RE: Cisco ISE & FreeRADIUS

2017-08-08 Thread Case, Brandon J
Hi Sean, Our ISE deployment proxies most of our wireless authentications to a load balanced FreeRADIUS setup. It's had its bumps but it's been working well for several semesters now. Where are you running into trouble? Thanks, -- Brandon Case Senior Network Engineer IT Infrastructure Services

RE: Cisco 8540s, and 8.3.102 Code

2016-09-06 Thread Case, Brandon J
We deployed our first 8540s running 8.3.102 and ended up running into CSCva98592. Basically caused both HA peers to crash and reboot simultaneously. Also had problems re-pairing them after bringing the secondary out of maintenance state. We were advised to back down to 8.2.121.9 which is an

RE: [WIRELESS-LAN] Cisco interface groups

2016-08-25 Thread Case, Brandon J
Purdue is an all-Cisco shop and we've been using interface groups for a few years now. We use them our main 1x SSID and also with AAA override on eduroam to put Purdue users into the same set of VLANs as the 1x SSID (consistent access experience). It's worked very well so far. As Timothy said:

RE: Who WiFi vendors does everyone use? REVISITED

2016-04-01 Thread Case, Brandon J
Purdue University ~36,000 unique users per day from ~55,000 unique devices ~8500 Cisco APs (mix of 3500s, 3700s and 702Ws) Controller-based deployment with 3 HA pairs of Cisco 8510s Managed with Cisco Prime 3.0 and home grown tools -Brandon From: The EDUCAUSE Wireless Issues Constituent Group

RE: [WIRELESS-LAN] Who wifi vendors does everyone use?

2016-04-01 Thread Case, Brandon J
Purdue is an all-Cisco shop with about 8500 APs -Brandon -Original Message- From: The EDUCAUSE Wireless Issues Constituent Group Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Todd M. Hall Sent: Friday, April 1, 2016 8:44 AM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU

RE: User and/or Location-based Content Restriction

2016-02-10 Thread Case, Brandon J
Thanks everyone for the great responses and discussion about this. It's still unclear how we'll end up proceeding but all of the feedback from this group has been really valuable! -Brandon -Original Message- From: Case, Brandon J Sent: Monday, February 8, 2016 2:28 PM To: The EDUCAUSE

User and/or Location-based Content Restriction

2016-02-08 Thread Case, Brandon J
Is anyone exploring or able to suggest good options for rate limiting or preventing access to random content services? This idea was posed to me today from up the chain with the goal of limiting certain students' ability to access certain services for a certain time, potentially only from a

It's that time of year...

2015-12-02 Thread Case, Brandon J
The holidays are officially upon us! http://gizmodo.com/can-christmas-lights-really-play-havoc-with-your-wi-fi-1745648879 Has anyone else gotten wind of this yet? Seems to be making the rounds here. Thanks, -- Brandon Case Senior Network Engineer IT Infrastructure Services Purdue University

RE: [WIRELESS-LAN] Cisco WLC w/ ISE and/or Clearpass for Large-Scale Guest Access, MAC exceptions- problems?

2015-10-12 Thread Case, Brandon J
Hi Lee, Here are Purdue we've got a fleet of WLCs, mostly WiSM2s from which we're migrating to 8510s. We have one 8510 dedicated to wireless service in our residence halls. It has around 2400 APs joined to it and I've personally seen the concurrent user count reach over 11k during peak hours.

RE: [WIRELESS-LAN] Handling Non 802.1x Devices on the Enterprise Network

2015-09-01 Thread Case, Brandon J
We are doing pretty much the same thing as well, although without the DHCP tie-in. We set up a separate SSID for gaming consoles/media devices in the residence halls and have students register them via one of ISE's portals. We did set up an authorization policy with a logical profile to

RE: [WIRELESS-LAN] Authentication failures at peak times (Cisco)

2014-09-02 Thread Case, Brandon J
, 2014 at 3:21 PM, Case, Brandon J ca...@purdue.edumailto:ca...@purdue.edu wrote: Would you be able to elaborate on the improvements you did over the summer? We have a similar setup with regards to the backend, although ours is just freeradius - ldap without the F5. Our usage levels are just a bit

RE: Authentication failures at peak times (Cisco)

2014-08-27 Thread Case, Brandon J
Would you be able to elaborate on the improvements you did over the summer? We have a similar setup with regards to the backend, although ours is just freeradius - ldap without the F5. Our usage levels are just a bit higher than yours but we're receiving lots of user reports of the inability to

RE: Cisco WLCs and Client Exclusion

2014-08-21 Thread Case, Brandon J
Listserv [mailto:WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU] On Behalf Of Case, Brandon J Sent: Thursday, August 21, 2014 10:11 AM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: [WIRELESS-LAN] Cisco WLCs and Client Exclusion For the Cisco shops out there: does anyone use Client Exclusion on their 1x WLANs

RE: [WIRELESS-LAN] Eduroam rollout- one more time

2013-11-01 Thread Case, Brandon J
We were in the same spot with #1 and still are (since our main SSID has been .1x for a while). #2 was considered for the briefest of seconds but was quickly surpassed by #3 which was the quickest to implement. We've been happy with the rollout and it's working well. -Brandon From: The

RE: Bandwidth utilization and IOS7 upgrade

2013-09-18 Thread Case, Brandon J
We are. Typical load at this time on a Wednesday is around 1.5Gbps aggregate for our ~22K-ish concurrent users. It's currently cooking along at 2.8Gbps with a very clear jump right around that time. -Brandon From: The EDUCAUSE Wireless Issues Constituent Group Listserv

4G Router Recommendations

2013-02-08 Thread Case, Brandon J
We have a small facility (less than 5 users) located just enough off-campus that some kind of wifi backhaul isn't possible for connectivity. Users at the site want to explore using some kind of 4G device as an uplink. This needs to be coupled with using one of the Cisco OfficeExtend APs as well

RE: [WIRELESS-LAN] Apple attempting to fix their faux-paus

2012-11-16 Thread Case, Brandon J
The newest release of the Apple TV software does support WPA2 Enterprise but, of course, there's a catch. It can't be configured directly from the Apple TV itself. It has to be done using the Apple Configurator software and pushed to the Apple TV via the USB port on the back (at least that was

RE: [WIRELESS-LAN] Cisco 7.3 Code and ISC DHCP

2012-10-17 Thread Case, Brandon J
We had the exact same issue with our old WiSM1s after upgrading the 6500 they were in to 12.2(33)SXI. Apparently when the WiSMs first booted they sent DHCP requests with a blank hostname (although I think these were running something in the 5.2 train or perhaps earlier). 12.2(33)SXH didn't care

Domain Logon Over Wireless

2012-07-30 Thread Case, Brandon J
Has anyone out there tried doing domain logons over a 1x-enabled network? We have a request in from one department (and potentially others) to offer such a service. Their goal is to create learning lab environments where students can use laptops that are dedicated just for the room the lab is

RE: [WIRELESS-LAN] WAPS seem to die after switch reboot

2012-01-11 Thread Case, Brandon J
We're dealing with a similar issue right now too, but it seems to be AP-independent. We have a mix of Cisco 3500's and 1250's running on Cisco 3750EPs (running 12.2(53)SE2) and a sample of each type of AP experience the problem. Our 3750's are Gigabit so I've been using the 'test

RE: NCS 1.0.2.28 (MR2)

2011-11-18 Thread Case, Brandon J
Has anyone who is running MR2 tried to migrate data from WCS 7.0.220.0? The release notes explicitly say it's supported but after a 7 hour wait, I was presented with this message last night: Appliance Restore Process ERROR: invalid backup file version. Exception: 7.0.220.0 is not a

RE: [WIRELESS-LAN] Mac OS 10.6.2 Update

2009-11-10 Thread Case, Brandon J
I applied this update to a Mac as a test client today, and I can confirm that it's still experiencing the same issue as it was pre-patching. Interestingly enough, toggling on broadcast of the SSID results in the client connecting immediately. Disable Airport, disable broadcast, re-enable

Cisco Environment and Apple products

2009-06-16 Thread Case, Brandon J
Is anyone out there a Cisco controller shop that's seeing lots of troubles with Apple products? We're transitioning (still) to an entirely controller-based infrastructure so we have a mix of buildings that are running on those and some that are still IOS-based APs. Lately it seems a lot of

RE: [WIRELESS-LAN] ACLs on Cisco WiSMs

2009-04-21 Thread Case, Brandon J
Lee, We use ACLs on two of our walled garden SSIDs that share a subnet but have different lists of allowed resources. They seem to work pretty well although I wouldn't dare try to add them through the CLI initially. It also helps when you remember that enabling an ACL anywhere automatically

RE: [WIRELESS-LAN] Wireless Installation Process

2008-12-18 Thread Case, Brandon J
Listserv [mailto:wireless-...@listserv.educause.edu] On Behalf Of Case, Brandon J Sent: Wednesday, December 17, 2008 10:01 AM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: [WIRELESS-LAN] Wireless Installation Process I'm curious as to how you all out there handle the actual physical installation

Wireless Installation Process

2008-12-17 Thread Case, Brandon J
I'm curious as to how you all out there handle the actual physical installation of APs in your environments. Do you handle that within the same team that manages the wireless network or is it a separate group that installs the equipment? How do you go about having the data jacks installed? Just as

RE: [WIRELESS-LAN] PEAP/MS-CHAPv2 and LDAP problems

2008-07-23 Thread Case, Brandon J
If you're using ACS with an external LDAP database then you're limited to EAP-FAST, PEAP-GTC, or EAP-TLS according to the ACS documentation. We did run into a similar problem but decided to access the user database via RADIUS instead (we have a proprietary, home-grown system which is accessible

RE: [WIRELESS-LAN] Cisco Wisms CPU

2008-02-15 Thread Case, Brandon J
You can browse the entire Airespace MIB that the controllers support at: http://tools.cisco.com/Support/SNMP/do/BrowseOID.do?objectInput=airespac etranslate=TranslatesubmitValue=SUBMIT with Cisco's SNMP Object Navigator tool. As far as I know there is no single OID for the number of access