Jump to content


0

vWlc and Radius not working correctly

vwlc radius 802.1X

No replies to this topic

#1 Paul279

Paul279

    Junior Member

  • Members
  • PipPip
  • 4 posts
  • 354 thanks

Posted 30 July 2015 - 12:54 AM

Hello community

I need your help please ;-)
I have a vWLC (version 8.1.102.0).
I have configured an interface called office10 172.19.19.0 /24 (this is my office network)
My management network is 192.168.200.0 /24 (for all APs)

I configured a network called "NormalOffice" with an interface/interfaceGroup "office10"(office network) and an preshared key.

Now when the clients connect to this network with the preshared key they get an ip address from my dhcp server from the network 172.19.19.X.
Great it is working as it should.

Now I want to set-up a wireless network with an authentication from my Radius server:
I followed this instructions from here to set-up a radius server: http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/115988-nps-wlc-config-000.html
I configured a Radius server on WINServer2012R2. Installed certificate, configured NPS like in the tutorial above.
Now on the vWLC I created a second wireless network called "RadiusOffice". Made the same settings like in the tutorial.
Layer 2 security: WPA + WPA2 plus authentication 802.1X. Interface group is also set to office10 like in my first network (NormalOffice)

The problem is now when the clients connect I get an ip address from my management network (192.168.200.X) and not from my office network.

1. What do I have to configure that my clients get a office ip address and not an ip from my management network?
2. What I don`t understand from the tutorial is, that he configures the wireless network to Layer2 security WPA+WPA2 plus authentication
802.1X. But why doesn`t he only change the Layer2 security to 802.1X?

Thank you for your help
Paul

//Edit in Windows Server NPS Policy I also configured the VLAN attributes for the cisco wlc, but my clients get still an ip address from the same network of my access points.
https://technet.microsoft.com/en-us/library/Cc754422%28v=WS.10%29.aspx?f=255&MSPPError=-2147217396

I got the information that I need FlexConnect groups.
I made one but here are some pictures, I think than it is easier to see what I did:

Attached Files

  • Attached File  3.PNG   7.98K   18 downloads
  • Attached File  2.PNG   13.39K   9 downloads
  • Attached File  1.PNG   22.37K   6 downloads
  • Attached File  4.PNG   10.54K   3 downloads
  • Attached File  5.PNG   43.98K   5 downloads
  • Attached File  6.PNG   11.39K   4 downloads
  • Attached File  7.PNG   14.53K   2 downloads
  • Attached File  8.PNG   18.92K   9 downloads

Edited by Paul279, 03 August 2015 - 09:08 AM.


Thanked by 1 Member:
rolij



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Organization

Community

Downloads

Test Providers

Site Info


Go to top