cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
488
Views
0
Helpful
3
Replies

802.1x and ACS 5.1

Ed Armstrong
Level 1
Level 1

We have been asked to extend an exiting wireless network utilising an ACS 1200 appliance for PEAP MSCHAPv2.  The ACS is currently configured to check a single security group for membership and then grant/deny access.

The customer has supplied 26 OUs across their AD that they would like all members of to be granted access.  Is there an easy, or relatively easy, way to configure this?

3 Replies 3

Scott Fella
Hall of Fame
Hall of Fame

An easy way would be to create a Wireless Group and add all the OU's to that group, then you only have to lookup one group.

Thanks,

Scott

Help out other by using the rating system and marking answered questions as "Answered"

-Scott
*** Please rate helpful posts ***

Scott,

Thanks for the reply.

I thought of using shadow groups with a PowerShell script to update the shadow groups but as my customer is a large multi-national running this type of script would not be acceptable.  Is this what you were thinking or is there a better way to add the OUs a a Wireless group?

I believe that is the only way.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card