<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.0 RADIUS timeout with WLC 7.0 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-0-radius-timeout-with-wlc-7-0/m-p/1782685#M247039</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It seems as though you are using ACS 5.0 without any patches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your information the product release is now up to 5.2 and ACS 5.3 is soon to be released&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seem to remember there was an issue with ACS 5.0 operations with WLC that was resolved in patch for 5.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure of the specific CDETS but may be:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;CSCsy17858&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt; Incorrect handling of Tunnel-Type &amp;amp; Tunnel-Client-Endpoint attrs&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ACS 5.0 has a cumulative patch appraoch with all fixes being accumulated&lt;/P&gt;&lt;P&gt;My recommendation would be to download patch 8 for ACS 5.0: 5.0.0.21.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patch can be downloaded from CCO&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;To install a patch define a repository on ACS (cumulative patches are larger than 32MB so you can't use TFTP for this), copy the patch file to the repository, then on ACS' CLI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# acs patch install &lt;FILENAME&gt; repository &lt;REPOSITORY name=""&gt;&lt;/REPOSITORY&gt;&lt;/FILENAME&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 Aug 2011 15:09:04 GMT</pubDate>
    <dc:creator>jrabinow</dc:creator>
    <dc:date>2011-08-31T15:09:04Z</dc:date>
    <item>
      <title>ACS 5.0 RADIUS timeout with WLC 7.0</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-0-radius-timeout-with-wlc-7-0/m-p/1782683#M247021</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am configuring a Cisco Secure ACS 1120 appliance running ACS 5.0.0.21 to handle RADIUS request from a Cisco WLC 5508 appliance running version 7.0.116.0.&lt;/P&gt;&lt;UL&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;these devices have open communication on all ports - no firewalls or ACL's&lt;/LI&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;they have successful ping communication&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following statements illustrate &lt;STRONG&gt;some but not all &lt;/STRONG&gt;the debugging I have done to ensure each device functions as it should in isolation.&lt;/P&gt;&lt;UL&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;Using a simple windows RADIUS server (radserv2.exe) instead of the Cisco ACS&amp;nbsp; &lt;UL&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;This &lt;STRONG&gt;works&lt;/STRONG&gt; and the WLC gets RADIUS response from my makeshift server&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;Using a simple windows EAP client to query the ACS using RADIUS protocol&amp;nbsp;&amp;nbsp; &lt;UL&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;this &lt;STRONG&gt;works&lt;/STRONG&gt; and the ACS processes the RADIUS request and sends a response&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;Placed a wireshark client on the network to inspect timeout. &lt;UL&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;Wireshark logs the packet from the WLC to the ACS using port 1812 but doesn't see any packet&amp;nbsp; responses from the ACS&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment I have the &lt;/P&gt;&lt;OL start="1"&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;WLC accepting the association from the wireless client and &lt;/LI&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;sending the RADIUS (PEAP, EAP-FAST or EAP-TLS) request to the ACS, &lt;/LI&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;the WLC receives no response and generates a timeout message and disassociates from the client. &lt;OL start="1"&gt;&lt;LI style="margin-top: px; margin-bottom: px;"&gt;&lt;STRONG&gt;note &lt;/STRONG&gt;this is not a reject or similar message, the ACS simple does not even process the packet. i.e. there is absolutely nothing in the ACS logs to suggest it even received a radius packet from the WLC.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In summary the WLC and the ACS successfully function independently but they do not communicate via radius.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance appreciated Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:21:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-0-radius-timeout-with-wlc-7-0/m-p/1782683#M247021</guid>
      <dc:creator>dpicomms</dc:creator>
      <dc:date>2019-03-11T01:21:23Z</dc:date>
    </item>
    <item>
      <title>ACS 5.0 RADIUS timeout with WLC 7.0</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-0-radius-timeout-with-wlc-7-0/m-p/1782684#M247029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the service selection screen, is the RADIUS policy being hit at all?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Aug 2011 13:59:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-0-radius-timeout-with-wlc-7-0/m-p/1782684#M247029</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2011-08-31T13:59:39Z</dc:date>
    </item>
    <item>
      <title>ACS 5.0 RADIUS timeout with WLC 7.0</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-0-radius-timeout-with-wlc-7-0/m-p/1782685#M247039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It seems as though you are using ACS 5.0 without any patches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your information the product release is now up to 5.2 and ACS 5.3 is soon to be released&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seem to remember there was an issue with ACS 5.0 operations with WLC that was resolved in patch for 5.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure of the specific CDETS but may be:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;CSCsy17858&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt; Incorrect handling of Tunnel-Type &amp;amp; Tunnel-Client-Endpoint attrs&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ACS 5.0 has a cumulative patch appraoch with all fixes being accumulated&lt;/P&gt;&lt;P&gt;My recommendation would be to download patch 8 for ACS 5.0: 5.0.0.21.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patch can be downloaded from CCO&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;To install a patch define a repository on ACS (cumulative patches are larger than 32MB so you can't use TFTP for this), copy the patch file to the repository, then on ACS' CLI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# acs patch install &lt;FILENAME&gt; repository &lt;REPOSITORY name=""&gt;&lt;/REPOSITORY&gt;&lt;/FILENAME&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Aug 2011 15:09:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-0-radius-timeout-with-wlc-7-0/m-p/1782685#M247039</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-08-31T15:09:04Z</dc:date>
    </item>
    <item>
      <title>ACS 5.0 RADIUS timeout with WLC 7.0</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-0-radius-timeout-with-wlc-7-0/m-p/1782686#M247048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;issue resolved by upgrading from 5.0 to 5.2, Thanks for the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Sep 2011 05:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-0-radius-timeout-with-wlc-7-0/m-p/1782686#M247048</guid>
      <dc:creator>dpicomms</dc:creator>
      <dc:date>2011-09-21T05:14:14Z</dc:date>
    </item>
  </channel>
</rss>

