06-05-2025 02:59 PM
Hi I'm Ivan
I would like to know, If is possible with AP in stadalone mode (using architecture Flex connect Central Auth-Local Switc) when it losss conectivity with WLC 9800, it could authenticate new end users (in the failure)?
We have reviewed, on failure, AP keeps the connection of end users with TLS, LWA, PEAP. But If some end user reauthenticate (in the branch site) for any reason (Windows suspend examp) he could not access to wifi DOT1X.
Thanks you for your advices,
Kind regards.
06-05-2025 04:59 PM
it depends on if the SSID is configured with Local Authentication
But for 802.1x SSIDs you would also need to define the RADIUS server/ certificate to the APs, that being said if the RADIUS server is not local to the site then there is no point.
06-05-2025 05:21 PM
06-05-2025 06:06 PM
Might want to review this so you understand the different states when using central vs local. This way you understand the risk of doing either modes.
06-08-2025 11:52 AM
As @Haydn Andrews says the only way to support 802.1x in standalone mode is with local radius authentication, configured in the flex profile. https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-15/config-guide/b_wl_17_15_cg/m-sniffer-cg.html#flex-ap-local-auth
There are a few examples of using central auth as primary with fallback to local auth.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide