cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
500
Views
5
Helpful
5
Replies

Restrict the use of a particular EAP method to a SSID

claeysg
Level 1
Level 1

Hello,

I use a WLC and Cisco radius ACS.

I have two SSIDs, one for the IP phones using LEAP and one for the computers using PEAP. To authenticate on both SSIDs, I use the same username and password, only the EAP methods used is different.

My problem is that both EAP methods can be used to access to each SSID (LEAP or PEAP).

Is there any way to restrict the use of a particular EAP method to an SSID ?

Is it possible with the Cisco ACS ? Indeed, EAP methods are globally defined.

Thanks for your help,

Gaetan

5 Replies 5

Hi

We have exactly the same problem with IP phones and clients. We have 3 SSID's and would also like to use the two different EAP methods (LEAP and PEAP) on 1 ACS. How did you configure the ACS to support 2 EAP-Methods for 1 WLC?

Thanks in advance

Dominic

You can use NAP with ACS 4.0.

you filter the profile based on called-station-id and this way you can restrict the type of eap.

cheers,

Thanks a lot. We just installed ACS 4.1 (we had 3.2) so we couldn't configure NAP before.

Not applicable

Not applicable

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card