01-18-2010 10:46 AM - edited 07-03-2021 06:25 PM
Hi,
When I got the information to configure Lightweight Access Point as an 802.1x Supplicant in Document ID 107946,
I saw I need to configure the Switch as a AAA Client with RADIUS (Cisco Aiornet), but I already have configurated this Switch as a AAA Client with RADIUS (IOS) to support the 802.1x in IP Phone and Workstations
My question is:
How can I configure the ACS to support the same switch to authenticate both the 802.1x IP Phones Supplicant as the LWAPP 802.1x Supplicant
My Best Regards,
Thanks in Advanced
01-21-2010 05:23 AM
Hi,
We had a similar situation where we needed to authenticate wireless users with RADIUS as well as TACACS+ users for AP configuration.
The way we did it was to create two entries in ACS for each AP. We called one "AP-NAME" and the other "AP-NAME+". The AP entries had the same IP address but different authentication methods and we used different shared keys too.
The entries were placed under different groups to keep things clearer - one group for RADIUS and one for TACACS+.
Hope that helps.
Pete
01-25-2010 04:04 AM
Hello
If you need authenticate LWAPP AP with ACS you should do this:
1. Add switch (I hope this is Cisco Switch ) in ACS as RADIUS (Cisco IOS/PIX 6.0) device
2. Add your AP credentials as user (you can configure one credential set for all your AP on WLC)
3. Configure dot1x auth on port where you have AP
For correct phone auth you need this:
1. Configure Multi Domain Authentication on switch port
2. Configure av-pair for voice traffic on ACS
Regards,
Stanislav Kuchma
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide