<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Moving to the Wlc 9800 and setting up CWA with ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5261599#M595041</link>
    <description>&lt;P&gt;&lt;SPAN&gt;AAA Server Down &amp;lt;&amp;lt;- server dead???&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There is connection issue I think.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Try do test aaa from wlc'&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Check aaa server dead criteria.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Share&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Show aaa dead criteria radius&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Show aaa servers | s wncd&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Feb 2025 20:40:39 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-02-17T20:40:39Z</dc:date>
    <item>
      <title>Moving to the Wlc 9800 and setting up CWA with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5261287#M595024</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;We are currently moving our Guest network (CWA) from WLC 5520 to the newer WLC 9800. While configuring Central Web Authentication (CWA) with Cisco ISE, we encountered an issue where client authentication fails, and the logs indicate that the server is down.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;However, when using WPA2 with 802.1X, the WLC successfully communicates with the ISE RADIUS server, and clients authenticate without any issues. The problem arises specifically when using MAC filtering, where the client should be redirected to the ISE login page but instead fails to connect.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Below is a relevant portion of our configuration:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;wlan GuestVlan 21GuestVlan &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;ccx aironet-iesupport &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;channel-scan defer-priority 4 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;mac-filtering default &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;radio policy dot11 5ghz &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;security ft reassociation-timeout 100 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;no security ft adaptive &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;no security wpa &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;no security wpa wpa2 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;no security wpa wpa2 ciphers aes &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;no security wpa akm dot1x &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;security dot1x authentication-list ISE_Auth&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;no shutdown&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;wireless profile policy GuestVlan_policy &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;aaa-override &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;aaa-policy ISE_Policy &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;accounting-list ISE_Accounting &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;ipv4 acl ACL-REDIRECT &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;nac &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;vlan 21 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;no shutdown&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;wireless profile flex GuestWln_Flex &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;acl-policy ACL-REDIRECT &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;central-webauth &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;ip http client proxy 0.0.0.0 0 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;vlan-name VLAN021 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;acl ACL-REDIRECT &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;vlan-id 21&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Blow is modified client logs:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.593281513 {wncd_x_R0-0}{1}: [client-orch-state] [19826]: (note): MAC: XXXX.XXXX.XXXX Client state transition: S_CO_INIT -&amp;gt; S_CO_ASSOCIATING&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.593478186 {wncd_x_R0-0}{1}: [client-orch-state] [19826]: (note): MAC: XXXX.XXXX.XXXX Client state transition: S_CO_ASSOCIATING -&amp;gt; S_CO_MACAUTH_IN_PROGRESS&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.593498128 {wncd_x_R0-0}{1}: [client-auth] [19826]: (note): MAC: XXXX.XXXX.XXXX MAB Authentication initiated. Policy VLAN 21, AAA override = 1, NAC = 1&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.594785822 {wncd_x_R0-0}{1}: [ewlc-infra-evq] [19826]: (note): Authentication Success. Resolved Policy bitmap:15 for client XXXX.XXXX.XXXX&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.594910729 {wncd_x_R0-0}{1}: [ewlc-infra-evq] [19826]: (ERR): SANET_AUTHC_FAILURE - AAA Server Down, audit session id XXXXXXXXXXXXXXXX&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.594926484 {wncd_x_R0-0}{1}: [errmsg] [19826]: (note): %SESSION_MGR-5-FAIL: R0/0: wncd: Authorization failed or unapplied for client (XXXX.XXXX.XXXX) on Interface capwap_XXXX. Failure reason: Authc fail. Authc failure reason: AAA Server Down.&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.594971575 {wncd_x_R0-0}{1}: [sanet-shim-miscellaneous] [19826]: (ERR): authc policy update from SANet vlan 0&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.595010552 {wncd_x_R0-0}{1}: [client-orch-state] [19826]: (note): MAC: XXXX.XXXX.XXXX Client state transition: S_CO_MACAUTH_IN_PROGRESS -&amp;gt; S_CO_ASSOCIATING&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.595026368 {wncd_x_R0-0}{1}: [dot11] [19826]: (ERR): MAC: XXXX.XXXX.XXXX Failed to assoc failure tr state entry. Incorrect validation status value :1&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.595142139 {wncd_x_R0-0}{1}: [dot11] [19826]: (ERR): MAC: XXXX.XXXX.XXXX Dot11 update co assoc fail. Sent assoc failure to CO. delete reason: 9, CO_CLIENT_DELETE_REASON_MAB_FAILED&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.595166908 {wncd_x_R0-0}{1}: [client-orch-sm] [19826]: (note): MAC: XXXX.XXXX.XXXX Client delete initiated. Reason: CO_CLIENT_DELETE_REASON_MAB_FAILED&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.595210879 {wncd_x_R0-0}{1}: [client-orch-sm] [19826]: (note): MAC: XXXX.XXXX.XXXX Delete mobile payload sent for BSSID: XXXX.XXXX.XXXX WTP mac: XXXX.XXXX.XXXX slot id: 1&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.595215493 {wncd_x_R0-0}{1}: [client-orch-state] [19826]: (note): MAC: XXXX.XXXX.XXXX Client state transition: S_CO_ASSOCIATING -&amp;gt; S_CO_DELETE_IN_PROGRESS&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.595292681 {wncd_x_R0-0}{1}: [sanet-shim-translate] [19826]: (note): MAC: XXXX.XXXX.XXXX Session manager disconnect event called, session label: XXXXXXXXXX&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.596282757 {wncd_x_R0-0}{1}: [client-orch-state] [19826]: (note): MAC: XXXX.XXXX.XXXX Client state transition: S_CO_DELETE_IN_PROGRESS -&amp;gt; S_CO_DELETED&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.656092284 {wncd_x_R0-0}{1}: [apmgr-db] [19826]: (ERR): XXXX.XXXX.XXXX failed to retrieve radio aid record for slot 2, tdl err:0&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.656317169 {wncd_x_R0-0}{1}: [client-orch-state] [19826]: (note): MAC: XXXX.XXXX.XXXX Client state transition: S_CO_INIT -&amp;gt; S_CO_ASSOCIATING&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.656523888 {wncd_x_R0-0}{1}: [client-orch-state] [19826]: (note): MAC: XXXX.XXXX.XXXX Client state transition: S_CO_ASSOCIATING -&amp;gt; S_CO_MACAUTH_IN_PROGRESS&lt;/P&gt;&lt;P&gt;2025/02/17 08:33:15.656541943 {wncd_x_R0-0}{1}: [client-auth] [19826]: (note): MAC: XXXX.XXXX.XXXX MAB Authentication initiated. Policy VLAN 21, AAA override = 1, NAC = 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would appreciate any insights or recommendations on resolving this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 09:05:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5261287#M595024</guid>
      <dc:creator>aya24</dc:creator>
      <dc:date>2025-02-17T09:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Moving to the Wlc 9800 and setting up CWA with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5261334#M595029</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1843086"&gt;@aya24&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I would recommend to check the ACL. Mac filter alone is not enough. The guide belew can help you double check all your config.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;ip access-list extended REDIRECT&lt;BR /&gt; deny ip any host &amp;lt;ISE-IP&amp;gt;&lt;BR /&gt; deny ip host&amp;lt;ISE-IP&amp;gt; any&lt;BR /&gt; deny udp any any eq domain&lt;BR /&gt; deny udp any eq domain any&lt;BR /&gt; permit tcp any any eq 80&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 10:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5261334#M595029</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2025-02-17T10:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Moving to the Wlc 9800 and setting up CWA with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5261592#M595039</link>
      <description>&lt;P&gt;Your issue might be a combination of factors - there are very good guides on the web on how to configure this stuff.&lt;/P&gt;
&lt;P&gt;One thing that often catches people out is the URL redirection mechanism. On the 9800 it requires the line&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;ip http server&lt;/LI-CODE&gt;
&lt;P&gt;which looks bad from a security point of view, and therefore people tend to disable that. It is mandatory for the 9800 to allow URL interception and redirection. If you want to secure the 9800's Admin web UI (and disable http access to only allow https access) then there are different (more specific) commands to do that.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 20:08:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5261592#M595039</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-02-17T20:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: Moving to the Wlc 9800 and setting up CWA with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5261599#M595041</link>
      <description>&lt;P&gt;&lt;SPAN&gt;AAA Server Down &amp;lt;&amp;lt;- server dead???&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There is connection issue I think.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Try do test aaa from wlc'&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Check aaa server dead criteria.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Share&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Show aaa dead criteria radius&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Show aaa servers | s wncd&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 20:40:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5261599#M595041</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-02-17T20:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: Moving to the Wlc 9800 and setting up CWA with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5262354#M595060</link>
      <description>&lt;P&gt;Thank you for your reply. The problem is not solved yet. We are going to upgrade the firmware from 17.14 to 17.16 and see if that helps.&lt;/P&gt;&lt;P&gt;By the way, I had ALC, and the ISE server is up—we still have our old environment running on it. As mentioned, the new WLC&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;can&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;communicate with ISE when using WPA2 only as a RADIUS server. However, there seems to be a bug since the client is getting an IP address from another VLAN, which was very strange. Therefore, we decided to upgrade the WLC firmware, as we read that there are some known bugs in the current version.&lt;/P&gt;&lt;P&gt;By the way, I want to make sure about the ACL. Should the ACL be assigned to a VLAN, or is it enough to just create it if we are not using Flex?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regrads&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 08:56:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5262354#M595060</guid>
      <dc:creator>aya24</dc:creator>
      <dc:date>2025-02-19T08:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Moving to the Wlc 9800 and setting up CWA with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5262367#M595061</link>
      <description>&lt;P&gt;By the way, I want to make sure about the ACL. Should the ACL be assigned to a VLAN, or is it enough to just create it if we are not using Flex?&lt;BR /&gt;ACL redirect ? you meaning ? If Yes then not need to assign it to WLAN/VLAN&amp;nbsp;&lt;BR /&gt;only add it to WLC&amp;nbsp;&lt;BR /&gt;make sure the name is same in WLC and ISE&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 09:30:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5262367#M595061</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-02-19T09:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Moving to the Wlc 9800 and setting up CWA with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5262426#M595063</link>
      <description>I had no issues with guest on 17.14.1 release.&lt;BR /&gt;&lt;BR /&gt;The ACL is not tied to the client VLAN. The VLAN that the client traffic ends up on is one that should have a DHCP scope for these guest clients devices. They must get IP address before the redirect even can take place. The ACL on the WLC ensures that the redirect happens to ISE CWA portal.&lt;BR /&gt;</description>
      <pubDate>Wed, 19 Feb 2025 11:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-to-the-wlc-9800-and-setting-up-cwa-with-ise/m-p/5262426#M595063</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-02-19T11:09:18Z</dc:date>
    </item>
  </channel>
</rss>

