<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Autonomous AP's support OTP for web console? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646506#M296043</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am going to open a TAC case for this as I just confirmed this issue using v4.2.1.15.3 of ACS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Feb 2011 16:25:49 GMT</pubDate>
    <dc:creator>mmletzko</dc:creator>
    <dc:date>2011-02-21T16:25:49Z</dc:date>
    <item>
      <title>Autonomous AP's support OTP for web console?</title>
      <link>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646501#M295964</link>
      <description>&lt;P&gt;I'm having trouble finding this documented, hoping someone could answer it for me.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Do Cisco Autonomous APs support token authentication (RSA) via ACS for the web console option?&amp;nbsp; I found in some realease notes for Wireless LAN controllers that it's supported for http management, but I cannot find anything documented for APs.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We're seeing a problem in which authenticating to APs using http (with caching enabled) with RSA token is sometimes prompting over and over even though the correct credentials are supplied.&amp;nbsp; It can then put the token in next tokencode mode, or disable it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this dependent on AP model/code version?&amp;nbsp; Is there a setting on the AP or in ACS that can prevent this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:50:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646501#M295964</guid>
      <dc:creator>mmletzko</dc:creator>
      <dc:date>2019-03-11T00:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Autonomous AP's support OTP for web console?</title>
      <link>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646502#M295970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you would need to troubleshoot this on the ACS side. The AP is just sending radius requests and expecting an access-accept from the ACS.&lt;/P&gt;&lt;P&gt;So when it doesn't work, check if ACS is logging a failed or passed attempt, check the authorization as well to see if all went fine.&lt;/P&gt;&lt;P&gt;It could be a bug on the specific version of ACS you are having. What version is that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 07:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646502#M295970</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-02-18T07:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Autonomous AP's support OTP for web console?</title>
      <link>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646503#M295979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, unfortunately for a few of our infrastructures, we're still running v3.3.4.12.6.&amp;nbsp; We're on our way to v4.2.1.15.3, but still have some work to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The failed log just shows the standard "extrernal db password invalid" so it's not much help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything from CLI (APs, routers, switches) works fine, and WLCs work fine - http/ssh.&amp;nbsp; It's only APs via http that are giving us a problem - and may be only some...which is why I was asking if model/code was relevant.&amp;nbsp; I'm working on trying to determine that now.&amp;nbsp; What I am finding so far is that I can get in most without a problem, but after 5/10/15 minutes of being in, I will get prompted for our credentials again.&amp;nbsp; At that point it doesn't matter what's entered...it fails, and if you aren't careful, the token will get disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm at the beginning stages of troubleshooting so I need to get more details, but I was wondering if OTP was in fact supported for the http connection to automonomous APs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 15:50:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646503#M295979</guid>
      <dc:creator>mmletzko</dc:creator>
      <dc:date>2011-02-18T15:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Autonomous AP's support OTP for web console?</title>
      <link>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646504#M296000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition to this, it looks like what happens is when it prompts, it fails multiple times for the same connection, which is in turn disabling our tokens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I was logged into an AP via http for about 15/20 minutes with no issues...then all of a sudden it popped up with a box to enter credentials.&amp;nbsp; I entered my current token credentials one time and there ended up being 10 entries in the failed log for the one attempt.&amp;nbsp; That disabled my token.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 16:25:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646504#M296000</guid>
      <dc:creator>mmletzko</dc:creator>
      <dc:date>2011-02-18T16:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Autonomous AP's support OTP for web console?</title>
      <link>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646505#M296023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was just authenticated to an AP via http using my token for more than an hour, then it popped up with an authentication box.&amp;nbsp; I escaped out and looked in the ACS log and it shows a failed authentication - external db password invalid.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Does the AP http session attempt to reauthenticate?&amp;nbsp; Is there any way to control that or adjust the settings?&amp;nbsp; I'm assuming it tries to authent using the old token and of course fails.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Would a tacacs-timeout setting come into play at all?&amp;nbsp; How about in ACS - are there any settings that could help this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 21:28:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646505#M296023</guid>
      <dc:creator>mmletzko</dc:creator>
      <dc:date>2011-02-18T21:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: Autonomous AP's support OTP for web console?</title>
      <link>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646506#M296043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am going to open a TAC case for this as I just confirmed this issue using v4.2.1.15.3 of ACS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Feb 2011 16:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/autonomous-ap-s-support-otp-for-web-console/m-p/1646506#M296043</guid>
      <dc:creator>mmletzko</dc:creator>
      <dc:date>2011-02-21T16:25:49Z</dc:date>
    </item>
  </channel>
</rss>

