We have a 9800-L WLC, running 3 main WLANs.
Employee production - Internal resources and Internet Access,
Guest - Internet Access only, ACLs in place to block all access to internet resources
Mac Filtering - Mac Address list + PSK, for printers, RF Guns, Tablets, and essentially anything that is not a person that needs wireless access to the internet and internal resources.
Today, our Client Support has enabled wireless access for the majority of IDs. This means that I can use xxx to connect to the employee wireless. Now I can use that on my work computer, byod or my cell phone. I want to be able to limit an Active Directory ID to only be able to connect to a specific WLAN. There are a few ways to do this, some way more complex than others.
here is what I have in place today.
Cisco 9800-L controller, Windows server running NPS - Radius agent. I do not have Cisco ISE. Has anyone been able to do this or has anyone done this? What is the best method? Tips/Tricks?