What is best resource for steps to implement 802.1x on ICX7450 and SmartZone
WLAN
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-15-2019 05:38 AM
Goal --> implement 802.1x configuration on ICX Switches/WLAN to support 802.1x Authentication for SmartZone WLAN users.
Currently, users are directed to WebAuth Page where login credentials are Authenticated by RADIUS.
Need to ensure proper configurations are applied and VLANs are available on ICXs/WLAN for initial login and Authenticated user connections
Currently, users are directed to WebAuth Page where login credentials are Authenticated by RADIUS.
Need to ensure proper configurations are applied and VLANs are available on ICXs/WLAN for initial login and Authenticated user connections
9 REPLIES 9
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-15-2019 03:00 PM
Couple of questions? Are you wanting to do 802.1x auth on the ICX and on your WLAN's?
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-16-2019 08:51 AM
Tim,
Currently utilizing NPS to perform RADIUS Auth for ICXs and RADIUS works with WLAN WebAuth.
Trying to get 802.1x Auth working for WLANs
Currently utilizing NPS to perform RADIUS Auth for ICXs and RADIUS works with WLAN WebAuth.
Trying to get 802.1x Auth working for WLANs
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-16-2019 03:14 PM
Very common thing to setup. Since you are using NPS you should have a handle on that except that depending on how you configure it each radio is a client or the controller is the client in NPS. We usually add each radio or the subnet that the radios are on for management as the client. 
Then create a connection request policy. Overview tab is a name and the rest default then the conditions tab is as follows.

The settings tab is default except for the authentication methods.
If you edit the EAP type then you can select the certificate to use.

On the VSC or SZ controller it looks like this. Create a Radius Server Connection under Services/Profiles/authentication.

Create a WLAN that uses 802.1x. The picture in this one is named cloupath but disregard as it is one I use for testing lots of different things.
You have to watch your logs on the NAP server to see what might be happening if the clients are not able to connect. If the NAP log shows nothing it might have to be enabled.
auditpol /set /subcategory:"Network Policy Server" /success:enable /failure:enable
Sometimes the local policy has issues and it can be found here to enable the NAP logging.
The success/failure setting can be found at Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> Audit Policies -> Logon/Logoff -> Audit Network Policy Server.
Then create a connection request policy. Overview tab is a name and the rest default then the conditions tab is as follows.
The settings tab is default except for the authentication methods.
If you edit the EAP type then you can select the certificate to use.
On the VSC or SZ controller it looks like this. Create a Radius Server Connection under Services/Profiles/authentication.
Create a WLAN that uses 802.1x. The picture in this one is named cloupath but disregard as it is one I use for testing lots of different things.
You have to watch your logs on the NAP server to see what might be happening if the clients are not able to connect. If the NAP log shows nothing it might have to be enabled.
auditpol /set /subcategory:"Network Policy Server" /success:enable /failure:enable
Sometimes the local policy has issues and it can be found here to enable the NAP logging.
The success/failure setting can be found at Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Advanced Audit Policy Configuration -> Audit Policies -> Logon/Logoff -> Audit Network Policy Server.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-16-2019 03:23 PM
Here is a youtube from Ruckus that covers it on a ZD and 2012R2 NAP.
https://www.youtube.com/watch?v=QlL777qF95s
https://www.youtube.com/watch?v=QlL777qF95s
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-18-2019 05:37 AM
Thank you Tim B. Just now seeing your Post -

