Cisco WLC 5508 Quarantine / Remediation Methods

Posted on 2011-04-24
Last Modified: 2012-05-11
I am looking for suggestions on Quarantine / Remediation / Production design on our wireless network.

We are moving from an autonomous AP environment to a Cisco WLC 5508 controlling LAPs.

I am considering Dynamic VLAN Assignment at the WLC using RADIUS for authentication.

Does anyone have anything on quarantine / remediation / production design best-practices for wireless infrastructures?
Question by:c-h-r-i-s-t-o-p-h
    LVL 26

    Accepted Solution

    I assume you are planning on using 802.1X  for Radius VLAN assignment. 802.1x alone won't provide posture assessement and remediation, but may offer some type or quarantine by placing a failed authentication client on a "failed authentication" vlan. If you want full blow posture assessement and remediation you may want to look into Cisco NAC Clean Access.

    Author Comment

    We have an internal NAC solution. I plan to tie it into radius and the wlc using 802.1x... possibly AD in the future.

    Author Comment

    To add, I am interested in the shortcomings/  failings of this system as well as other best practice suggestions.
    LVL 26

    Expert Comment

    What NAC solution are you using. I did a NAC Deployment a few years ago and we did not need Radius for Wireless Quarantine and Remediation on our WLC's.
    LVL 26

    Expert Comment

    If you currently don't have AD, what identity source will you use for Radius, or would you be creating account locally on the radius server?
    LVL 44

    Expert Comment

    by:Craig Beck
    Just a note, but if you're using AD and want to use GPOs to configure policies on machines you may hit problems.  Microsoft don't support Dynamic-VLANs and in quite a few installations I've seen you will get problems when applying GPOs.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    Suggested Solutions

    Title # Comments Views Activity
    good comptia a+ teacher? 4 51
    Is this error real? 2 33
    Cisco Switch Password ---Urgent 3 20
    Security Permissions Issues 10 26
    Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
    This story has been written with permission from the scammed victim, a valued client of mine – identity protected by request.
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    Sending a Secure fax is easy with eFax Corporate ( First, Just open a new email message.  In the To field, type your recipient's fax number You can even send a secure international fax — just include t…

    733 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now