01-31-2019 09:33 AM - edited 07-05-2021 09:47 AM
Hello
We have a central site which host a Virtual WLC and 5 or 6 remote offices each with a local Windows NPS authentication server used for a standard 802.1x SSID. This all works perfectly.
However we encounter an issue when the WLC is offline, the remote sites using Flexconnect and with standard PSK SSIDs continue to work. But the 802.1x SSIDs fail.
I know that this is due to the WLC proxing the requests. I have been trying to find a way to make the AP's wither failback to authenticate against the Local NPS when in flex connect mode, or even all the time if needed.
I have read through a lot of documentation on whats needed, but I can not find anything concrete. This is not something I am able to replicate until I have an allotted outage, so anything I can find out before would be great. This diagram shows what I am trying to achieve. Is it as simple as just enabling flex connect local switching??
01-31-2019 10:50 AM
Hi
Create a flexconnect group, add the AP to this group and inside the group point to you radius server. On General tab, AAA you can define up to 2 radius server, one as primary and a second as secondary.
-If I helped you somehow, please, rate it as useful.-
01-31-2019 11:19 AM
01-31-2019 02:10 PM - edited 01-31-2019 02:13 PM
Yes you need to enable local authentication so the Radius Servers to be used are the ones configured on the FlexC Group. However, where is your DHCP Server located?
This document tells you what you need: https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/7-5/Flex_7500_DG.pdf
02-01-2019 01:12 AM
09-16-2022 06:33 AM - edited 09-16-2022 06:40 AM
Yes it works, I've used it for some customers. But be careful: what version of software and what APs are you using?
There's a bug https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy00740 that causes it to break so you need at least 8.5.182.0 or 8.10.x. It's nasty because you configure it and it works until CAPWAP to the WLC is reset for any reason (days, weeks or months later) then it stops working until you reboot the AP.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide