09-09-2024 12:32 AM
Good day Cisco community.
I want to extend a partner's corporate Wifi to our premises by creating an SSID on our Cisco WLC and tunnelling the traffic over Internet to partner's remote radius server. Our partner is using Ruckus network gear. how best can this be achieved ? is GRE tunneling possible and IPsec on top?...Any configurations to be made on our Cisco Firewal aswell ? Any configuration guidance will be appreciated.
Solved! Go to Solution.
09-09-2024 12:39 AM
GRE is use only to overrride some routing issue
IPSec in otherhand is perfect to connect NAD to radius because it secure not such GRE.
You want to run tunnel between WLC to AAA
MHM
09-09-2024 04:36 AM
>...is it possible defining an Ipsec Vpn directly from the WLC towards the radius server - or this can be best done by having the VPN on firewall level?
- As you are already saying : you can't setup an ipsec vpn directly on the WLC. It must be done at perimeter equipment such as the firewall or a router (indeed). Afterwards you must test if the intended radius server becomes reachable from the WLC ,
M.
09-09-2024 12:39 AM
GRE is use only to overrride some routing issue
IPSec in otherhand is perfect to connect NAD to radius because it secure not such GRE.
You want to run tunnel between WLC to AAA
MHM
09-09-2024 04:20 AM
Thank you. My follow up question is whether to define the Ipsec VPN connection at my firewall level or this is best done on the WLC level?
09-09-2024 04:38 AM
FW sure' I don't think wlc can run ipsec directly to server.
In FW you need to use policy based VPN and specify host mgmt IP in acl of IPsec.
MHM
09-09-2024 01:52 AM
- You don't tunnel an SSID towards a Radius server , the only thing that (can) happen(s) ; is that you
define 802.1x security with radius for the particular SSID/WLAN. Then you must make sure
that the radius server's defined on the WLC can be reached by the WLC over the networking infrastructure
'That's it'
M.
09-09-2024 04:28 AM
Thanks @marce1000. Since the radius server is remote (over the Internet) is it possible defining an Ipsec Vpn directly from the WLC towards the radius server - or this can be best done by having the VPN on firewall level?
09-09-2024 04:36 AM
>...is it possible defining an Ipsec Vpn directly from the WLC towards the radius server - or this can be best done by having the VPN on firewall level?
- As you are already saying : you can't setup an ipsec vpn directly on the WLC. It must be done at perimeter equipment such as the firewall or a router (indeed). Afterwards you must test if the intended radius server becomes reachable from the WLC ,
M.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide