Solved

Cisco Aironet SSID with Radius

Posted on 2010-11-15
8
1,755 Views
Last Modified: 2013-12-09
Hi Guys,

I have a ssid on my Cisco Aironet 1310 and a radius server running (freeradius)

What setting do I need to put on the AP so when a user tries to connect to that ssid he is prompted for a username and password and not a wpa ley.

And that username and password would be checked from the radius server.

Thanks
0
Comment
Question by:masdf123
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
8 Comments
 
LVL 25

Accepted Solution

by:
Ken Boone earned 500 total points
ID: 34145307
something like this:

aaa group server radius rad_eap
 server 1.1.2.13 auth-port 1645 acct-port 1646
!
aaa group server radius rad_acct
 server 1.1.2.13 auth-port 1645 acct-port 1646

aaa authentication login eap_methods group rad_eap

dot11 ssid example-ssid
   vlan 29
   authentication network-eap eap_methods
   authentication open eap eap_methods

radius-server attribute 32 include-in-access-req format %h
radius-server host 1.1.2.13 auth-port 1645 acct-port 1646 key radius-pwd
radius-server host 1.1.2.13 auth-port 1812 acct-port 1813 key radius-pwd
radius-server vsa send accounting


The radius password has to match on the radius server.  You will also need a certificate on the radius server, as well as on the client.  
0
 
LVL 1

Author Comment

by:masdf123
ID: 34145653
Why do you have 2 lines?:

radius-server host 1.1.2.13 auth-port 1645 acct-port 1646 key radius-pwd
radius-server host 1.1.2.13 auth-port 1812 acct-port 1813 key radius-pwd
0
 
LVL 25

Assisted Solution

by:Ken Boone
Ken Boone earned 500 total points
ID: 34146407
sorry you don't need the second line.  Radius can use 1812 and 1813 or 1645 and 1646.  So the rest of the config is refering to 1645 and 1646 in my example.  If your radius server uses 1812 and 1813 you will also need to change the previous lines in the aaa group commands and then ditch the 1645 and 1646 references.
0
Turn your laptop into a mobile console!

The CV211 Laptop USB Console Adapter provides a direct Laptop-to-Computer connection for fast and easy remote desktop access with no software to install.

 
LVL 1

Author Comment

by:masdf123
ID: 34149027
For this to work with freeradius. I am enabling anything specific?
0
 
LVL 25

Expert Comment

by:Ken Boone
ID: 34149045
Not that I am aware of.  I have never set up freeradius.   I have used cisco's acs server and I have used microsoft IAS and NPS.  Radius is a standards based protocol.  I would think you would still need to define the AP as a radius client and configure the shared key password that will be used for the radius communications on the freeradius server.
0
 
LVL 1

Author Comment

by:masdf123
ID: 34149052
So something like EAP enabled?
0
 
LVL 1

Author Comment

by:masdf123
ID: 34149065
And when I connect this AP so a vlan port on the switch. Do I tell the switch about radius ?
0
 
LVL 25

Assisted Solution

by:Ken Boone
Ken Boone earned 500 total points
ID: 34149256
No its just between the AP and radius.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Working settings for French ISP Orange "Prêt à Surfer" SIM cards for data connections only. Can't be found anywhere else !
DECT technology has become a popular standard for wireless voice communication. DECT devices are not likely to be affected by other electronic devices and signals because they operate in a separate frequency-band.
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question