Solved

RADIUS with multi SSID's on same AP (RADIUS Client)

Posted on 2016-08-17
4
22 Views
Last Modified: 2016-08-18
Good morning Experts,

We have an Ubiquiti wireless network system, the AP's give out multiple wireless networks, each one using a different VLAN for pointing guest networks out on a separate ADSL connection, and corporate networks using another VLAN which is part of our corporate network.

I have just about managed to work out how to set up RADIUS authentication on these AP's (Clients) ... but I am wondering if it is possible to configure separate network policies and rules, for each different wireless network?

This might be a straight 'No' but I just would like someone else's opinion.

Thanks
0
Comment
Question by:Nathan Lindley
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 46

Expert Comment

by:Craig Beck
ID: 41759853
Of course you can do that. Just create a condition that matches your SSID for each policy. Your APs or WLC will need to send the "Called-Station" attribute which is formatted as "Client-MAC:SSID" to the RADIUS server.

If your APs or WLC supports the "NAS-ID" attribute per SSID you could use that as a condition, which is easier.
0
 

Author Comment

by:Nathan Lindley
ID: 41760752
Hi Craig,

When you say 'create a condition' do you mean create a Network Policy with the same name as the SSID?

And where would I specify the 'Called-Station' attribute? Sorry I am a complete beginner when it comes to setting up RADIUS.

Here is a screen shot of the configuration options I have on a test wireless network i set up on our AP's management console.

wireless-config.PNG
Thanks
0
 

Author Comment

by:Nathan Lindley
ID: 41760818
Craig, I've done a bit more reading into this since my last comment, and found where to specify VLAN info instead.

vlan.PNG
However, when my computer connects to the network, it is not picking up the VLAN 8 which was specified. Any tips?

thanks
0
 
LVL 46

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 41761161
If you do VLAN assignment via RADIUS you only need one SSID. The RADIUS policy tells the WLC which VLAN to put the client on. You need to untick the VLAN ID box in the SSID config though and in some cases the WLC might need to be told to use the VLAN attributes that you configured in the RADIUS profile.
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Need WiFi? Often, there are perfectly good networks that don't have WiFi capability - and there's a need to add it.  - Perhaps you have an Ethernet port into a network but no WiFi nearby. - Perhaps you have a powerline extender and no WiFi at the…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…

634 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question