EasyManuals Logo

Cisco SD2008T-NA User Manual

Cisco SD2008T-NA
406 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #35 background imageLoading...
Page #35 background image
1-13
Cisco Wireless LAN Controller Configuration Guide
OL-9141-03
Chapter 1 Overview
Identity Networking
VLAN, access control list (ACL), DHCP server, and physical port assignments. This MAC Filtering can
be used as a coarse version of AAA Override, and normally takes precedence over any AAA (RADIUS
or other) Override.
However, when Allow AAA Override is enabled, the RADIUS (or other AAA) server can alternatively
be configured to return QoS
, DSCP, 802.1p priority tag values and ACL on a per-MAC Address basis.
Allow AAA Override gives the AAA Override precedence over the MAC Filtering parameters set in the
controller; if there are no AAA Overrides available for a given MAC Address, the operating system uses
the MAC Filtering parameters already in the controller. This AAA (RADIUS or other) Override can be
used as a finer version of AAA Override, but only takes precedence over MAC Filtering when Allow
AAA Override is enabled.
Note that in all cases, the Override parameters (Operator-Defined Interface and QoS, for example) must
already be defined in the controller configuration.
In all cases, the operating system will use QoS
, DSCP, 802.1p priority tag values and ACL provided
by the AAA server or MAC Filtering regardless of the Layer 2 and/or Layer 3 authentication used.
Also note that the operating system only moves clients from the default Cisco UWN Solution WLAN
VLAN to a different VLAN when configured for MAC filtering, 802.1X, and/or WPA Layer 2
authentication. To configure WLANs, refer to Chapter 6.
Enhanced Integration with Cisco Secure ACS
The identity-based networking feature uses authentication, authorization, and accounting (AAA)
override. When the following vendor-specific attributes are present in the RADIUS access accept
message, the values override those present in the wireless LAN profile:
QoS level
802.1p value
VLAN interface name
Access control list (ACL) name
In this release, support is being added for the AAA server to return the VLAN number or name using the
standard “RADIUS assigned VLAN name/number” feature defined in IETF RFC 2868 (RADIUS
Attributes for Tunnel Protocol Support). To assign a wireless client to a particular VLAN, the AAA
server sends the following attributes to the controller in the access accept message:
IETF 64 (Tunnel Type): VLAN
IETF 65 (Tunnel Medium Type): 802
IETF 81 (Tunnel Private Group ID): VLAN # or VLAN Name String
This enables Cisco Secure ACS to communicate a VLAN change that may be a result of a posture
analysis. Benefits of this new feature include:
Integration with Cisco Secure ACS reduces installation and setup time
Cisco Secure ACS operates smoothly across both wired and wireless networks
This feature supports 2000, 2100 and 4400 series controllers and 1000, 1130, 1200 and 1500 series
lightweight access points.

Table of Contents

Other manuals for Cisco SD2008T-NA

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco SD2008T-NA and is the answer not in the manual?

Cisco SD2008T-NA Specifications

General IconGeneral
BrandCisco
ModelSD2008T-NA
CategoryExtender
LanguageEnglish

Related product manuals