12-18-2011 02:20 AM - edited 07-03-2021 09:15 PM
I have the situation where I need to talk to multiple different Radius servers depending on the WLAN. Some of the WLANs are not able to route traffic over my entire network, and within these secure areas the Radius server for that area sit. Is there away that I can instruct the WLC to use its virtual interface to make the Radius Auth instead of using the WLCs Management interface?
Thanks
Randy Moore
12-18-2011 06:50 AM
The communication from the WLC and Radius uses the management ip of the wlc. Your defined AAA client in radius has to use the management ip... The VIP will not work.
Why wouldn't you have routing between the management and the subnet(s) your radius server is on?
Sent from Cisco Technical Support iPhone App
12-18-2011 11:36 PM
Hi Scott,
Thanks for the reply. We have the setup we have as two companies in the middle of a JV and different support models/needs in a new office. I don't want to have two WLCs and APs throughout the building so we are doing 1 with different needs.... Due to the different support arrangements a PC from one legacy company is not allowed on the network of the others... Lot's of fun.
Thanks again for the help.
Randy
12-18-2011 07:00 AM
It doesn't matter if the user WLAN does not route to your radius subnet(s)... It matters that your management ip routes to your radius subnet(s).
Sent from Cisco Technical Support iPhone App
12-18-2011 09:30 AM
To add to this ... If you have a WLC in the DMZ and you do say office extends or 802.1X in some flavor you would need to allow access from the radius server to the DMZ WLC managment address.
12-18-2011 12:04 PM
Cant the "Radius Server Overwrite interface" feature be used here, where in the interface mapped to WLAN will be used to reach the RADIUS server
Thanks
NikhiL
12-18-2011 12:06 PM
You can do vlan override... This will change the vlan a user will be placed on depending on what vlan id you specify on the radius server. The wlc has to have a dynamic interface on each of the vlans.
http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008076317c.shtml
Thanks,
Scott Fella
Sent from my iPhone
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide