<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Troubleshooting Nac Guest Server Authentication Error in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/troubleshooting-nac-guest-server-authentication-error/m-p/1673386#M238539</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alois,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This looks more a AAA related issue so moving it to AAA domain for faster response from Experts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Vinay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 May 2011 14:57:12 GMT</pubDate>
    <dc:creator>Vinay Sharma</dc:creator>
    <dc:date>2011-05-09T14:57:12Z</dc:date>
    <item>
      <title>Troubleshooting Nac Guest Server Authentication Error</title>
      <link>https://community.cisco.com/t5/network-access-control/troubleshooting-nac-guest-server-authentication-error/m-p/1673385#M238537</link>
      <description>&lt;P&gt;Hello Everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I installed NGS 2.0.2 for wireless guest user management and authentication. I implement webauth via webauth page on wlc deployed.&lt;/P&gt;&lt;P&gt;One Branch with a WLC5508 version 7.0 wireless anchor controller is working on the NGS.&lt;/P&gt;&lt;P&gt;But now I integrate next branch with WLC4402 version 6.0.188 and the authentication of users at the new branch gets an error, wrong user/password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I double checked configuration and user/password but I can't find any configuration error. Also stopping and starting of radius service and reboot of NGS still does not help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to debug the radius via web interface and watched for the loggfile and there is still a reject.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried the freeradius command radiusd -X but I got an error when starting the radiusd -X.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) How can I figure out, if I will get the correct password from my WLC ?&lt;/P&gt;&lt;P&gt;Are there any debug options to see more ? e.g. some cli commands, radiustest utilities or did someone know how to get the received password from the chap challenge of the debug ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) I have appended a part from my radius loggfile. How can I find the detailed error in the radius loggfile ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is it correct that the password in the debug file is empty ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; raiuds logg line "[radius-user-auth] &lt;SPAN&gt; &lt;/SPAN&gt;expand: %{User-Password} -&amp;gt; "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Alois&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/troubleshooting-nac-guest-server-authentication-error/m-p/1673385#M238537</guid>
      <dc:creator>alois.heilmaier</dc:creator>
      <dc:date>2019-03-11T01:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Nac Guest Server Authentication Error</title>
      <link>https://community.cisco.com/t5/network-access-control/troubleshooting-nac-guest-server-authentication-error/m-p/1673386#M238539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alois,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This looks more a AAA related issue so moving it to AAA domain for faster response from Experts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Vinay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 May 2011 14:57:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/troubleshooting-nac-guest-server-authentication-error/m-p/1673386#M238539</guid>
      <dc:creator>Vinay Sharma</dc:creator>
      <dc:date>2011-05-09T14:57:12Z</dc:date>
    </item>
    <item>
      <title>Troubleshooting Nac Guest Server Authentication Error</title>
      <link>https://community.cisco.com/t5/network-access-control/troubleshooting-nac-guest-server-authentication-error/m-p/1673387#M238540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;updated WLC4402 to version 7.0.98.0, same version is on WLC5508.&lt;/P&gt;&lt;P&gt;But WLC4402 has the same problem for authentication, like with 6.0.188 again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions on this problem ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Alois&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2011 11:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/troubleshooting-nac-guest-server-authentication-error/m-p/1673387#M238540</guid>
      <dc:creator>alois.heilmaier</dc:creator>
      <dc:date>2011-09-23T11:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting Nac Guest Server Authentication Error</title>
      <link>https://community.cisco.com/t5/network-access-control/troubleshooting-nac-guest-server-authentication-error/m-p/1673388#M238544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;think I found the error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config guide for external web-auth showed radius-auth method is configurable.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008067489f.shtml"&gt;http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008067489f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"config custom-web radiusauth &lt;AUTH method=""&gt;"&lt;/AUTH&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config guide of NGS has a small but important note:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/nac/guestserver/configuration_guide/20/g_radius.html"&gt;http://www.cisco.com/en/US/docs/security/nac/guestserver/configuration_guide/20/g_radius.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"NAC Guest Server supports only PAP in RADIUS Authentication"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I checked my configurations (show custom-web all), and now I see the error. &lt;/P&gt;&lt;P&gt;Working controller has PAP authentication configured, failed controller has CHAP authentication configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will change the congfiguration and test it, but I think that's the problem, because NGS does not support CHAP based authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Alois&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Dec 2011 09:59:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/troubleshooting-nac-guest-server-authentication-error/m-p/1673388#M238544</guid>
      <dc:creator>alois.heilmaier</dc:creator>
      <dc:date>2011-12-27T09:59:10Z</dc:date>
    </item>
  </channel>
</rss>

