cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1509
Views
0
Helpful
5
Replies

Guest Access Required but using AD credentials.

Garry Cooper
Level 1
Level 1

Currently we have a single Cisco 5508 setup for corporate access backed off to ACS and Active Directory.

Guest access is using the NAC Guest server with web auth..

What the requirements are is for a new SSID and to use the guest interface, so corporate users can authenticate at the network level, against the AD db so they can use none corporate devices. (ie: Iphone, android, tablets.)

This does not work at the moment because the client requires a certificate from AD.

Is there a way to do this.

Thanks

Garry Cooper

ICT Technical Analyst (Lan & Wan)

5 Replies 5

nikhilcherian
Level 5
Level 5

Are you trying to prevent Iphone, android,tablets from accesing the network using the guest WLAN

No.... I want to allow these devices to connect using their AD credentials, so semi trusted clients.

They will connect to a different SSID but use the guest interface.

What secuity type you use with the client, LEAP/PEAP

Stephen Rodriguez
Cisco Employee
Cisco Employee

On the ACS, if you allow for PEAP it should work.  Most 'i' devices will reach and pull the cert if they need it, but per the standard the cert is not needed on the client for PEAP.  and a droid devices should be able to connect to PEAP as well

HTH,

Steve

----------------------------------------------------------------------------------------------------------

Please remember to rate helpful posts or to mark the question as answered so that it can be found later.

HTH,
Steve

------------------------------------------------------------------------------------------------
Please remember to rate useful posts, and mark questions as answered

Thanks for pointing me in the right direction.

PEAP works great.

All sorted.

Thanks

Garry

Review Cisco Networking for a $25 gift card