<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication rejected because of challenge failure ReasonCode: 15 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320103#M139909</link>
    <description>The client isn't authenticated.  I can see logs showing the clients associating and then attempt to authenticating before getting rejected due to timeout.</description>
    <pubDate>Sat, 27 Jan 2018 08:07:57 GMT</pubDate>
    <dc:creator>Leo Laohoo</dc:creator>
    <dc:date>2018-01-27T08:07:57Z</dc:date>
    <item>
      <title>Authentication rejected because of challenge failure ReasonCode: 15</title>
      <link>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320075#M139904</link>
      <description>&lt;P&gt;I have configured a guest&amp;nbsp;network that authenticates using the local database in my 2500 series wireless controller. When I login, using the username/password I create, I see a success screen and I get an IP address but am not connected to the internet. (Not able to ping&amp;nbsp;8.8.8.8). When I look at the recent traps, I see&amp;nbsp;the following corresponding entries:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="800"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;1080&lt;/TD&gt;
&lt;TD&gt;Fri Jan 26 18:18:43 2018&lt;/TD&gt;
&lt;TD&gt;Client Disassociated: MACAddress:45:85:00:b1:14:e4 Base Radio MAC:48:90:a5:cb:9c:80 Slot: 1 User Name: test, Ip Address: 10.20.44.106 Reason:Unspecified ReasonCode: 1 TxPkts: 0l TxBytes: 0l RxPkts: 0l RxBytes: 0l&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;1081&lt;/TD&gt;
&lt;TD&gt;Fri Jan 26 18:18:43 2018&lt;/TD&gt;
&lt;TD&gt;Client Deauthenticated: MACAddress:45:85:00:b1:14:e4 Base Radio MAC:48:90:a5:cb:9c:80 Slot: 1 User Name:&amp;nbsp;test Ip Address: 10.20.44.106 Reason:Unspecified ReasonCode: 1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;1082&lt;/TD&gt;
&lt;TD&gt;Fri Jan 26 18:18:43 2018&lt;/TD&gt;
&lt;TD&gt;Client Disassociated: MACAddress:45:85:00:b1:14:e4 Base Radio MAC:48:90:a5:cb:9c:80 Slot: 1 User Name: test, Ip Address: 10.20.44.106 Reason:Unspecified ReasonCode: 1 TxPkts: 0l TxBytes: 0l RxPkts: 0l RxBytes: 0l&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;1083&lt;/TD&gt;
&lt;TD&gt;Fri Jan 26 18:18:43 2018&lt;/TD&gt;
&lt;TD&gt;Client Disassociated: MACAddress:45:85:00:b1:14:e4 Base Radio MAC:48:90:a5:cb:9c:80 Slot: 1 User Name: test, Ip Address: 10.20.44.106 Reason:Unspecified ReasonCode: 1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;1084&lt;/TD&gt;
&lt;TD&gt;Fri Jan 26 18:18:42 2018&lt;/TD&gt;
&lt;TD&gt;Client Association Failure: MACAddress:45:85:00:b1:14:e4 Base Radio MAC:48:90:a5:cb:9c:80 Slot: 1 User Name:test IP Addr: 10.20.44.106 Reason:Authentication rejected because of challenge failure ReasonCode: 15&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;1092&lt;/TD&gt;
&lt;TD&gt;Fri Jan 26 18:18:09 2018&lt;/TD&gt;
&lt;TD&gt;User&amp;nbsp;test logged in. Client MAC:45:85:00:b1:14:e4, Client IP:10.20.44.106, AP MAC:48:90:a5:cb:9c:80, AP Name:AP4810.7A70.464A&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;1093&lt;/TD&gt;
&lt;TD&gt;Fri Jan 26 18:18:09 2018&lt;/TD&gt;
&lt;TD&gt;Client Authenticated: MAC Address:45:85:00:b1:14:e4 base Radio MAC:48:90:a5:cb:9c:80 Slot: 1 User Name:test IP Addr:10.20.44.106 SSID:Guest&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't seem to find any information on what "Authentication rejected because of challenge failure ReasonCode: 15" corresponds to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 15:10:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320075#M139904</guid>
      <dc:creator>gyip</dc:creator>
      <dc:date>2021-07-05T15:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication rejected because of challenge failure ReasonCode: 15</title>
      <link>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320092#M139905</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/458134"&gt;@gyip&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Reason:Authentication rejected because of challenge failure ReasonCode: 15&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;4-way handshake timeout.&lt;/P&gt;
&lt;P&gt;This means that during the initial phase of authentication the wireless client didn't respond or didn't respond within the time frame.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2018 07:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320092#M139905</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2018-01-27T07:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication rejected because of challenge failure ReasonCode: 15</title>
      <link>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320095#M139906</link>
      <description>This happens on my mobile device, laptop and other laptops. Because of that I am thinking it has to be a setting on the controller.&lt;BR /&gt;</description>
      <pubDate>Sat, 27 Jan 2018 07:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320095#M139906</guid>
      <dc:creator>gyip</dc:creator>
      <dc:date>2018-01-27T07:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication rejected because of challenge failure ReasonCode: 15</title>
      <link>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320097#M139907</link>
      <description>It's not just a setting in the controller or WLAN but also the authentication server.</description>
      <pubDate>Sat, 27 Jan 2018 07:43:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320097#M139907</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2018-01-27T07:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication rejected because of challenge failure ReasonCode: 15</title>
      <link>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320101#M139908</link>
      <description>The authentication server is the wireless controller itself. I created a user by hand in the Local Net Users section. As you can also see by the trap that I am authenticated.&lt;BR /&gt;</description>
      <pubDate>Sat, 27 Jan 2018 08:05:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320101#M139908</guid>
      <dc:creator>gyip</dc:creator>
      <dc:date>2018-01-27T08:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication rejected because of challenge failure ReasonCode: 15</title>
      <link>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320103#M139909</link>
      <description>The client isn't authenticated.  I can see logs showing the clients associating and then attempt to authenticating before getting rejected due to timeout.</description>
      <pubDate>Sat, 27 Jan 2018 08:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320103#M139909</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2018-01-27T08:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication rejected because of challenge failure ReasonCode: 15</title>
      <link>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320557#M139910</link>
      <description>What link are you using when you configured 802.1x on the controller?  Seems to me that your configuration is most likely not correct.</description>
      <pubDate>Sun, 28 Jan 2018 20:55:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320557#M139910</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2018-01-28T20:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication rejected because of challenge failure ReasonCode: 15</title>
      <link>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320602#M139911</link>
      <description>I'm not really sure what link you are referring to.&lt;BR /&gt;I have Layer 3 configured on the WLAN to be a Web Policy and using Authentication. Then on the AAA Servers tab I only have LOCAL specified in the Authentication priority order for web-auth user.&lt;BR /&gt;To me it seems like authentication is working because in trap #1093 and #192 you will see "Client Authenticated" and also "User test logged in." On my computer after I enter the creds, the Success page is displayed and says I am logged in also. I have an IP address but when I ping 8.8.8.8 there is no response.&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Jan 2018 01:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3320602#M139911</guid>
      <dc:creator>gyip</dc:creator>
      <dc:date>2018-01-29T01:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication rejected because of challenge failure ReasonCode: 15</title>
      <link>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3321395#M139912</link>
      <description>&lt;P&gt;I've resolved my issue and just wanted to give everyone my resolution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I mentioned above, the authentication traps are indeed correct and show that the client was authenticated. The signs that point me to this conclusion were the fact that the traps show client authenticated (which is identical traps to when you&amp;nbsp;authenticate with radius and any other method successfully) in addition to the web auth success page.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a post auth ACL to restrict&amp;nbsp;access of my guest wireless network to internal resources by blocking all private IP address spaces. Because of I have DHCP coming from a server (rather than the wireless controller as the DHCP server), I needed to include the guest wireless network subnet as a permitted address space in the ACL.&amp;nbsp;It seems that the IP address range of the client wasn't implied and I had to explicitly grant access to it. Once I added it, everything works now.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 05:09:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/authentication-rejected-because-of-challenge-failure-reasoncode/m-p/3321395#M139912</guid>
      <dc:creator>gyip</dc:creator>
      <dc:date>2018-01-30T05:09:23Z</dc:date>
    </item>
  </channel>
</rss>

