Additional Radius Configuration Options

RADIUS Accounting

RADIUS Accounting, which provides start/stop information and byte counts on the connection, is supported on port 1813.

RADIUS Server VLAN Attributes

When setting up SSIDs in the WLC, you can use VLANS to apply policies for different groups by combining the VLAN in the RADIUS Request as a RADIUS attribute. RADIUS attributes are configured on the certificate template.

VLAN Tagging

The onboard RADIUS server can assign policy information for devices by defining VLAN tags in the certificate template.

If you are using the Microsoft NPS as a RADIUS server, VLAN tags are managed from the NPS.

Certificate Revocation

You can disable network access in Cloudpath by revoking the user or device certificates.

  • When using the NPS acting as your RADIUS server, you can disable the AD account, and because the AD and RADIUS server are tied together, the disabled account status is registered by the RADIUS server.
  • When using the onboard RADIUS server:
    • To disable access for a user, locate the certificates associated with the user account and revoke these certificates in Cloudpath.
    • To disable access for a device, revoke only the certificate associated with the device.