Integrate WLC & Active Directory

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-12-2013 01:08 AM - edited 07-04-2021 12:38 AM
Hi,
Iam trying to find that how can i configure WLC to authenticate the wireless clietns based in the username and password from Active Directory.
Please suggest.
Regards,
Taufeeq.
- Labels:
-
Wireless LAN Controller
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-20-2013 03:19 AM
As I know WLC can only work with a LDAP database but not Microsoft AD.
The below link will provide the config example and also depth understanding on the requirements, please go through the link atleast once..
http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a0080a03e09.shtml

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-20-2013 03:55 AM
Yes, LDAP or RADIUS, you can use FreeRADIUS if you don't want to buy a RADIUS server.
Thanks
Chris
Edit: To correct punctuation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-20-2013 12:29 PM
Hello,
As per your query i can suggest you the following solution-
WLC will work with LDAP not AD with RADIUS protocol.
Hope this will help you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-21-2013 12:01 AM
Hi Taufeeq,
I am not sure Abishek and Ravi provided correct answers however Mooncat did (in my opinion).
You can configure WLANs to authenticate through various different methods including:
- RADIUS
- LDAP
- Local (Based on WLC)
Additionally, you can configure different ways to auth those users. For example I have a couple of networks setup in different ways:
1. 802.1x Security linked to a RADIUS server with the WLC configured as a Radius Client and shared secrets setup etc. This authenticates my AD users through NPS (Network Policy Server) installed on a Windows 2008 server.
2. Web authentication pass through linked to both local (on WLC) and RADIUS. In this setup there are local users I've setup on my WLC who can log in to the guest portal or alternatively any AD user can also log in as I have setup RADIUS as my secondary method of authentication for that WLAN.
3. Web authentication pass through linked to an LDAP server -> I tried this and actually found it tricky to implement for what I wanted it for. I ended up going for the RADIUS installation instead as it was more flexible but it does work as well!
I hope that helps.
Thanks,
Ric
Please rate helpful / correct posts
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-21-2013 03:38 PM
Rated Mooncat & Ric's posts.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-22-2024 05:57 PM
Hi,
For mobile users, can we use LDAP or we need Radius for Authentication? And how we can authenticate mobile users?
