Showing posts with label WLC. Show all posts
Showing posts with label WLC. Show all posts

Monday, January 19, 2015

ISE 1.3 + vWLC 7.6 - Basic 802.1x Configuration for Wireless Devices

I have setup ISE 1.3 + vWLC 7.6 in my lab virtually on my UCS server.  Good thing is now ISE 1.3 comes with a OVA, which you can deploy and use immediately without lengthy installation.  It still needs to go through a wizard and need some time to initialize the database, but comparatively easier than pervious release.  vWLC also comes with a evaluation license that you can test things out after you accept the EULA.  Here is a step-by-step guide to configure basic 802.1x authentication for wireless devices using ISE local DB.


1.  Add ISE as Authentication Server, 192.168.24.71 is my ISE IP address.
2. Add ISE as Accounting Server
3. Add a WLAN, the SSID of my testing WLAN is DW-BYOD
Remember to enable AAA Override, choose Radius NAC under NAC state and check DHCP Profiling (this is just used to feed info to my ISE for device profiling).  In my lab I am using FlexConnect local switching therefore you can see I have checked that checkbox.

4.  Create Users on ISE, now I am going to use the ISE local database.

Done!  You should now able to access your SSID using the user credentials that you have created in ISE local database.  

The next post we will go a step further, to configure BYOD with EAP-TLS and self on-boarding capability.

Friday, May 16, 2008

LWAPP Join-Request does not include valid certificate CERTIFICATE_PAYLOAD

If you get this message, 90% of chance you've got the wireless lan controller date wrong. Do a "show time" and you will suprise! I saw that I am in the year of 2029 when I do a "show time" on WLC. Fix it and it will work.

Erase Lightweight access points configuration

Once your lightweight Aironet access points register with the Cisco wireless lan controller, you can't change the ip address and controller information via console. So if you want to move the LWAP from one controller to the other, and if you have static address configured. You will have trouble. To clear the LWAP configuration, you can console to the access point and do the following:

1. Disconnect the ethernet connections
2. "clear lwapp private-config"
3. If you see the errors "ERROR!!! Command is disabled", you still have another way. Do a "debug lwapp console cli"
4. write erase
5. reload