?
Solved

Cisco Aironet SSID with Radius

Posted on 2010-11-15
8
Medium Priority
?
1,767 Views
Last Modified: 2013-12-09
Hi Guys,

I have a ssid on my Cisco Aironet 1310 and a radius server running (freeradius)

What setting do I need to put on the AP so when a user tries to connect to that ssid he is prompted for a username and password and not a wpa ley.

And that username and password would be checked from the radius server.

Thanks
0
Comment
Question by:masdf123
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
8 Comments
 
LVL 25

Accepted Solution

by:
Ken Boone earned 2000 total points
ID: 34145307
something like this:

aaa group server radius rad_eap
 server 1.1.2.13 auth-port 1645 acct-port 1646
!
aaa group server radius rad_acct
 server 1.1.2.13 auth-port 1645 acct-port 1646

aaa authentication login eap_methods group rad_eap

dot11 ssid example-ssid
   vlan 29
   authentication network-eap eap_methods
   authentication open eap eap_methods

radius-server attribute 32 include-in-access-req format %h
radius-server host 1.1.2.13 auth-port 1645 acct-port 1646 key radius-pwd
radius-server host 1.1.2.13 auth-port 1812 acct-port 1813 key radius-pwd
radius-server vsa send accounting


The radius password has to match on the radius server.  You will also need a certificate on the radius server, as well as on the client.  
0
 
LVL 1

Author Comment

by:masdf123
ID: 34145653
Why do you have 2 lines?:

radius-server host 1.1.2.13 auth-port 1645 acct-port 1646 key radius-pwd
radius-server host 1.1.2.13 auth-port 1812 acct-port 1813 key radius-pwd
0
 
LVL 25

Assisted Solution

by:Ken Boone
Ken Boone earned 2000 total points
ID: 34146407
sorry you don't need the second line.  Radius can use 1812 and 1813 or 1645 and 1646.  So the rest of the config is refering to 1645 and 1646 in my example.  If your radius server uses 1812 and 1813 you will also need to change the previous lines in the aaa group commands and then ditch the 1645 and 1646 references.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 1

Author Comment

by:masdf123
ID: 34149027
For this to work with freeradius. I am enabling anything specific?
0
 
LVL 25

Expert Comment

by:Ken Boone
ID: 34149045
Not that I am aware of.  I have never set up freeradius.   I have used cisco's acs server and I have used microsoft IAS and NPS.  Radius is a standards based protocol.  I would think you would still need to define the AP as a radius client and configure the shared key password that will be used for the radius communications on the freeradius server.
0
 
LVL 1

Author Comment

by:masdf123
ID: 34149052
So something like EAP enabled?
0
 
LVL 1

Author Comment

by:masdf123
ID: 34149065
And when I connect this AP so a vlan port on the switch. Do I tell the switch about radius ?
0
 
LVL 25

Assisted Solution

by:Ken Boone
Ken Boone earned 2000 total points
ID: 34149256
No its just between the AP and radius.
0

Featured Post

The Ideal Solution for Multi-Display Applications

Check out ATEN’s VS1912 12-Port DP Video Wall Media Player at InfoComm 2017. Kerri describes how easy it is to design creative video walls in asymmetric layouts and schedule detailed playlists ahead of time with its advanced scheduling feature.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This program is used to assist in finding and resolving common problems with wireless connections.
The Summer 2017 Scholarship Winners have been announced!
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question