Search This Blog

Showing posts with label ACS. Show all posts
Showing posts with label ACS. Show all posts

Friday, 18 March 2011

AP Policies ACS

AP Policies can be used to have a list of approved AP's.  It is also possible to back this off to Radius. Remember to check the MAC address delimiter. Add the MAC address of the AP to ACS with the MAC as the username and password.

Also you must check "Network User" on the Radius server as the server cannot be individually specified.



ACS Network Access Profiles

You can use Network Access Profiles in ACS to either grant or deny access based on various attributes. This example denies users from SSID "Sec1" and a particular OUI from accessing the network. You can use various attributes so its worth learning what the main ones are.








You can also use this to allow authentication based on certain attributes and deny others.

Friday, 4 March 2011

Airspace Attributes ACS

Check the Aire-Interface-Name and assign a name with THE SAME as the WLC Interface you created.. It’s case sensitive.

Submit & Restart.

IETF Radius Attributes VLAN Assignment


Make sure that allow aaa override is checked at the WLAN config.