WellingtonIS
asked on
Radius Server
I need to build a 2003 Server with Radius on it. Can someone recommend software for this project. I looked into Cisco ACACS but thats extremely expensive. I basically need it for 12 access points.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
How do you setup SSIDs?
I haven't worked with Cisco in years, but look at this:
http://sysadminnotebook.blogspot.no/2011/05/cisco-aironet-ssid-with-radius.html
http://networkengineering.stackexchange.com/questions/1824/using-radius-to-restrict-ssid-on-cisco-aironet
http://sysadminnotebook.blogspot.no/2011/05/cisco-aironet-ssid-with-radius.html
http://networkengineering.stackexchange.com/questions/1824/using-radius-to-restrict-ssid-on-cisco-aironet
ASKER
Can this do wpa2?
WPA2 - encryption is handled by the Access Point, and dependent on firmware on AP - most likely you have this ability...
And give that clients are at least XP SP2
And give that clients are at least XP SP2
ASKER
OK I have a radius server set up. I'm using the Aironet 1130 ag I can get the access point to the server but I can't figure out how to get WPA2 installed. Can this even be done? According to Cisco it can but how??
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Yes he is correct. I did get it to work with only 1 wpa2. My challenge is added the rest. When I do that i lose the clients.
ASKER
got this set up so far 1 vlan the test pc is connect but I can't get an IP address. what am I doing wrong?
Can you post an IAS event from the Security log on the server?
ASKER
Here ya go. It authenticates but it only gets a 169 address... I did exactly what the instructions said. It's on VLAN 7 but its not finding DHCP
log.png
log.png
That's not the IAS security events. That's the AP log.
However you're not even using RADIUS - The client authenticated using PSK.
Can you post the AP config?
However you're not even using RADIUS - The client authenticated using PSK.
Can you post the AP config?
ASKER
Humm. I have the radius set up in there. Anyway here's t he config.
ap.txt
ap.txt
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
OK so is this the reason i'm not getting an IP from my DHCP server?
Maybe...
If you turn off WPA and just use a wide-open SSID do you get an IP address?
The config doesn't look very clean to me. Have you edited it in the CLI?
If you turn off WPA and just use a wide-open SSID do you get an IP address?
The config doesn't look very clean to me. Have you edited it in the CLI?
ASKER
Actually I used the GUI in the AP.
You don't have a native VLAN configured. The GUI won't let you not select a native VLAN as it relies on it for management.
ASKER
correct. - so I have to do t hat via command? If I don't put in a VLAN and just hook up one ssid it works. SOmething with the VLANS. again connecting to the ap but no IP address.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
ok THANKS. Will try
ASKER
OK I did that, made the native vlan 7 and I go at least one device connected. THanks.
Ok that's good... so what you need to do is make the VLAN where the management IP address sits as the native VLAN on the AP, then set up all the other SSIDs and VLANs.
ASKER
The native VLAN is 3 so I made that the native vlan. So now I have 2 ssids with security working. Believe it or not I can't get the guest to work! that has no security at all.
Check the VLANs...
ASKER
I did. I have vlans not communication or no showing up on the AP. One is my guest and one is for what's called an ascom phone. I'm not sure what's wrong because I'm basically doing everything the same. The guest network is open no security - the ascom phone is aes not tpik and wpa2 with a security code. I'm adding everything but no luck.
Can you post your AP's current config, and switch config.
ASKER
here you go. Keep in mind that I did all of these via the GUI on the AP itself. I checked the switches for the VLAN info and confirmed it's set up correctly. Vlan 4 and VLan 21 are my "problem" children.
airconfigs.txt
airconfigs.txt
I appreciate that you have checked the switch VLAN info, however I'd still like to see it.
Also, the output you provided is truncated. I can only see as far as a few subinterfaces on the 2.4GHz radio. I really need to see all of the config.
Can you disable shared authentication on the Guest SSID?
dot11 ssid GUEST
vlan 4
authentication open
authentication shared
Also, the output you provided is truncated. I can only see as far as a few subinterfaces on the 2.4GHz radio. I really need to see all of the config.
Can you disable shared authentication on the Guest SSID?
dot11 ssid GUEST
vlan 4
authentication open
authentication shared
ASKER
ok took out the shared and I also checked the box Set SSID as guest mode. Ill get you a better config file.
ASKER
here's the config exported from the AP.
airconfig.txt
airconfig.txt
Ok, that looks fine.
So, does the Regi0n@l SSID work?
So, does the Regi0n@l SSID work?
ASKER
YEs that's a spectralink phone. The strange thing is if I do a show VLAN I see packets transmitting. Is it possible just not showing up in the AP?
If you connect the spectralink phone to the Guest SSID does it work?
ASKER
Can't do that the phone is preprogramed
Ok I need to see the switch config and the following outputs from the switch..
show interface trunk
show vlan brief
show interface trunk
show vlan brief
ASKER
The ap doesn't show trunk but I got the vlan...
vlanconfig.txt
vlanconfig.txt
I need the SWITCH not AP config and outputs...
ASKER
ok that may take a bit. I'll get back to you soon thanks so much for this;..
ASKER
I know what the problem is with VLAN 21 the ascom phones. that vlan needs to have world mode enabled. I see how to do this but It appears that this will be for everyone and I only need this on one vlan.
Don't worry about enabling world mode globally - it just means that auto power levels won't work properly.
ASKER
OK suddenly everything is working! I can't get it into world mode because everytime I use the country code for the United States it tells Can't find Country code of World mode. I'm using Dot11d? I think I"m going to let that go... I'll be closing shortly. I'm going export the config and import it and change the IPs. Thanks so much for ALL of your help.
ASKER
Didn't know exactly what got me to this point actually all the suggestions did it. Thank you so much for all of this help. I wound up using the GUI and got everything working without using Radius. If someone is looking for help read this all and check out the links too.
ASKER