<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to Log into WLC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4735701#M578742</link>
    <description>&lt;P&gt;Hello Dary ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wonder if you can share how you managed to solve this , as I have the same issue , ssh CLI access to WLC is not possible due to PAC expired , DNAC cannot provision WLC due to this issue , all devices are supposed to renew PAC automatically but failed on WLC.&lt;/P&gt;&lt;P&gt;I can access the WLC from GUI but not through ssh CLI&lt;/P&gt;&lt;P&gt;WLC OOB Pac showing expired in ISE (Network Devices )&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Anas&lt;/P&gt;</description>
    <pubDate>Fri, 09 Dec 2022 12:07:15 GMT</pubDate>
    <dc:creator>aghoush</dc:creator>
    <dc:date>2022-12-09T12:07:15Z</dc:date>
    <item>
      <title>Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4668655#M576656</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am having an issue logging into my C9800L WLC due to an expired PAC. Issue exists both at the CLI and the GUI. ISE(2.7) and DNA(2.2.3.5) are also throwing connection errors. Does anyone have any insight on how to resolve this issue?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Daryl&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 21:39:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4668655#M576656</guid>
      <dc:creator>DeeReal_99</dc:creator>
      <dc:date>2022-08-12T21:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4668687#M576657</link>
      <description>&lt;P&gt;Can you paste the exact error log&lt;/P&gt;</description>
      <pubDate>Sat, 13 Aug 2022 01:55:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4668687#M576657</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2022-08-13T01:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4669012#M576662</link>
      <description>&lt;P&gt;If you have a local user account on the WLC then one trick I often use is to untick the TACACS (or RADIUS if RADIUS is used for device admin) in ISE for that particular device. Then the WLC loses comms with ISE for device admin and will be forced to use the local account for logins. Of course, you hope that the the "aaa authenticaiton" and "aaa authorization" commands were done right to include the "local" option - I suspect DNAC does provision aaa that way &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; - give it a try.&lt;/P&gt;
&lt;P&gt;As for the PAC - perhaps others can answer that - you can try to re-provision the device through DNAC - or, fix the aaa config yourself using shared secret instead of PAC.&lt;/P&gt;
&lt;P&gt;PAC (as far as I know) is used by DNAC because it's a handy way to setup the CTS (Cisco Trust Sec) stuff in one go - if you don't use SDA/CTS then don't worry about PAC - just revert to using regular TACACS/RADIUS shared secret configs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Aug 2022 20:25:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4669012#M576662</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-08-14T20:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4669176#M576666</link>
      <description>&lt;P&gt;Here are some of the screenshots I took...&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 12:08:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4669176#M576666</guid>
      <dc:creator>DeeReal_99</dc:creator>
      <dc:date>2022-08-15T12:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4669177#M576667</link>
      <description>&lt;P&gt;Please see the screenshots I posted.&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 12:09:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4669177#M576667</guid>
      <dc:creator>DeeReal_99</dc:creator>
      <dc:date>2022-08-15T12:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4669222#M576671</link>
      <description>&lt;P&gt;Thanks for the Arne, I will try during our next maintenance window&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 14:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4669222#M576671</guid>
      <dc:creator>DeeReal_99</dc:creator>
      <dc:date>2022-08-15T14:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4735701#M578742</link>
      <description>&lt;P&gt;Hello Dary ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wonder if you can share how you managed to solve this , as I have the same issue , ssh CLI access to WLC is not possible due to PAC expired , DNAC cannot provision WLC due to this issue , all devices are supposed to renew PAC automatically but failed on WLC.&lt;/P&gt;&lt;P&gt;I can access the WLC from GUI but not through ssh CLI&lt;/P&gt;&lt;P&gt;WLC OOB Pac showing expired in ISE (Network Devices )&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Anas&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 12:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4735701#M578742</guid>
      <dc:creator>aghoush</dc:creator>
      <dc:date>2022-12-09T12:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4735822#M578743</link>
      <description>&lt;P&gt;Hi aghoush,&lt;/P&gt;&lt;P&gt;Odd that you are able to access GUI. When this happens, I am locked out of both gui and cli(odd because I am no guru..lol). The issue clears up after a reboot of the WLC. It grabbed a new PAC from ISE. I have an open TAC case to come up with a way to avoid this in the future. Unfortunately, syncing up with the Tech has been a chore. For the time being, my plan is to setup a reminder to renew the PAC 1 week prior to expiration. This will have to do until we can develop a more automated process.&lt;/P&gt;&lt;P&gt;And btw, I have not ventured down the path Arne recommended above as of yet. But will try at some point until we fully realize SDA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 16:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4735822#M578743</guid>
      <dc:creator>DeeReal_99</dc:creator>
      <dc:date>2022-12-09T16:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4737280#M578789</link>
      <description>&lt;P&gt;just wanted to update you that we managed to solve this with the support from TAC team:&lt;/P&gt;&lt;P&gt;- we have access to the GUI as we have added 2 separate admin accounts from day1 , one is used for GUI access and one for ssh and WLC EXEC configuration in ISE (administration -- network Device -- WLC )&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;using the command prompt GUI in WLC:&amp;nbsp;&lt;/P&gt;&lt;P&gt;- we managed to reset the WLC device cts&amp;nbsp; credential&amp;nbsp;&amp;nbsp;using :&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt; clear&lt;/STRONG&gt;&lt;/EM&gt;&lt;I&gt;&lt;STRONG&gt;&amp;nbsp;cts credentials&lt;/STRONG&gt;&lt;BR /&gt;- &lt;/I&gt;then reassign the wlc device cts password again&amp;nbsp; :&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;cts credentials id WLC-DEVICE-ID&amp;nbsp; PASSWORD&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( WLS &lt;EM&gt;DEVICE-ID&lt;/EM&gt; AND &lt;EM&gt;PASSWORD&lt;/EM&gt; AS SHOW in ISE )&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do a refresh for cts and pac :&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;clear cts environment-data&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp; &lt;EM&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; cts refresh pac&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 17:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4737280#M578789</guid>
      <dc:creator>aghoush</dc:creator>
      <dc:date>2022-12-12T17:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4898709#M583288</link>
      <description>&lt;P&gt;But what is the root cause ? (Sure the PAC is expired, should the 9800 not just auto renew it ?).&lt;/P&gt;
&lt;P&gt;Is there a BugID for this ?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 10:28:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4898709#M583288</guid>
      <dc:creator>Thomas Obbekaer Thomsen</dc:creator>
      <dc:date>2023-08-04T10:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4900689#M583307</link>
      <description>&lt;P&gt;We are also having this issue. We can only login to the WLC after a reboot. CLI and GUI won't work. CLI gives error message "PAC Expired"&lt;BR /&gt;&lt;BR /&gt;Is there a bug on this? And how can we fix the root cause?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 11:57:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4900689#M583307</guid>
      <dc:creator>stian.johansen</dc:creator>
      <dc:date>2023-08-07T11:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4914446#M583733</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We have the same issue for the second time.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our setup is ISE 2.7 patch 8 and DNA 2.2.3.5&lt;/P&gt;
&lt;P&gt;WLC upgraded to&amp;nbsp;17.03.07 since the previous episode of the issue.&lt;/P&gt;
&lt;P&gt;So last time we had this issue PAC renewal failed on a second automated attempt.&lt;/P&gt;
&lt;P&gt;Issue fixed the same way as this time with&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;clear cts environment-data&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;cts refresh pac&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;22/03/2023 06:26 PM&lt;BR /&gt;## 1-st auto-renew:&lt;BR /&gt;Credential Lifetime: 19:58:30 BST Jun 20 2023&lt;BR /&gt;Refresh timer is set for 12w4d&lt;/P&gt;
&lt;P&gt;## 2-nd auto-renew:&lt;BR /&gt;Credential Lifetime: 05:13:50 BST Aug 24 2023&lt;BR /&gt;Refresh timer is set for 9w5d&lt;/P&gt;
&lt;P&gt;This failed on the second attempt.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a TAC case open for this. I will post it here if we get the cause of the issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Lucas&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 09:19:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4914446#M583733</guid>
      <dc:creator>woocash_m</dc:creator>
      <dc:date>2023-08-30T09:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4975407#M585639</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;So we got to the bottom of this with TAC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue is due to&amp;nbsp;&lt;SPAN&gt;authentication events for WLC user in ISE not logged in the prrt-server.log.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi41440" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi41440&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 11:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/4975407#M585639</guid>
      <dc:creator>woocash_m</dc:creator>
      <dc:date>2023-12-11T11:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/5006221#M586749</link>
      <description>&lt;P&gt;We have the same issue with our WLC but also several switches. However, the conditions in the mentioned bug do NOT apply:&lt;/P&gt;
&lt;P&gt;- No account disable policy&lt;/P&gt;
&lt;P&gt;- No logging collection filter&lt;/P&gt;
&lt;P&gt;However, the PAC file hasnt renewed automatically on several devices.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 07:15:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/5006221#M586749</guid>
      <dc:creator>denny_strijdonck</dc:creator>
      <dc:date>2024-01-26T07:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/5013828#M587117</link>
      <description>&lt;P&gt;i have the same issue with our DNA and ise 3.2 setup. have not found a resolution as yet.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 00:41:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/5013828#M587117</guid>
      <dc:creator>ben.posner</dc:creator>
      <dc:date>2024-02-07T00:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/5016394#M587265</link>
      <description>&lt;P&gt;Rebooting the WLC helped for us&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 07:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/5016394#M587265</guid>
      <dc:creator>denny_strijdonck</dc:creator>
      <dc:date>2024-02-12T07:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/5164285#M591342</link>
      <description>&lt;P&gt;I've had this problem as well. We couldn't log in with either Radius or local account.&lt;/P&gt;&lt;P&gt;We had to block all radius traffic so the WLC did a fall back to the local account. Then we used the commands, posted in earlier in this post:&lt;/P&gt;&lt;P&gt;Using the CLI:&amp;nbsp;&lt;/P&gt;&lt;P&gt;-reset the WLC device cts&amp;nbsp; credential&amp;nbsp;&amp;nbsp;using :&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;clear&lt;/STRONG&gt;&lt;/EM&gt;&lt;I&gt;&lt;STRONG&gt;&amp;nbsp;cts credentials&lt;/STRONG&gt;&lt;BR /&gt;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;then reassign the wlc device cts password again&amp;nbsp; :&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;cts credentials id WLC-DEVICE-ID&amp;nbsp; PASSWORD&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ( WLS&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;DEVICE-ID&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;AND&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;PASSWORD&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;AS SHOW in ISE )&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do a refresh for cts and pac :&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;clear cts environment-data&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; cts refresh pac&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And it worked. But it will expire again in a few months.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 08:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/5164285#M591342</guid>
      <dc:creator>Emirage</dc:creator>
      <dc:date>2024-08-22T08:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Log into WLC</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/5238336#M593868</link>
      <description>&lt;P&gt;This seems to be the bug hit : &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk90748" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk90748&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Just says "Fixed" but no software mentioned of fixed release.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 10:15:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-log-into-wlc/m-p/5238336#M593868</guid>
      <dc:creator>Thomas Obbekaer Thomsen</dc:creator>
      <dc:date>2024-12-18T10:15:59Z</dc:date>
    </item>
  </channel>
</rss>

