Soru

Zorluk: Çok zorWireless LAN Client Connectivity Configuration via WLC GUI

A network administrator configures a WPA2-Enterprise wireless network on a Cisco Wireless LAN Controller (WLC) GUI. On the WLANs > Edit page, the administrator sets the Interface/Interface Group on the General tab to a default VLAN dynamic interface, configures RADIUS authentication under the Security > AAA Servers tab, and confirms 802.1X Key Management under the Security > Layer 2 tab. During testing, wireless clients successfully authenticate against the external RADIUS server, but all clients are assigned to the default dynamic interface specified on the General tab rather than the individual per-user VLAN IDs returned in the RADIUS server IETF attributes (Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID). Which GUI configuration change on the WLC is required to enforce the dynamic VLAN assignments supplied by the RADIUS server?

  1. Navigate to the Advanced tab of the WLAN edit page and enable the Allow AAA Override option.Cevap
  2. B
    Navigate to the Security > Layer 3 tab and enable RADIUS Web Authentication.
  3. C
    Navigate to the General tab and set the Radio Policy option to FlexConnect Local Switching.
  4. D
    Navigate to the Security > Layer 2 tab and select Native VLAN Tagging under WPA2 Parameters.

Cevap

Enable the Allow AAA Override option under the Advanced tab of the WLAN configuration page on the WLC GUI.
On a Cisco WLC, the 'Allow AAA Override' setting on the WLAN's Advanced tab must be enabled for the controller to accept client-specific attributes returned by a RADIUS server during 802.1X authentication. Without this setting checked, the WLC ignores RADIUS IETF attributes (such as Tunnel-Private-Group-ID for dynamic VLAN placement) and forces all authenticated clients onto the static interface configured on the WLAN's General tab.

Adım Adım Çözüm

1
Analyze the client connectivity issue.
802.1X authentication succeeds, but RADIUS-supplied attributes (VLAN IDs) are ignored, defaulting clients to the WLAN's mapped interface.
By default, Cisco WLC ignores user-specific AAA parameters returned in RADIUS Access-Accept messages unless explicitly configured to apply them.
2
Locate the required configuration feature in the WLC GUI.
Identify that feature overrides (AAA Override) reside under WLANs > Edit > Advanced tab.
The Advanced tab controls policy override capabilities, including Allow AAA Override, Coverage Hole Detection, and Client Band Select.
3
Enable 'Allow AAA Override'.
The WLC overrides the default dynamic interface on the General tab with the RADIUS IETF attributes 64 (Tunnel-Type), 65 (Tunnel-Medium-Type), and 81 (Tunnel-Private-Group-ID).
This setting instructs the controller to dynamically place authenticated clients into their assigned VLANs based on RADIUS authorization profiles.

Anahtar Kavram

WLAN AAA Override Configuration for Dynamic RADIUS VLAN Assignment via WLC GUI
Bu soruyu puanla