cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1101
Views
15
Helpful
4
Replies

Initial configuration of ACS 5.1 for EAP authentication for Wireless clients

vinodjad1234
Level 2
Level 2

Hi,

I have set-up with below devices :

Wireless LAN controller 5508

LAP 3302i

and ACS 5.1

since i am new in ACS 5.1 configuration , I need so information to go ahead to configure ACS 5.1.

which EAP method to use for wireless client authentication ? what is the best practice ?

I have gone through some cisco documents and it shows that best practice is to configure PEAP but for the same , I need to install certificate in ACS server as well in client PC. is that so ?

I have no clear picture for this certificate ?

from where i can get this certificate or do i need to purchase this certificate separately from cisco. how to install it in ACS server ?

I will be obliged to get atleast initial configuration for ACS 5.1 to enable the EAP method,

I need GUI based initial configuration for ACS 5.1

This mentioned ACS 5.1 is installed on ACS 1121 hardware appliance.

4 Replies 4

Tiago Antunes
Cisco Employee
Cisco Employee

Hi,

which EAP method to use for wireless client authentication ? what is the best practice ?

-> I would advise the most widely spread EAP method, which has the best ratio security/easy to deploy: PEAP with MSCHAPv2, which is available by default by all windows machines.

I  have gone through some cisco documents and it shows that best practice  is to configure PEAP but for the same , I need to install certificate in  ACS server as well in client PC. is that so ?

-> You will always need to install a server certificate, however, there is no need for client certificate because the authentication is based on the MSCHAP credentials exchange, not certificate based. The only requirement on the client regarding certificates is the following.

If you want to validate the server certificate, you have to install the server certificate under the trusted CAs of the clients.

If you do not require to trust the server certificate, you can simply disable the option of server certificate validation.

I have no clear picture for this certificate ?

from  where i can get this certificate or do i need to purchase this  certificate separately from cisco. how to install it in ACS server ?

-> The server certificate can be a simple self signed certificate that you generate and install on the ACS GUI.

Please feel free to follow this step-by-step guide on

PEAP under Unified Wireless Networks with ACS 5.1 and Windows 2003 Server:

http://www.cisco.com/en/US/partner/products/ps10315/products_configuration_example09186a0080b4cdb9.shtml or in pdf

http://www.cisco.com/image/gif/paws/112175/acs51-peap-deployment-00.pdf.

HTH,

Tiago

--

If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

Hi,

Thanks for your reply.

I want to go ahead with PEAP-MSCHAPv2 configuration in ACS .

I am sorry to say that still I am somewhat confused that I want to install the certificate in ACS or generate the certificate. why do i need IIS or CA server ?

or do i need external server which is there in domain and configure that same server as CA server and generate the certificate and then upload the same on ACS .

Is that so ?

I tried to generate the certificate from the ACS and copy on local computer with PAK number but still I am no having clear picture ?

Please put light on the same.

I will be really obliged with your valuable knowledge.

Hi,

It is not mandatory to generate certificate from IIS. You can use ACS self signed certificate for PEAP. And the simplest thing is simply to configure the clients to not validate server cert. This way, the clints will trust the ACS self signed certificate.

HTH,

Tiago

--

If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

Hi,

Thanks for your reply and sharing knowledge with me.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: