cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
462
Views
5
Helpful
1
Replies

Guest WLAN Authentication Issue

ejjacobs63
Level 1
Level 1

We recently added a guest WLAN to our 4402 controller and have successfully created and used "guest accounts". The issue we are having is our corporate users can connect to the guest WLAN and use their credentials to authenticate to the guest WLAN. Is there a way to limit Web Authentication to not utilize our ACS in addition to the local user name/password accounts created on the WLC?

1 Accepted Solution

Accepted Solutions

Scott Fella
Hall of Fame
Hall of Fame

What you need to do is create 3 bogus radius servers and then on the guest wlan ssid, point the 3 bogus radius servers on that. This will prevent the internal users from authenticating to the correct radius server. If you need to know.... the WLC will look up the local account first and if there is no valid username and password, then the wlc will automatically look at the radius servers setup on the wlan. If no radius server are defined, then the wlc will look at the other radius servers configured on the wlc.

Hope this helps.

-Scott
*** Please rate helpful posts ***

View solution in original post

1 Reply 1

Scott Fella
Hall of Fame
Hall of Fame

What you need to do is create 3 bogus radius servers and then on the guest wlan ssid, point the 3 bogus radius servers on that. This will prevent the internal users from authenticating to the correct radius server. If you need to know.... the WLC will look up the local account first and if there is no valid username and password, then the wlc will automatically look at the radius servers setup on the wlan. If no radius server are defined, then the wlc will look at the other radius servers configured on the wlc.

Hope this helps.

-Scott
*** Please rate helpful posts ***
Review Cisco Networking products for a $25 gift card