10-20-2022 12:52 PM
Hello. I have the following scenario
3 sites (A,B,C) with 1 WLC located at Site A. We use the same SSID's at every site
all Access points at every site are in flex connect mode. The SSID's are configured for local switching.
I have three flex connect groups; the access points in these flex connect groups are sorted by Site.
When access points at Site B and C enter standalone mode (lose connectivity with the WLC). I need them to use external authentication with a radius server located on-site but switch back to central authentication via WLC when the AP enters connected-mode.
I do not want the Access-Points using local authentication.
10-20-2022 10:07 PM
unfortunatly not a current feature available
10-20-2022 11:30 PM
Add both servers (Central and Local radius servers) under local authentication for Flex. But in this case you need to add all your AP’s as NAD (radius client).
10-21-2022 06:41 AM
by adding the radius servers under local authentication in the flex connect group settings, while that disable the use of the central authentication via the WLC when the AP is in connected mode.
10-21-2022 09:15 AM
No as long as the WLAN is configured for central authentication it should only use the local radius as fallback.
https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/flexconnect.html#ID42
You'll have to test to see how it behaves in reality - how long it takes to failover and failback.
I've only used the local radius for pure local auth not tried switching between them.
10-21-2022 11:11 AM
Specific description of that behaviour here:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-8/FlexConnect_DG.html#pgfId-43489
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide