Pasul 2. Configurare controler WiFi 9800
În acest pas vom configura controlerul WiFi 9800 pentru a solicita autorizarea către ISE pentru comenzile primite.
În CLI vom introduce următoarele comenzi:
WLC9800-demo(config)#aaa authorization config-commands
WLC9800-demo(config)# aaa authorization commands 15 Autorizare group TacacsRares
WLC9800-demo(config)#aaa accounting commands 15 Autorizare start-stop group TacacsRares
WLC9800-demo(config)#line vty 0 15
WLC9800-demo(config-line)#authorization commands 15 Autorizare
Configul pe WLC arată ca în imaginea de mai jos pentru AAA și pentru liniile virtuale:
WLC9800-demo#show run | s aaa
aaa new-model
aaa group server radius RADIUS-GROUP
server name ISE-demo
deadtime 5
aaa group server tacacs+ TacacsRares
server name ISE-Tacacs
aaa authentication login default local
aaa authentication login Autentificare local group TacacsRares
aaa authorization config-commands
aaa authorization exec default local
aaa authorization exec Autorizare local group TacacsRares
aaa authorization commands 15 Autorizare group TacacsRares
aaa accounting commands 15 Autorizare start-stop group TacacsRares
aaa accounting network RaresAccounting start-stop group RADIUS-GROUP
aaa server radius dynamic-author
client 172.20.16.100 server-key Cisco123
aaa session-id common
ip http authentication aaa login-authentication Autentificare
ip http authentication aaa exec-authorization Autorizare
snmp-server enable traps aaa_server
wireless aaa policy default-aaa-policy
WLC9800-demo#show run | s vty
line vty 0 4
authorization commands 15 Autorizare
authorization exec Autorizare
login authentication Autentificare
length 0
transport input ssh
line vty 5 15
authorization commands 15 Autorizare
authorization exec Autorizare
login authentication Autentificare
transport input ssh