Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 

Dynamic ACL with PEAP-MSCHAPv2 and EAP-TLS

Hi All..

Using WLC 4.0.171.0 with a WPA / 802.1x SSID, backing off to ACS SE v4.1, which backs off to Win2k3 domain.

The SSID utilises the AAA Override function, which is used to apply Access Control Lists. The ACLs change dependent upon whether a Machine Account or User Account is used to log in.

All of this works brilliantly with PEAP-MSCHAPv2, but when EAP-TLS (using machine cert / user smartcard) is used, the ACL doesn't seem to change.

ACS logs the authentication as being successful in both circumstances, and both EAP types are allowed on ACS, so I'm thinking that either;

(A) There's a bug on ACS?

or

(B) That the WLC is misbehaving?

Finally, is there a WLC command that allows me to see what ACLs are actually applied to what user? This would allow me to see if the WLC is actually changing the ACL, or not.

Thanks all,

Richard..

1 REPLY
Community Member

Re: Dynamic ACL with PEAP-MSCHAPv2 and EAP-TLS

Becuase EAP-TLS doesnt have username or password but contians only with certificates it will not work. PEAP has an option for using username and passwords.

272
Views
0
Helpful
1
Replies
CreatePlease to create content