Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

FlexConnect Group Radius

All of our FlexConnect AP's from remote campuses connect to central WLC, so they share the same config for everything (SSID, Radius, etc).

We're about to test our ISE deployment, and need to selectively have a subset of remote sites' AP's use different set of Radius (ISE) servers from the rest.

How can we achieve this? Through FlexConnect Groups?

Looking at the config guide, it says "These servers can be used when the FlexConnect access point is in of these two modes: standalone or connected."

http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010001111.html#ID1255

 

Does this mean whatever Radius servers we define under FlexConnect groups over-ride the global config?

Are these Radius servers under FlexConnect groups used by ALL of the SSID's?

What if we have multiple SSID's, and some of them need to point to the original Radius servers that are globally defined, and some need to point to the ISE servers as a test?

2 REPLIES
Bronze

Hi,Yes, you can configure in

Hi,

Yes, you can configure in this way that your FlexConnect AP group authenticate from any backup server, these servers can be used when the FlexConnect access point is in of these two modes: standalone or connected.

And yes, it will over-ride the global config whatever Radius servers we define under FlexConnect groups.

You have to make group of those APs whom you want to authenticate from primary radius server.

New Member

Hi Did it work for you...? I

Hi Did it work for you...? I have created a flexconnect Group and put my ap in it and configure local radius server which is a ISE PSN node locally available in Branch. But still authentication goes to centralized ISE PSN. I am unable to get it working.

62
Views
0
Helpful
2
Replies