When you user site configuration with local RADIUS authentication, the authenticator is moved to the AP, not the controller. (as you can see in the screenshot REN1AIR000x are APs Name)
![51b9f83325f5476a9d54e9f6f384492c_RackMultipart20171129-74108-1q4p3an-2017-11-29_12-43-30_inline.png 51b9f83325f5476a9d54e9f6f384492c_RackMultipart20171129-74108-1q4p3an-2017-11-29_12-43-30_inline.png](/t5/image/serverpage/image-id/387i9AC52E77F65D3283/image-size/large?v=v2&px=999)
but it this case, if AP are counted as devices in NMS, the licensing price will be huge (customer got around 300 AP on multiple site)
I hope there is a way to make the AP count from AP license count and use local radius authentication.
We need this design to deliver local authentication (local NAC Gateway& Active Directory) because of multiple factor:
- bad WAN links causing authentication stale or failure
- some remote site with over 2000 users with lot of connection/disconnection (app testing purpose)