Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Users might experience few discrepancies in Search results. We are working on this on our side. We apologize for the inconvenience it may have caused.
New Member

AAA Clients in a WDS infrastructure

Dear All, we have a Cisco WDS infrastructure with an ACS Radius Server. Do we have to add all infrastructure APs as AAA-Clients in ACS or should we only define the WDS Master AP and the WDS Backup AP as AAA-Clients ?

We thought it's better to add all APs as AAA-Clients for the Case the WDS devices should fail. Then the APs can authenticate against ACS directly. Is that reasoning correct ? Thanks.


Re: AAA Clients in a WDS infrastructure

You will only have to add the WDS devices themselves and not the infrastructure AP's. Basically the infrastructure AP's are authenticating to the WDS as clients, same as a wireless client would authenticate to the AP. The active WDS will be the only AP that will talk directly to the Radius server. All client authentications will be forwarded from the infrastructure AP to the WDS and then sent on to the Radius server.

New Member

Re: AAA Clients in a WDS infrastructure

Dear dancampb,

thanks for your reply. Just one more question on this:

Suppose the WDS AP fails (and no backup WDS device exists)- then the complete WLAN would be dead because all the other APs can't forward AAA-requests to the Radius Server. Is that correct ?

Wouldn't it make sense to additionally define the APs as AAA-Clients on the Radius Server and enable AP Authentication to make sure that the APs will be authenticated as well either way (either through WDS or directly by the Radius Server in case WDS fails) ? Thanks to all for your appreciated feedback in this conceptional matter.

CreatePlease to create content