Dynamic ACL with PEAP-MSCHAPv2 and EAP-TLS

Unanswered Question
Jun 27th, 2007
User Badges:
  • Silver, 250 points or more

Hi All..

Using WLC with a WPA / 802.1x SSID, backing off to ACS SE v4.1, which backs off to Win2k3 domain.

The SSID utilises the AAA Override function, which is used to apply Access Control Lists. The ACLs change dependent upon whether a Machine Account or User Account is used to log in.

All of this works brilliantly with PEAP-MSCHAPv2, but when EAP-TLS (using machine cert / user smartcard) is used, the ACL doesn't seem to change.

ACS logs the authentication as being successful in both circumstances, and both EAP types are allowed on ACS, so I'm thinking that either;

(A) There's a bug on ACS?


(B) That the WLC is misbehaving?

Finally, is there a WLC command that allows me to see what ACLs are actually applied to what user? This would allow me to see if the WLC is actually changing the ACL, or not.

Thanks all,


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
lisa.hall Tue, 07/03/2007 - 11:21
User Badges:

Becuase EAP-TLS doesnt have username or password but contians only with certificates it will not work. PEAP has an option for using username and passwords.


This Discussion



Trending Topics: Other Wireless Mobility

client could not be authenticated
Network Analysis Module (NAM) Products
Cisco 6500 nam
reason 440 driver failure
Cisco password cracker
Cisco Wireless mode