NAC Wireless SSO

Unanswered Question
Oct 9th, 2008

We are trying to setup Cisco NAC on our wireless and we are unable to get Wireless SSO working with our Wireless Control System and WiSMs.

We have WPA2 with 802.1X working and we have NAC working, currently without the agent. But after authenticating for wireless we get the web login page from the NAC.

I've tried to follow the documentation from the NAC guide and NAC Cisco Press book, but their instructions are confusing and vague.

Currently we have the NAM pointing to the ACS for its RADIUS authentication and accounting servers. We have the WiSMs added to NAC as VPN concentrators and pointing to the NAS for RADIUS accounting servers. The WiSM are configured to use the ACS for its RADIUS authentication server.

I've tried setting up the accounting mapping on the NAS for the VPN concentrators to use the NAS itself as the accounting server and I've tried using the ACS for the accounting server, but no luck with either configuration.

Does anyone have experience on this configuration and might have an idea on the correct configuration or tips on troubleshooting?

Thanks in advance,

Joe

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
c2jkeegan Wed, 10/15/2008 - 07:18

Just in case anyone else has the same issue, there was two things we needed to do to solve this issue.

First RADIUS accounting only runs on the active node of the NAS, so point the WiSMs to the NAS VIP for the cluster.

We Also needed to add Cisco VPN SSO as an authentication server.

Actions

This Discussion