Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

NAC integration with WLC

Any doc on implementing inband wireless with NAC?

Lets say 2 SSIDs. 1 staff that has 30 networks based on 30 locations and 1 guest network for all locations. The Controller is trunked to the switch. How do u force the traffic to go to CAS?

Thanks in advance!

2 REPLIES
New Member

Re: NAC integration with WLC

Hi, found this link, may be of some use:

http://www.cisco.com/en/US/docs/wireless/technology/clean_access/technical/reference/cleanAN.html

Can you let me know how it goes? Have to deploy a similar solution in a couple of weeks!

Hall of Fame Super Silver

Re: NAC integration with WLC

In-Band Virtual Gateway is the recommended configuration. What you have in the link is In-Band Real IP. You can use either one... with real ip you will need static routes. In IN-Band virtual gateway, the NAC will bridge the traffic from the untrusted to the trusted.

Basically the ssid is mapped to a vlan like 50 and that is passed onto a dot1q trunk to the switch. Vlan 50 is not routed and the only other port on vlan 50 is the untrusted port on the CAS. The CAS then bridges that to... lets say vlan 51 which is routed on the network.

Every time I have to deploy one of these, it still confuses me somewhat... So hope this doesn't confuse you.

-Scott
*** Please rate helpful posts ***
158
Views
5
Helpful
2
Replies