cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
519
Views
20
Helpful
6
Replies

possible to have 2 ssid using two different AD groups?

baselzind
Level 6
Level 6

atm i have a wlc with a ssid that uses a group in AD for authentication, question is can i create a second ssid that uses a different group in the same AD for authentication? like can i create a second entry for my same AD with the same IP and enter a different group then tie this second entry to a ssid?

6 Replies 6

Arshad Safrulla
VIP Alumni
VIP Alumni

Assuming that you are using Radius for authentication, it is perfectly possible. But since the IP range will be same consider using per user dynamic ACL assignment using your radius server to maintain segregation and security if required. You can have a different ACL for Group1 and different one for Group2. 

No I'm not using radius , I just have a wlc and active directory windows server. there is no acl involved, when I added my initial AD I specified a group which contains all the users that will authenticate , i want to add a second ssid that use another group in my AD. is it possible or i can only use one group

Arshad Safrulla
VIP Alumni
VIP Alumni

Are you using LDAP for Dot1x? or Layer3 Auth?

DOt1x

Arshad Safrulla
VIP Alumni
VIP Alumni

I haven't done any deployments on this, but as per the Cisco documentation it states that "Users inside a Group cannot be authenticated. They need to be inside a Default Container (CN) or an Organizational Unit (OU)"

https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/211277-WLC-with-LDAP-Authentication-Configurati.html

 

If you want more granularity I would suggest that you run NPS service, and do a Radius integration. This will add more security (depends on the EAP mechanism) and will give you more flexibility.

patoberli
VIP Alumni
VIP Alumni

My suggestion is to add the NPS Role onto that server (or even better a separate one). That includes Radius functionality. Then you can use Radius between the WLC and the DC and do this (and much more). 

Review Cisco Networking for a $25 gift card