<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [Cisco ACS] 11036 The Message-Authenticator RADIUS attribute is in in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/5262529#M595066</link>
    <description>&lt;P&gt;its old post but on newer version of 9800 WLC there was similar issue but later it found to be BUG&lt;/P&gt;&lt;P&gt;check below link for more details&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A title="https://bst.cloudapps.cisco.com/bugsearch/bug/cscwi93213" href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi93213" target="_blank" rel="noreferrer noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi93213&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Feb 2025 14:30:55 GMT</pubDate>
    <dc:creator>maruti.hv</dc:creator>
    <dc:date>2025-02-19T14:30:55Z</dc:date>
    <item>
      <title>[Cisco ACS] 11036 The Message-Authenticator RADIUS attribute is invalid</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054255#M185205</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got many Cisco AP which are linked to 2 Cisco WLC.&lt;/P&gt;&lt;P&gt;On each WLC, I configured a primary and a secondary RADIUS Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS servers are Cisco ACS 5.2.0.26 (patch 10)&lt;/P&gt;&lt;P&gt;Primary and secondary ACS &lt;A&gt;&lt;/A&gt;configurations are synchronized.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no problem between primary WLC and Cisco ACS (primary and secondary).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When secondary WLC requests primary Cisco ACS, I get this error "11036 The Message-Authenticator RADIUS attribute is invalid"&lt;/P&gt;&lt;P&gt;Secondary WLC automatically contacts secondary Cisco ACS and it works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco ACS description for this error: "This maybe because of mismatched Shared Secrets."&lt;/P&gt;&lt;P&gt;The two Cisco ACS are synchronized so I should have same error on them...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why does primary ACS generate this error?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:30:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054255#M185205</guid>
      <dc:creator>Patrick Tran</dc:creator>
      <dc:date>2019-03-11T02:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: [Cisco ACS] 11036 The Message-Authenticator RADIUS attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054256#M185218</link>
      <description>&lt;P&gt;Patrick: The shared secret mismatch could be from WLC side, not from ACS side.&lt;/P&gt;
&lt;P&gt;Make sure that the shared secret of the primary radius server is configured correctly on the secondary WLC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Amjad&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jan 2019 20:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054256#M185218</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2019-01-26T20:03:34Z</dc:date>
    </item>
    <item>
      <title>[Cisco ACS] 11036 The Message-Authenticator RADIUS attribute is</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054257#M185231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is a good observation, shouldnt 7.3 (which recently released) help put these types of issues to rest? I hear that the configuration can now be replicated from one controller to the next in a failover setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2012 13:10:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054257#M185231</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-11T13:10:14Z</dc:date>
    </item>
    <item>
      <title>[Cisco ACS] 11036 The Message-Authenticator RADIUS attribute is</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054258#M185248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;It was a shared secret mismatch from WLC side... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 07:07:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054258#M185248</guid>
      <dc:creator>Patrick Tran</dc:creator>
      <dc:date>2012-09-12T07:07:01Z</dc:date>
    </item>
    <item>
      <title>[Cisco ACS] 11036 The Message-Authenticator RADIUS attribute is</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054259#M185280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Patrick,&lt;/P&gt;&lt;P&gt;Glad that I could help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 07:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054259#M185280</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-09-12T07:28:08Z</dc:date>
    </item>
    <item>
      <title>[Cisco ACS] 11036 The Message-Authenticator RADIUS attribute is</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054260#M185314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Tarik Admani wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is a good observation, shouldnt 7.3 (which recently released) help put these types of issues to rest? I hear that the configuration can now be replicated from one controller to the next in a failover setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes. That is a good point.&lt;/P&gt;&lt;P&gt;With 7.3 you can use high availability (HA) between two WLCs and you can configure only one WLC (the primary) and all the configuraiotn can be replicated and synched to the other WLC (the secondary).&lt;/P&gt;&lt;P&gt;The two WLCs in the HA must be on same subnet though. Otherwise hot-standby HA between WLCs can't be used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 07:31:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/2054260#M185314</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-09-12T07:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: [Cisco ACS] 11036 The Message-Authenticator RADIUS attribute is in</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/5262529#M595066</link>
      <description>&lt;P&gt;its old post but on newer version of 9800 WLC there was similar issue but later it found to be BUG&lt;/P&gt;&lt;P&gt;check below link for more details&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A title="https://bst.cloudapps.cisco.com/bugsearch/bug/cscwi93213" href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi93213" target="_blank" rel="noreferrer noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi93213&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 14:30:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-11036-the-message-authenticator-radius-attribute-is/m-p/5262529#M595066</guid>
      <dc:creator>maruti.hv</dc:creator>
      <dc:date>2025-02-19T14:30:55Z</dc:date>
    </item>
  </channel>
</rss>

