01-26-2009 07:59 AM - edited 03-10-2019 04:18 PM
I have multiple wireless networks. I am building a guest wireless network. I would like to assign a guest a username password. When the guest connects to the SSID (guest network) they are prompted for username password and assigned the correct guest vlan.
I am thinking I should be able to define a unique group in ACS 4.0. The unique group will only be allowed or assigned guest vlan access. Guests to the network will be associated to the guest vlan.
I haven't been able to figure out how to associate a username account with a vlan assignment.
01-26-2009 08:25 AM
I think this might help you:
http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a00808c9bd1.shtml
This uses the group to the vlan assignment but you can certainly assign this Guest user to a Guest Group :)
01-26-2009 09:30 AM
I the found document you referenced earlier. I have read it again and researched a little more. The ACS options the doc references are available in ACS v4.1. I am running v4.0. Options such as Cisco Airspace Radius and Aironet Radius are not available in v4.0.
v4.0 has Cisco IOS Radius Attriutes (sub category - cisco-av-pair) and IETF Radius attributes. There are others but I can't help but think these categories might be used to solve my problem.
01-26-2009 09:32 AM
I believe that as long as you use Radius IETF you will be ok with using this link. Why don't you give it a shot
01-26-2009 09:59 AM
01-26-2009 10:05 AM
Ok, I think I did not explained myself.
ACS uses a type of radius to define its aaa client, in the case of using wireless controller, you would tipically define Aironet Radius type. This will enable you some of the wireless attributes. Now since your ACS does not support and contain the Aironet Wireless Radius Attributes, first you would need to define your AAA client (access point or wireless controller) with the IETF Radius client attributes.
Then using Cisco Vendor Specific Attributes you can define Vlan type and all of the attributes that the document uses.
If this is too complex or confusing, you can always contact the TAC to get assistance on this.
01-26-2009 10:10 AM
Thanks for the help. I should (and will) probably open a case.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: