<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Difficulty Configuring a RADIUS server with a Cisco 2500 Series Wireless Controller in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/difficulty-configuring-a-radius-server-with-a-cisco-2500-series/m-p/2782799#M40968</link>
    <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;We are attempting to configure a RADIUS server with a Cisco 2500 Series Wireless Controller (AIR-CT2504-K9). Below you can see the configuration of the RADIUS sever on the controller, with the correct IP:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/radius1.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/radius2.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/radius3.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Below is the configuration we have for the current WLAN when we try to attempt to connect it to the RADIUS server:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wlan1.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wlan2.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wlan3.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wlan4.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wlan5.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We know that this WLAN configuration works when not configured wit RADIUS (no AAA servers configured, only Layer 2). When trying to connect using a Windows Laptop or phone, the connection attempt times out. When attempting to connect a Macbook the we receive a 'Failed to connect to authentication Server' error message. Below are the logs for an attempted authentication from a particular MAC address, in this case an iPhone 5s.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;(Cisco Controller) &amp;gt;*apfMsConnTask_6: Jan 13 11:26:57.063: [iPhone MAC Address] Processing assoc-req station:[iPhone MAC Address] AP:[AP MAC Address]-00 thread:15117ba0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.063: [iPhone MAC Address] Adding mobile on LWAPP AP [AP MAC Address](0)&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.063: [iPhone MAC Address] Association received from mobile on BSSID [AP MAC Address] AP AP0462.733a.44f4&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.063: [iPhone MAC Address] Global 200 Clients are allowed to AP radio&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.063: [iPhone MAC Address] Max Client Trap Threshold: 0 &amp;nbsp;cur: 1&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Rf profile 600 Clients are allowed to AP wlan&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] override for default ap group, marking intgrp NULL&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Applying Interface policy on Mobile, role Unassociated. Ms NAC State 0 Quarantine Vlan 0 Access Vlan 0&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Re-applying interface policy for client&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===&amp;gt; 'none' (ACL ID 255) --- (caller apf_policy.c:2399)&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===&amp;gt; 'none' (ACL ID 255) --- (caller apf_policy.c:2420)&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] In processSsidIE:5682 setting Central switched to TRUE&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] In processSsidIE:5685 apVapId = 1 and Split Acl Id = 65535&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Setting the NAS Id to WLAN specific Id '[System Name]'&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Applying site-specific Local Bridging override for station [iPhone MAC Address] - vapId 1, site 'default-group', interface 'management'&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Applying Local Bridging Interface Policy for station [iPhone MAC Address] - vlan 0, interface id 0, interface 'management'&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] processSsidIE &amp;nbsp;statusCode is 0 and status is 0&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] processSsidIE &amp;nbsp;ssid_done_flag is 0 finish_flag is 0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] STA - rates (8): 130 132 139 150 36 48 72 108 0 0 0 0 0 0 0 0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] suppRates &amp;nbsp;statusCode is 0 and gotSuppRatesElement is 1&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] STA - rates (12): 130 132 139 150 36 48 72 108 12 18 24 96 0 0 0 0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] extSuppRates &amp;nbsp;statusCode is 0 and gotExtSuppRatesElement is 1&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: RSNIE in Assoc. Req.: (20)&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: &amp;nbsp; &amp;nbsp; &amp;nbsp;[0000] 01 00 00 0f ac 04 01 00 00 0f ac 04 01 00 00 0f&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: &amp;nbsp; &amp;nbsp; &amp;nbsp;[0016] ac 01 0c 00&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Processing RSN IE type 48, length 20 for mobile [iPhone MAC Address]&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Received 802.11i 802.1X key management suite, enabling dot1x Authentication&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] RSN Capabilities: &amp;nbsp;12&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] apfValidateDot11iCapabilities:1286 Received RSNIE with Capabilities with STA MFPC: 0, STA MFPR:0, &amp;amp; AP MFPC:0MFPR:0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Marking Mobile as non-11w Capable&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Received RSN IE with 0 PMKIDs from mobile [iPhone MAC Address]&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Setting active key cache index 8 ---&amp;gt; 8&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] unsetting PmkIdValidatedByAp&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] apfValidateDot11wGroupMgmtCipher:1716, Received NULL 11w Group Mgmt Cipher Suite for STA, hence returning&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] 0.0.0.0 START (0) Initializing policy&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] 0.0.0.0 AUTHCHECK (2) Change state to 8021X_REQD (3) last state AUTHCHECK (2)&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Encryption policy is set to 0x80000001&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Not Using WMM Compliance code qosCap 00&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Sending 11w Flag 0 for Client [iPhone MAC Address]&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] 0.0.0.0 8021X_REQD (3) Plumbed mobile LWAPP rule on AP [AP MAC Address] vapId 1 apVapId 1 flex-acl-name:&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] apfMsAssoStateInc&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] apfPemAddUser2 (apf_policy.c:352) Changing state for mobile [iPhone MAC Address] on AP [AP MAC Address] from Idle to Associated&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] apfPemAddUser2:session timeout forstation [iPhone MAC Address] - Session Tout 0, apfMsTimeOut '0' and sessionTimerRunning flag is &amp;nbsp;0&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Stopping deletion of Mobile Station: (callerId: 48)&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Func: apfPemAddUser2, Ms Timeout = 0, Session Timeout = 0&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Sending assoc-resp with status 0 station:[iPhone MAC Address] AP:[AP MAC Address]-00 on apVapId 1&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Sending Assoc Response to station on BSSID [AP MAC Address] (status 0) ApVapId 1 Slot 0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] apfProcessAssocReq (apf_80211.c:9463) Changing state for mobile [iPhone MAC Address] on AP [AP MAC Address] from Associated to Associated&lt;/P&gt;
&lt;P&gt;*spamApTask0: Jan 13 11:26:57.068: [iPhone MAC Address] Sent 1x initiate message to multi thread task for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.068: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 1 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:47&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.068: [iPhone MAC Address] EAP-PARAM Debug - eap-params for Wlan-Id :1 is disabled - applying Global eap timers and retries&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.068: [iPhone MAC Address] Disable re-auth, use PMK lifetime.&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.068: [iPhone MAC Address] Station [iPhone MAC Address] setting dot1x reauth timeout = 1800&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.068: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Connecting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.069: [iPhone MAC Address] Sending EAP-Request/Identity to mobile [iPhone MAC Address] (EAP Id 1)&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.099: [iPhone MAC Address] Received EAPOL EAPPKT from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.099: [iPhone MAC Address] Received Identity Response (count=1) from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.100: [iPhone MAC Address] Resetting reauth count 1 to 0 for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.100: [iPhone MAC Address] EAP State update from Connecting to Authenticating for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.100: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Authenticating state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.100: [iPhone MAC Address] Entering Backend Auth Response state for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] Reset the reauth counter since EAPOL START has been received!!!&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] reauth_sm state transition 1 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:53&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] Received EAPOL START from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Aborting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Connecting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] Sending EAP-Request/Identity to mobile [iPhone MAC Address] (EAP Id 3)&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] Received EAPOL EAPPKT from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] Received Identity Response (count=1) from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] Resetting reauth count 1 to 0 for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] EAP State update from Connecting to Authenticating for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Authenticating state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] Entering Backend Auth Response state for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.102: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.120: [iPhone MAC Address] Reset the reauth counter since EAPOL START has been received!!!&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.120: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:53&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.120: [iPhone MAC Address] Received EAPOL START from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.120: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Aborting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.120: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.121: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Connecting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.121: [iPhone MAC Address] Sending EAP-Request/Identity to mobile [iPhone MAC Address] (EAP Id 5)&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.121: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.121: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.125: [iPhone MAC Address] Received EAPOL EAPPKT from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.125: [iPhone MAC Address] Received Identity Response (count=1) from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.125: [iPhone MAC Address] Resetting reauth count 1 to 0 for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.125: [iPhone MAC Address] EAP State update from Connecting to Authenticating for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.126: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Authenticating state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.126: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.126: [iPhone MAC Address] Entering Backend Auth Response state for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.126: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] Reset the reauth counter since EAPOL START has been received!!!&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:53&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] Received EAPOL START from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Aborting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Connecting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] Sending EAP-Request/Identity to mobile [iPhone MAC Address] (EAP Id 7)&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.161: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] Received EAPOL EAPPKT from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] Received Identity Response (count=1) from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] Resetting reauth count 1 to 0 for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] EAP State update from Connecting to Authenticating for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Authenticating state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] Entering Backend Auth Response state for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.381: [iPhone MAC Address] Processing AAA Error 'Timeout' (-5) for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.381: [iPhone MAC Address] Sent Deauthenticate to mobile on BSSID [AP MAC Address] slot 0(caller 1x_auth_pae.c:1581)&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.381: [iPhone MAC Address] Setting active key cache index 8 ---&amp;gt; 8&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.381: [iPhone MAC Address] Deleting the PMK cache when de-authenticating the client.&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.381: [iPhone MAC Address] Global PMK Cache deletion failed.&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.382: [iPhone MAC Address] Scheduling deletion of Mobile Station: &amp;nbsp;(callerId: 65) in 10 seconds&lt;BR /&gt;*osapiBsnTimer: Jan 13 11:27:47.333: [iPhone MAC Address] apfMsExpireCallback (apf_ms.c:632) Expiring Mobile!&lt;BR /&gt;*apfReceiveTask: Jan 13 11:27:47.333: [iPhone MAC Address] apfMsExpireMobileStation (apf_ms.c:6976) Changing state for mobile [iPhone MAC Address] on AP [AP MAC Address] from Associated to Disassociated&lt;/P&gt;
&lt;P&gt;*apfReceiveTask: Jan 13 11:27:47.333: [iPhone MAC Address] Scheduling deletion of Mobile Station: &amp;nbsp;(callerId: 45) in 10 seconds&lt;BR /&gt;*osapiBsnTimer: Jan 13 11:27:57.333: [iPhone MAC Address] apfMsExpireCallback (apf_ms.c:632) Expiring Mobile!&lt;BR /&gt;*apfReceiveTask: Jan 13 11:27:57.333: [iPhone MAC Address] apfMsAssoStateDec&lt;BR /&gt;*apfReceiveTask: Jan 13 11:27:57.333: [iPhone MAC Address] apfMsExpireMobileStation (apf_ms.c:7108) Changing state for mobile [iPhone MAC Address] on AP [AP MAC Address] from Disassociated to Idle&lt;/P&gt;
&lt;P&gt;*apfReceiveTask: Jan 13 11:27:57.333: [iPhone MAC Address] pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.&lt;BR /&gt;*apfReceiveTask: Jan 13 11:27:57.333: [iPhone MAC Address] 0.0.0.0 START (0) Deleted mobile LWAPP rule on AP [[AP MAC Address]]&lt;BR /&gt;*apfReceiveTask: Jan 13 11:27:57.333: [iPhone MAC Address] Deleting mobile on AP [AP MAC Address](0)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The logs on the RADIUS server indicate that no authentication attempts have been made when attemping using an iPhone or Macbook, while attemping connection using a windows laptop shows failed authentication logs using incorrect login details.&lt;/P&gt;
&lt;P&gt;The RADIUS server is running on Windows Server 2008 RS with setup from this guide:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint" wrap=""&gt;&lt;A class="moz-txt-link-freetext" href="http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/115988-nps-wlc-config-000.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/115988-nps-wlc-config-000.html&lt;/A&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any Assistance is greatly appreciated&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:23:41 GMT</pubDate>
    <dc:creator>edgar_spam1</dc:creator>
    <dc:date>2019-03-11T06:23:41Z</dc:date>
    <item>
      <title>Difficulty Configuring a RADIUS server with a Cisco 2500 Series Wireless Controller</title>
      <link>https://community.cisco.com/t5/network-access-control/difficulty-configuring-a-radius-server-with-a-cisco-2500-series/m-p/2782799#M40968</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;We are attempting to configure a RADIUS server with a Cisco 2500 Series Wireless Controller (AIR-CT2504-K9). Below you can see the configuration of the RADIUS sever on the controller, with the correct IP:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/radius1.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/radius2.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/radius3.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Below is the configuration we have for the current WLAN when we try to attempt to connect it to the RADIUS server:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wlan1.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wlan2.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wlan3.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wlan4.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wlan5.jpeg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We know that this WLAN configuration works when not configured wit RADIUS (no AAA servers configured, only Layer 2). When trying to connect using a Windows Laptop or phone, the connection attempt times out. When attempting to connect a Macbook the we receive a 'Failed to connect to authentication Server' error message. Below are the logs for an attempted authentication from a particular MAC address, in this case an iPhone 5s.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;(Cisco Controller) &amp;gt;*apfMsConnTask_6: Jan 13 11:26:57.063: [iPhone MAC Address] Processing assoc-req station:[iPhone MAC Address] AP:[AP MAC Address]-00 thread:15117ba0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.063: [iPhone MAC Address] Adding mobile on LWAPP AP [AP MAC Address](0)&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.063: [iPhone MAC Address] Association received from mobile on BSSID [AP MAC Address] AP AP0462.733a.44f4&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.063: [iPhone MAC Address] Global 200 Clients are allowed to AP radio&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.063: [iPhone MAC Address] Max Client Trap Threshold: 0 &amp;nbsp;cur: 1&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Rf profile 600 Clients are allowed to AP wlan&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] override for default ap group, marking intgrp NULL&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Applying Interface policy on Mobile, role Unassociated. Ms NAC State 0 Quarantine Vlan 0 Access Vlan 0&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Re-applying interface policy for client&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] 0.0.0.0 START (0) Changing IPv4 ACL 'none' (ACL ID 255) ===&amp;gt; 'none' (ACL ID 255) --- (caller apf_policy.c:2399)&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] 0.0.0.0 START (0) Changing IPv6 ACL 'none' (ACL ID 255) ===&amp;gt; 'none' (ACL ID 255) --- (caller apf_policy.c:2420)&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] apfApplyWlanPolicy: Apply WLAN Policy over PMIPv6 Client Mobility Type&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] In processSsidIE:5682 setting Central switched to TRUE&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] In processSsidIE:5685 apVapId = 1 and Split Acl Id = 65535&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Setting the NAS Id to WLAN specific Id '[System Name]'&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Applying site-specific Local Bridging override for station [iPhone MAC Address] - vapId 1, site 'default-group', interface 'management'&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Applying Local Bridging Interface Policy for station [iPhone MAC Address] - vlan 0, interface id 0, interface 'management'&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] processSsidIE &amp;nbsp;statusCode is 0 and status is 0&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] processSsidIE &amp;nbsp;ssid_done_flag is 0 finish_flag is 0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] STA - rates (8): 130 132 139 150 36 48 72 108 0 0 0 0 0 0 0 0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] suppRates &amp;nbsp;statusCode is 0 and gotSuppRatesElement is 1&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] STA - rates (12): 130 132 139 150 36 48 72 108 12 18 24 96 0 0 0 0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] extSuppRates &amp;nbsp;statusCode is 0 and gotExtSuppRatesElement is 1&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: RSNIE in Assoc. Req.: (20)&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: &amp;nbsp; &amp;nbsp; &amp;nbsp;[0000] 01 00 00 0f ac 04 01 00 00 0f ac 04 01 00 00 0f&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: &amp;nbsp; &amp;nbsp; &amp;nbsp;[0016] ac 01 0c 00&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Processing RSN IE type 48, length 20 for mobile [iPhone MAC Address]&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Received 802.11i 802.1X key management suite, enabling dot1x Authentication&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] RSN Capabilities: &amp;nbsp;12&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] apfValidateDot11iCapabilities:1286 Received RSNIE with Capabilities with STA MFPC: 0, STA MFPR:0, &amp;amp; AP MFPC:0MFPR:0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Marking Mobile as non-11w Capable&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Received RSN IE with 0 PMKIDs from mobile [iPhone MAC Address]&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] Setting active key cache index 8 ---&amp;gt; 8&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] unsetting PmkIdValidatedByAp&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] apfValidateDot11wGroupMgmtCipher:1716, Received NULL 11w Group Mgmt Cipher Suite for STA, hence returning&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.064: [iPhone MAC Address] 0.0.0.0 START (0) Initializing policy&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] 0.0.0.0 START (0) Change state to AUTHCHECK (2) last state START (0)&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] 0.0.0.0 AUTHCHECK (2) Change state to 8021X_REQD (3) last state AUTHCHECK (2)&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Encryption policy is set to 0x80000001&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Not Using WMM Compliance code qosCap 00&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Sending 11w Flag 0 for Client [iPhone MAC Address]&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] 0.0.0.0 8021X_REQD (3) Plumbed mobile LWAPP rule on AP [AP MAC Address] vapId 1 apVapId 1 flex-acl-name:&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] apfMsAssoStateInc&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] apfPemAddUser2 (apf_policy.c:352) Changing state for mobile [iPhone MAC Address] on AP [AP MAC Address] from Idle to Associated&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] apfPemAddUser2:session timeout forstation [iPhone MAC Address] - Session Tout 0, apfMsTimeOut '0' and sessionTimerRunning flag is &amp;nbsp;0&amp;nbsp;&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Stopping deletion of Mobile Station: (callerId: 48)&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Func: apfPemAddUser2, Ms Timeout = 0, Session Timeout = 0&lt;/P&gt;
&lt;P&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Sending assoc-resp with status 0 station:[iPhone MAC Address] AP:[AP MAC Address]-00 on apVapId 1&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] Sending Assoc Response to station on BSSID [AP MAC Address] (status 0) ApVapId 1 Slot 0&lt;BR /&gt;*apfMsConnTask_6: Jan 13 11:26:57.065: [iPhone MAC Address] apfProcessAssocReq (apf_80211.c:9463) Changing state for mobile [iPhone MAC Address] on AP [AP MAC Address] from Associated to Associated&lt;/P&gt;
&lt;P&gt;*spamApTask0: Jan 13 11:26:57.068: [iPhone MAC Address] Sent 1x initiate message to multi thread task for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.068: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 1 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:47&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.068: [iPhone MAC Address] EAP-PARAM Debug - eap-params for Wlan-Id :1 is disabled - applying Global eap timers and retries&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.068: [iPhone MAC Address] Disable re-auth, use PMK lifetime.&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.068: [iPhone MAC Address] Station [iPhone MAC Address] setting dot1x reauth timeout = 1800&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.068: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Connecting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.069: [iPhone MAC Address] Sending EAP-Request/Identity to mobile [iPhone MAC Address] (EAP Id 1)&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.099: [iPhone MAC Address] Received EAPOL EAPPKT from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.099: [iPhone MAC Address] Received Identity Response (count=1) from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.100: [iPhone MAC Address] Resetting reauth count 1 to 0 for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.100: [iPhone MAC Address] EAP State update from Connecting to Authenticating for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.100: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Authenticating state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:26:57.100: [iPhone MAC Address] Entering Backend Auth Response state for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] Reset the reauth counter since EAPOL START has been received!!!&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] reauth_sm state transition 1 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:53&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] Received EAPOL START from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Aborting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Connecting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] Sending EAP-Request/Identity to mobile [iPhone MAC Address] (EAP Id 3)&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.095: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] Received EAPOL EAPPKT from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] Received Identity Response (count=1) from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] Resetting reauth count 1 to 0 for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] EAP State update from Connecting to Authenticating for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Authenticating state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.101: [iPhone MAC Address] Entering Backend Auth Response state for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:02.102: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.120: [iPhone MAC Address] Reset the reauth counter since EAPOL START has been received!!!&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.120: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:53&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.120: [iPhone MAC Address] Received EAPOL START from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.120: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Aborting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.120: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.121: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Connecting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.121: [iPhone MAC Address] Sending EAP-Request/Identity to mobile [iPhone MAC Address] (EAP Id 5)&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.121: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.121: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.125: [iPhone MAC Address] Received EAPOL EAPPKT from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.125: [iPhone MAC Address] Received Identity Response (count=1) from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.125: [iPhone MAC Address] Resetting reauth count 1 to 0 for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.125: [iPhone MAC Address] EAP State update from Connecting to Authenticating for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.126: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Authenticating state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.126: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.126: [iPhone MAC Address] Entering Backend Auth Response state for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:07.126: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] Reset the reauth counter since EAPOL START has been received!!!&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:53&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] Received EAPOL START from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Aborting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Connecting state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] Sending EAP-Request/Identity to mobile [iPhone MAC Address] (EAP Id 7)&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.160: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.161: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] Received EAPOL EAPPKT from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] Received Identity Response (count=1) from mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] Resetting reauth count 1 to 0 for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] EAP State update from Connecting to Authenticating for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] dot1x - moving mobile [iPhone MAC Address] into Authenticating state&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] Entering Backend Auth Response state for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:12.166: [iPhone MAC Address] reauth_sm state transition 0 ---&amp;gt; 0 for mobile [iPhone MAC Address] at 1x_reauth_sm.c:71&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.381: [iPhone MAC Address] Processing AAA Error 'Timeout' (-5) for mobile [iPhone MAC Address]&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.381: [iPhone MAC Address] Sent Deauthenticate to mobile on BSSID [AP MAC Address] slot 0(caller 1x_auth_pae.c:1581)&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.381: [iPhone MAC Address] Setting active key cache index 8 ---&amp;gt; 8&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.381: [iPhone MAC Address] Deleting the PMK cache when de-authenticating the client.&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.381: [iPhone MAC Address] Global PMK Cache deletion failed.&lt;BR /&gt;*Dot1x_NW_MsgTask_0: Jan 13 11:27:37.382: [iPhone MAC Address] Scheduling deletion of Mobile Station: &amp;nbsp;(callerId: 65) in 10 seconds&lt;BR /&gt;*osapiBsnTimer: Jan 13 11:27:47.333: [iPhone MAC Address] apfMsExpireCallback (apf_ms.c:632) Expiring Mobile!&lt;BR /&gt;*apfReceiveTask: Jan 13 11:27:47.333: [iPhone MAC Address] apfMsExpireMobileStation (apf_ms.c:6976) Changing state for mobile [iPhone MAC Address] on AP [AP MAC Address] from Associated to Disassociated&lt;/P&gt;
&lt;P&gt;*apfReceiveTask: Jan 13 11:27:47.333: [iPhone MAC Address] Scheduling deletion of Mobile Station: &amp;nbsp;(callerId: 45) in 10 seconds&lt;BR /&gt;*osapiBsnTimer: Jan 13 11:27:57.333: [iPhone MAC Address] apfMsExpireCallback (apf_ms.c:632) Expiring Mobile!&lt;BR /&gt;*apfReceiveTask: Jan 13 11:27:57.333: [iPhone MAC Address] apfMsAssoStateDec&lt;BR /&gt;*apfReceiveTask: Jan 13 11:27:57.333: [iPhone MAC Address] apfMsExpireMobileStation (apf_ms.c:7108) Changing state for mobile [iPhone MAC Address] on AP [AP MAC Address] from Disassociated to Idle&lt;/P&gt;
&lt;P&gt;*apfReceiveTask: Jan 13 11:27:57.333: [iPhone MAC Address] pemApfDeleteMobileStation2: APF_MS_PEM_WAIT_L2_AUTH_COMPLETE = 0.&lt;BR /&gt;*apfReceiveTask: Jan 13 11:27:57.333: [iPhone MAC Address] 0.0.0.0 START (0) Deleted mobile LWAPP rule on AP [[AP MAC Address]]&lt;BR /&gt;*apfReceiveTask: Jan 13 11:27:57.333: [iPhone MAC Address] Deleting mobile on AP [AP MAC Address](0)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The logs on the RADIUS server indicate that no authentication attempts have been made when attemping using an iPhone or Macbook, while attemping connection using a windows laptop shows failed authentication logs using incorrect login details.&lt;/P&gt;
&lt;P&gt;The RADIUS server is running on Windows Server 2008 RS with setup from this guide:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint" wrap=""&gt;&lt;A class="moz-txt-link-freetext" href="http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/115988-nps-wlc-config-000.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/115988-nps-wlc-config-000.html&lt;/A&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any Assistance is greatly appreciated&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difficulty-configuring-a-radius-server-with-a-cisco-2500-series/m-p/2782799#M40968</guid>
      <dc:creator>edgar_spam1</dc:creator>
      <dc:date>2019-03-11T06:23:41Z</dc:date>
    </item>
    <item>
      <title>I'm guessing you figured this</title>
      <link>https://community.cisco.com/t5/network-access-control/difficulty-configuring-a-radius-server-with-a-cisco-2500-series/m-p/2782800#M40969</link>
      <description>&lt;P&gt;I'm guessing you figured this out? Do you have it configured as a client on the radius server and the policy to handle the request?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2016 19:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difficulty-configuring-a-radius-server-with-a-cisco-2500-series/m-p/2782800#M40969</guid>
      <dc:creator>Alex Sierra</dc:creator>
      <dc:date>2016-12-01T19:41:36Z</dc:date>
    </item>
  </channel>
</rss>

