Solved

RADIUS with multi SSID's on same AP (RADIUS Client)

Posted on 2016-08-17
4
19 Views
Last Modified: 2016-08-18
Good morning Experts,

We have an Ubiquiti wireless network system, the AP's give out multiple wireless networks, each one using a different VLAN for pointing guest networks out on a separate ADSL connection, and corporate networks using another VLAN which is part of our corporate network.

I have just about managed to work out how to set up RADIUS authentication on these AP's (Clients) ... but I am wondering if it is possible to configure separate network policies and rules, for each different wireless network?

This might be a straight 'No' but I just would like someone else's opinion.

Thanks
0
Comment
Question by:Nathan Lindley
  • 2
  • 2
4 Comments
 
LVL 45

Expert Comment

by:Craig Beck
ID: 41759853
Of course you can do that. Just create a condition that matches your SSID for each policy. Your APs or WLC will need to send the "Called-Station" attribute which is formatted as "Client-MAC:SSID" to the RADIUS server.

If your APs or WLC supports the "NAS-ID" attribute per SSID you could use that as a condition, which is easier.
0
 

Author Comment

by:Nathan Lindley
ID: 41760752
Hi Craig,

When you say 'create a condition' do you mean create a Network Policy with the same name as the SSID?

And where would I specify the 'Called-Station' attribute? Sorry I am a complete beginner when it comes to setting up RADIUS.

Here is a screen shot of the configuration options I have on a test wireless network i set up on our AP's management console.

wireless-config.PNG
Thanks
0
 

Author Comment

by:Nathan Lindley
ID: 41760818
Craig, I've done a bit more reading into this since my last comment, and found where to specify VLAN info instead.

vlan.PNG
However, when my computer connects to the network, it is not picking up the VLAN 8 which was specified. Any tips?

thanks
0
 
LVL 45

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 41761161
If you do VLAN assignment via RADIUS you only need one SSID. The RADIUS policy tells the WLC which VLAN to put the client on. You need to untick the VLAN ID box in the SSID config though and in some cases the WLC might need to be told to use the VLAN attributes that you configured in the RADIUS profile.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Is your computer hacked? learn how to detect and delete malware in your PC
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question