Cisco Catalyst 9800 Wireless Controller integration

Overview

The following guide covers Cisco Catalyst 9800 WLAN Controller configurations required to integrate the controller with NAC to be leveraged as an enforcement device. Cisco Catalyst 9800 WLAN controllers running 17.3 or later are supported for centrally switched traffic. Radius Based Enforcement (RBE) is supported for Open networks and for Secure networks using WPA2E/802.1x. By configuring your NAC Enforcer as an Authentication and Accounting Server, creating Access-Lists and leveraging features available in the WLAN controller, NAC will be enabled to block, redirect or limit access based on NAC Policy Group definitions.

Network Preparation and Testing

Prior to integration with NAC, please confirm that the WLANs you will be integrating are fully functional. A simple test of successfully associating with the SSID and browsing to a non-cached website should suffice. Ensure the static route below is added to the Layer 3 routing device upstream of your wireless controller(s). Please contact your Network Specialist if you require assistance with this task.

Static Route (apply if NAC is not integrated with wired network)

XML
Copy

Add NAC Enforcer as a RADIUS Authentication server globally

XML
Copy

ACL Configuration

XML
Copy

Enable Redirection for HTTP or HTTPs

The web admin portal configuration is tied with the web authentication portal configuration and it needs to listen on port 80 in order to redirect. Ensure that you have the command "ip http server" for redirection on HTTP.

If you want to be redirected when you try to access an HTTPs URL, then add the command "intercept-https-enable" under the parameter map:

XML
Copy

Secure WPA2E/802.1X Wireless RBE Configuration

XML
Copy

Open Wireless RBE Configuration

XML
Copy

This completes the WLAN controller configuration. Please run the commands below, and send the results to your NAC Network Engineer for next steps to complete integration validation testing

XML
Copy
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard