Re: [WIRELESS-LAN] Link LDAP groups to Separate SSIDs for Authentication

2011-01-24 Thread Sam Stelfox
While you are correct about the 1500 result limit, this shouldn't be an issue with wireless authentication as the radius server will only query for the username requesting authentication. This works fine even with >4000 members in a group (we have this working right now). On 01/22/2011 06:21 A

RE: [WIRELESS-LAN] Link LDAP groups to Separate SSIDs for Authentication

2011-01-24 Thread Osborne, Bruce W
If you use AD groups to determine any access restrictions / vlans (Student vs. staff vs. IS Admins, etc.) then this can be an issue. It works with NPS Server (Sorry for the original typo). Bruce From: Sam Stelfox [mailto:sstel...@vtc.vsc.edu] Sent: Monday, January 24, 2011 9:02 AM To: The EDUCA

Re: [WIRELESS-LAN] Link LDAP groups to Separate SSIDs for Authentication

2011-01-24 Thread Dennis Xu
You should be able to do this with ACS 5(if your LDAP can return different groups for student and faculty/staff). You can create following rules: 1. If "wireless SSID(with Cisco WLC, it is called-station-id) == open SSID" and "LDAP.Group == Student", then Permit_Access. 2. If "wireless SSID(with

RE: Link LDAP groups to Separate SSIDs for Authentication

2011-01-24 Thread Pham, Loc
Hello Bruce, I am not much of a MS guy anymore: any link to this limitation/document ? Loc UCSF Medical Center From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Osborne, Bruce W Sent:

RE: Link LDAP groups to Separate SSIDs for Authentication

2011-01-24 Thread Chad Burnham
HI Bill, I wanted to make you aware of http://www.open.com.au/radiator/ - great product for complex proxy situations. I realize this would mean ditching your ACS. CB From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of

Re: [WIRELESS-LAN] Link LDAP groups to Separate SSIDs for Authentication

2011-01-24 Thread Kenneth Marshall
On Mon, Jan 24, 2011 at 01:41:31PM -0700, Chad Burnham wrote: > HI Bill, > > > I wanted to make you aware of http://www.open.com.au/radiator/ - great > product for complex proxy situations. I realize this would mean ditching > your ACS. > > > > CB > > A nice alternative to radiator is fr