cancel
Showing results for 
Search instead for 
Did you mean: 

A3 - Eduroam - LADP authentication

A3 - Eduroam - LADP authentication

drthiruna
New Contributor II

Hello there,

In the documentation explained ad A3 performs normal NTLM-based authentication using an AD or LDAP service.

Will A3 performs the authentication against the LDAP for the eduroam?

It the usecase it explained only about the NTLM authentication. Plz confirm me can we do authentication with G-Suite LDAP?

Thiru
3 REPLIES 3

Zdeněk_Pala
Extreme Employee

can you please elaborate more about the use case?

usually the goal is to verify credentials against one destination = either through NTLM to AD or through Radius to Eduroam or through LDAP...

 

Regards Zdeněk Pala

Hi 

NAC can be configured for both local and remote eduroam-related authentication. 

Our users are in Google WS Secure LDAP. Configured the NAC with LDAPs for the 802.1x authentication (EAP-TTLS-PAP) for the local Campus users. We are having a local AD, but no users in the local AD. 

Will NAC do authentication of our local users when they are in remote locations thro eduroam with GWS LDAPs or MS Entra?

In documentation, it's explained as follows: "A3 performs local NTLM authentication and sends the success/failure response back to the eduroam server"

Does it mean we can do only the NTLM authentication?

drthiruna_0-1699530455519.png

In the image the port is shown as 11812. Is it correct?

If I am correct there is no need to configure the Local Connection Profile - eduroam, in case we are doing 802.1x authentication in the campus SSIDs. 

Thiru

Configured the NAC with LDAP for the 802.1x authentication (Wi-Fi) for the Campus users. Roles are configured in the NAC and WLC. 

Our users are in Googlew WS Secure LDAP. 

drthiruna_0-1699347344613.png

Will NAC do authentication for the local users in remote location against the LDAP.

In documenattion it's explained as follows: "A3 performs local NTLM authentication and sends the success/failure response back to the eduroam server"

It means we can do only the NTLM authentication?

Thiru
GTM-P2G8KFN