cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
725
Views
6
Helpful
7
Replies

WLC 2504 dot1x

hs08
VIP
VIP

I was successfull create SSID with 802.1x on WLC 9800 with WPA2 and 802.1x as shown in below picture

hs08_0-1787928054495.png

But i create same thing on WLC 2504 then when endpoint try connect to this SSID there is no option connect using certificate? I only prompting username and password when connecting.

hs08_1-1787928176079.png

 

 

1 Accepted Solution

Accepted Solutions

aleabrahao
Meraki Community All-Star
Meraki Community All-Star

As I said, you need to configure the SSID manually, check the link I sent you please.

I am not a Cisco employee. My suggestions are based on documentation of Cisco, best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

7 Replies 7

aleabrahao
Meraki Community All-Star
Meraki Community All-Star

 

Assuming you are talking about 802.1x EAP-TLS, You need to manually install the certificate on the device and manually configure the SSID on your machine, or else configure the SSID via GPO.

 

https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html

I am not a Cisco employee. My suggestions are based on documentation of Cisco, best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

ammahend
VIP
VIP

connection via certificate is not configured on WLC, you only configure 802.1X on WLC like you have configured here, your endpoint need to be configured to use certificates for authentication and your radius server needs to be configured to accept EAP-TLS for AAA. 

-hope this helps-

@hs08 problem are same on both wlcs.. 802.1x only prompt user/pass by default, bcs EAP method is negotiated between client supplicant and RADIUS server, not WLC.. u need to cfg Windows supplicant (via GPO..) to use EAP-TLS with cert instead of PEAP.. and be sure RADIUS server has EAP-TLS cfg as an allowed procotols..

hs08
VIP
VIP

hi @Stefan Mihajlov @ammahend @aleabrahao 

I use same endpoint and the certificate already installed in the endpoint. When the endpoint connect to the SSID on WLC9800 there are option to enter the credential or connect using certificate.

hs08_0-1788022287181.png

Same endpoint if will connect to the SSID on WLC2504 only asking to enter the credential, the is no option to select using certificate.

aleabrahao
Meraki Community All-Star
Meraki Community All-Star

As I said, you need to configure the SSID manually, check the link I sent you please.

I am not a Cisco employee. My suggestions are based on documentation of Cisco, best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

@hs08 difference is caused by SSID profile saved in Windows for each WLC.. delete saved Wifi profile for WLC 2504 ssid on endpoint, reconnect fresh and connect using a cert option will apper just like on 9800 ssid

aleabrahao
Meraki Community All-Star
Meraki Community All-Star

@Stefan Mihajlov @hs08 No matter how often he does that, it won't always work. The most reliable method is to add the network manually, and for a real-world scenario, it is best to configure it via GPO, the very document I sent shows this.

I am not a Cisco employee. My suggestions are based on documentation of Cisco, best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Review Cisco Networking for a $25 gift card