cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1582
Views
6
Helpful
3
Replies

lwapp capwap AP to act as a supplicant on a 802.1x enabled switch port

Hi

All our switchports is configured to validate the connected device with 802.1x

However when a wireless accesspoint, that is running FlexConnect, is connected I have to make a "mac bypass" on the AP mac addess and add the multihost command to the port config.

I really like to move away from the mac bypass, but keep the multihost command, and install a certificat on the AP. Have anyone any ideas about how to get the AP itself to auth?

1 Accepted Solution

Accepted Solutions

Scott Fella
Hall of Fame
Hall of Fame

There isn't a way to have an AP authenticate on a switchport setup for 802.1x. Mac bypass is the only way. Like on ISE, the switch can detect it's an access port and or phone and reconfigure the switchport for that type of device. Normal 802.1x on a switchport will not work for an AP.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

View solution in original post

3 Replies 3

Scott Fella
Hall of Fame
Hall of Fame

There isn't a way to have an AP authenticate on a switchport setup for 802.1x. Mac bypass is the only way. Like on ISE, the switch can detect it's an access port and or phone and reconfigure the switchport for that type of device. Normal 802.1x on a switchport will not work for an AP.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

Amjad Abdullah
VIP Alumni
VIP Alumni

Hi,

The AP can act as 802.1x supplicant if it is connected to a 802.1x enabled switch port.

Cisco unified APs however supports only EAP-FAST as the EAP method.

Here is a config example, hope it'll be useful.

http://goo.gl/HMbiHL

Regards,

Amjad

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"

This is the correct answer.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card