Link to home
Start Free TrialLog in
Avatar of WellingtonIS
WellingtonIS

asked on

Radius Server

I need to build a 2003 Server with Radius on it. Can someone recommend software for this project. I looked into Cisco ACACS but thats extremely expensive.  I basically need it for 12 access points.
SOLUTION
Avatar of Jakob Digranes
Jakob Digranes
Flag of Norway image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of WellingtonIS
WellingtonIS

ASKER

I have Cisco Aeronet AP 1131AG access points. I'm going to try this.. thanks.
How do you setup SSIDs?
Can this do wpa2?
WPA2 - encryption is handled by the Access Point, and dependent on firmware on AP - most likely you have this ability...
And give that clients are at least XP SP2
OK I have a radius server set up.  I'm using the Aironet 1130 ag I can get the access point to the server but I can't figure out how to get WPA2 installed.  Can this even be done?  According to Cisco it can but how??
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Yes he is correct.  I did get it to work with only 1 wpa2.  My challenge is added the rest.  When I do that  i lose the clients.
got this set up so far 1 vlan the test pc is connect but I can't get an IP address.  what am I doing wrong?
Can you post an IAS event from the Security log on the server?
Here ya go.  It authenticates but it only gets a 169 address...  I did exactly what the instructions said. It's on VLAN 7 but its not finding DHCP
log.png
That's not the IAS security events.  That's the AP log.

However you're not even using RADIUS - The client authenticated using PSK.

Can you post the AP config?
Humm. I have the radius set up in there. Anyway here's t he config.
ap.txt
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
OK so is this the reason i'm not getting an IP from my DHCP server?
Maybe...

If you turn off WPA and just use a wide-open SSID do you get an IP address?

The config doesn't look very clean to me.  Have you edited it in the CLI?
Actually I used the GUI in the AP.
You don't have a native VLAN configured.  The GUI won't let you not select a native VLAN as it relies on it for management.
correct. - so I have to do t hat via command?  If I don't put in a VLAN and just hook up one ssid it works.  SOmething with the VLANS. again connecting to the ap but no IP address.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ok THANKS.  Will try
OK I did that, made the native vlan 7 and I go at least one device connected.  THanks.
Ok that's good... so what you need to do is make the VLAN where the management IP address sits as the native VLAN on the AP, then set up all the other SSIDs and VLANs.
The native VLAN is 3 so I made that the native vlan.  So now I have 2 ssids with security working.  Believe it or not I can't get the guest to work!  that has no security at all.
Check the VLANs...
I did.  I have vlans not communication or  no showing up on  the AP.  One is my guest and one is for what's called an ascom phone.  I'm not sure what's wrong because I'm  basically doing everything the same.  The guest network is open no security - the ascom phone is aes not tpik and wpa2 with a security code.  I'm adding everything but no luck.
Can you post your AP's current config, and switch config.
here you go.  Keep in mind that I did all of these via the GUI on the AP itself.  I checked the switches for the VLAN info and confirmed it's set up correctly.  Vlan 4 and VLan 21 are my "problem" children.
airconfigs.txt
I appreciate that you have checked the switch VLAN info, however I'd still like to see it.

Also, the output you provided is truncated.  I can only see as far as a few subinterfaces on the 2.4GHz radio.  I really need to see all of the config.

Can you disable shared authentication on the Guest SSID?

dot11 ssid GUEST
   vlan 4
   authentication open
  authentication shared
ok took out the shared and I also checked the box Set SSID as guest mode.  Ill get you a better config file.
here's the config exported from the AP.
airconfig.txt
Ok, that looks fine.

So, does the Regi0n@l SSID work?
YEs that's a spectralink phone. The strange thing is if I do a show VLAN I see packets transmitting.  Is it possible just not showing up in the AP?
If you connect the spectralink phone to the Guest SSID does it work?
Can't do that the phone is preprogramed
Ok I need to see the switch config and the following outputs from the switch..

show interface trunk
show vlan brief
The ap doesn't show trunk but I got the vlan...
vlanconfig.txt
I need the SWITCH not AP config and outputs...
ok that may take a bit.  I'll get back to you soon thanks so much for this;..
I know what the problem is with VLAN 21 the ascom phones.  that vlan needs to have world mode enabled.  I see how to do this but It appears that this will be for everyone and I only need this on one vlan.
Don't worry about enabling world mode globally - it just means that auto power levels won't work properly.
OK suddenly everything is working! I can't get it into world mode because everytime I use the country code for the United States it tells Can't find Country code of World mode.  I'm using Dot11d?  I think I"m going to let that go...  I'll be closing shortly.  I'm going export the config and import it and change the IPs.  Thanks so much for ALL of your help.
Didn't know exactly what got me to this point actually all the suggestions did it.  Thank you so much for all of this help.  I wound up using the GUI and got everything working without using Radius.  If someone  is looking for help read this all and check out the links too.