12-18-2012 12:37 PM - edited 07-03-2021 11:14 PM
Infrastructure:
WLC2500, PEAP MS Chapv2 authentication thru a single IAS
PCI WLAN with AD Security group
Internal WLAN with AD security group
Scenerio:
I need to set up seperate authentication for each WLAN with it's appropiate AD security group. In other words, the PCI users can only authenticate (through the PCI WLAN) to the PCI AD security group.
Potentual issues:
Can't have the Internal user authenticating to the PCI network.
I've racked my brain on ways this can be done and I'm not wanting to create a 3 armed monster. Does anyone have any "best practices" ideas on how to easily accomplish this task?
Thanks
12-18-2012 01:10 PM
The only way I can think of would be NAR. Ate a policy that they ant connect to a specific DNIS. But I'd have to look to see if IAS supports it or not
Steve
Sent from Cisco Technical Support iPhone App
12-18-2012 01:12 PM
You need to have 3 policies create in IAS. Each will define the ssid and the AD group the user belongs to. So on the wlc, do you have 3 ssids and each has it own vlan?
Sent from Cisco Technical Support iPad App
12-18-2012 01:17 PM
What you need to use is the called-station-id radius attribute that is passed to IAS. You can specify a regex for that ex. *SSIDA
Sent from Cisco Technical Support iPad App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide