View Single Post
  #4 (permalink)  
Old 07-27-2005, 08:25 PM
aaron@cisco.com
Guest
 
Posts: n/a
Default Re: aaa authorization and aaa accounting with Cisco ACS and 1231 AP's

> Thanks for clarifying that for me Aaron, I had my suspicions that it
> may be something like that as I had exhausted all avenues of
> investigation.


> I am assuming that tacacs+ will not poeform the task either ?


I don't think you can authenticate wireless EAP clients against
Tacacs+, only RADIUS, but in any case, this has nothing to do with
the AAA protocol used between the AP and the AAA server, but
with the capabilities of the AP to assign an address to the wireless
client.

> The reason I looked into this originally was because I need to hand
> out IP addresses on a per vlan basis but when I have set up a lab with
> diferent (physical) dhcp servers connected to their coresponding vlans
> the clients don't always get the right address.


I don't know why your DHCP servers didn't assign the right addresses
- this should not be a problem. I'd recommend that you focus on fixing
this configuration.

Btw, one thing you *can* do is to have ACS assign a wireless client
to a VLAN on a per user basis. This flexibility is useful to some.
Of course, you still have to have DHCP working right on the VLANs.

Regards,

Aaron


Reply With Quote