to register the MAC Address client first for iPSK

 

Thanks,
Best Regards.

6 Replies 6

I dont think  wlc 5500 series support iPSK' it support in 9800 series. (I will check this point).

Second no way use iPSK without ISE.

MHM

From the documentation,

on AireOS >8.5
it supported for iPSK

but i still havent found if the iPSK able to do without ISE
and need to register the MAC




Cisco mention radius server not mention ISE exactly.

If you have radius server try config it.

You can use client profile (one password to each user) or you can use AP location (one password for each location).

I think second option more easy to config.

MHM

alisha_rascon01
Level 1
Level 1

Cisco Wireless LAN Controllers (WLCs) with AireOS software did not natively support iPSK (Identity Pre-Shared Key) without the use of Cisco Identity Services Engine (ISE). However, software features and capabilities may have evolved since then, so it's advisable to check the latest documentation or release notes for your specific WLC version.

JPavonM
VIP
VIP

Yes this is posible to use iPSK on MS NPS and Forescout, to mention some.

The problem with using MS NPS is that you need to setup a new account at the DC for every MAC address you want to register to use the iPSK, so that would be a pain to make it work, specially for your IT Admins.

Rich R
VIP
VIP

As the others have said it is only supported using Radius.  Cisco would like you to use ISE but any suitably configured radius will work.  If you have software developers who understand radius and know how to configure Free Radius then you could even write your own solution to work the way you want but otherwise you're stuck with the existing options already mentioned.

Review Cisco Networking for a $25 gift card