02-24-2014 12:54 PM - edited 07-05-2021 12:16 AM
Hello,
I have been trying to configure dynamic vlan assignment for the employee wlan. Trying to put the employee on vlan 20
Here are the components used
WLC: 2100 Software version: 7.0.240.0
AP: 3502I IOS version: 12.4 Mini IOS version: 7.0
Radius server: tried mutiple radius servers (rsa radius , free radius)
On the WLC:
-----------------
1. Created a AAA server.
2. Along with management interface(vlan 10), configured dynamic interfaces (vlan 20, vlan 30)
3. AP manager interface is on vlan 40
4. Created WLAN assigned to management interface-- WPA2 (AES) , 802.1x
5. on AAA servers tab - checked authentication servers and assigned the AAA server. authentication priority order is set to only radius
Here, I have 2 options for radius overwrite.
one on the AAA servers tab
second on the Advanced tab
I have selected both. or one at a time
Ports between WLC and switch is a trunk
On the AP:
--------------
1. Local mode
2. Port between AP and switch switchport access - vlan 40
On radius server:
----------------------
configured WLC's management interface as client
and assigned the following attributes
tunnel-type := vlan
tunnel-medium-type = ieee-802
tunnel-private-group-id = 20
When i try to authenticate with an iphone it is successful. But it puts me on the same interface as management interface (vlan10). When i do the packet capture i do see the access-accept but i dont see the attributes.
when i use a radius test utility against the radius server I do receive all the attributes.
Im a newbie on this. Iam i missing something here? any help will be much appreciated.
Solved! Go to Solution.
02-24-2014 02:43 PM
Take a look at this setup:
http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113591-aaa-override-acs52-00.html
What radius server are you using?
Sent from Cisco Technical Support iPhone App
02-24-2014 02:30 PM
The AAA override needs to be enabled on the WLAN advanced tab, don't use the entry in the AAA server tab.
Sent from Cisco Technical Support iPhone App
02-24-2014 02:38 PM
Thank you for the reply.
I have selected the Allow AAA override on the advanced tab. Tried the authentication but fails to put me on the right vlan.
Please note that in the access-accept i donot see the tunnel attributes. However i see them on the access-challenge from the radius.
02-24-2014 02:43 PM
Take a look at this setup:
http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/113591-aaa-override-acs52-00.html
What radius server are you using?
Sent from Cisco Technical Support iPhone App
02-25-2014 12:18 PM
Thank you for the replys.
Im using freeradius running on a linux machine.
I was having trouble getting the attributes from RSA radius server. So, i configured a user on users folder of freeradius. When i use Ntradping and test the connection i see that radius server returns the tunnel attributes. (vlan, ieee-802 , vlan-id)
Both the links you guys have provided are very useful but unfortunately we wont have a ACS until next month.
Scott--
I have followed step-by-step frm the link you provided either pc/phone it still puts me on the same vlan as management interface.
Please let me know if i need to upload any packet captures or configuration files.
02-25-2014 12:24 PM
No problem... if you have the attributes being passed back to the WLC, then the WLC will look at that attribute and assign the correct vlan, as long as AAA override is enabled on the WLAN advanced tab. I would look at the log on FreeRadius (if there is one) and or sniff the packets to and from the radius to the WCL and verify that it is being sent.
Thanks,
Scott
*****Help out other by using the rating system and marking answered questions as "Answered"*****
02-25-2014 12:29 PM
You can try these other attribures for airespace:
Thanks,
Scott
*****Help out other by using the rating system and marking answered questions as "Answered"*****
02-24-2014 08:23 PM
Here is a sample configuration with WLC 7.0.116.0 & ACS 5.2.
http://mrncciew.com/2013/05/21/aaa-override-in-acs5-2/
HTH
Rasika
**** Pls rate all useful responses ****
02-26-2014 02:37 AM
Kindly check the following link for reference.
sample configuration link
http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-0/configuration/guide/c70/c70intf.html
Trouble shooting link
03-04-2014 01:55 PM
I wanted to give an update on this.
We expedited our order for ACS and i was able to configure and test the setup based on the above documents within 30mins.
I now need to figure out how to do this with NPS.
Thank you all for the help!
03-04-2014 02:04 PM
Take a look at this link
https://lavazzza.wordpress.com/2010/05/29/wlc-school-for-network-admin?s-who-can-read-real-good-part-2-ok-so-it-has-been-awhile/
Sent from Cisco Technical Support iPhone App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide