<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Web Auth with Microsoft NPS in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3370084#M171913</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a 5520 controller, I already setup the wlan autentication with RADIUS on the AAA Servers, Security-&amp;gt;Leyer 2 in 802.1X and WPA2, Security-&amp;gt;Leyer 3&amp;nbsp; in NONE and works fine.&lt;/P&gt;
&lt;P&gt;The users get authenticated against the AD via RADIUS.&lt;/P&gt;
&lt;P&gt;My problem is if I change the WLAN authentication to Web Policy with Local webauth, and the same RADIUS, the authentication fail showing a invalid user or password message.&lt;/P&gt;
&lt;P&gt;First, its is possible?. If so, what is worong?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 15:32:41 GMT</pubDate>
    <dc:creator>Rafael Jimenez</dc:creator>
    <dc:date>2021-07-05T15:32:41Z</dc:date>
    <item>
      <title>Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3370084#M171913</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a 5520 controller, I already setup the wlan autentication with RADIUS on the AAA Servers, Security-&amp;gt;Leyer 2 in 802.1X and WPA2, Security-&amp;gt;Leyer 3&amp;nbsp; in NONE and works fine.&lt;/P&gt;
&lt;P&gt;The users get authenticated against the AD via RADIUS.&lt;/P&gt;
&lt;P&gt;My problem is if I change the WLAN authentication to Web Policy with Local webauth, and the same RADIUS, the authentication fail showing a invalid user or password message.&lt;/P&gt;
&lt;P&gt;First, its is possible?. If so, what is worong?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 15:32:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3370084#M171913</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2021-07-05T15:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3370171#M171914</link>
      <description>&lt;P&gt;good day Rafael,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;some pieces of information would be great to address this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;from the controller enable the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;debug aaa all enable&lt;/P&gt;
&lt;P&gt;debug client &amp;lt;mac address of test machine&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;once those are enable try to connect the test machine x3 times, attach the terminal output to this chain let's see.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 22:35:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3370171#M171914</guid>
      <dc:creator>H-H</dc:creator>
      <dc:date>2018-04-20T22:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371203#M171915</link>
      <description>&lt;P&gt;Good day H-H,&lt;/P&gt;
&lt;P&gt;this is the output:&lt;/P&gt;
&lt;P&gt;(Cisco Controller) &amp;gt;debug client B0:DF:3A:DA:F4:A2&lt;/P&gt;
&lt;P&gt;(Cisco Controller) &amp;gt;*ewmwebWebauth1: Apr 23 10:56:19.765: b0:df:3a:da:f4:a2 Username entry (rjimenez) created for mobile, length = 8&lt;BR /&gt;*ewmwebWebauth1: Apr 23 10:56:29.871: b0:df:3a:da:f4:a2 Username entry 'rjimenez' is deleted for mobile from the UserName table&lt;BR /&gt;*ewmwebWebauth1: Apr 23 10:56:29.871: b0:df:3a:da:f4:a2 Username entry rjimenez deleted for mobile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The error in the client is :&lt;/P&gt;
&lt;P&gt;Login Error.&lt;/P&gt;
&lt;P&gt;The User Name and Password combination you have entered is invalid. Please try again.&lt;BR /&gt;*ewmwebWebauth1: Apr 23 10:56:29.871: b0:df:3a:da:f4:a2 Plumbing web-auth redirect rule due to user logout&lt;BR /&gt;*ewmwebWebauth1: Apr 23 10:56:29.871: b0:df:3a:da:f4:a2 Web Authentication failure for station&lt;BR /&gt;*ewmwebWebauth1: Apr 23 10:56:29.871: b0:df:3a:da:f4:a2 172.16.64.66 WEBAUTH_REQD (8) Reached ERROR: from line 6920&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 14:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371203#M171915</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2018-04-23T14:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371211#M171916</link>
      <description>&lt;P&gt;The windows server is 2012 R2 Standard.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 15:06:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371211#M171916</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2018-04-23T15:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371231#M171917</link>
      <description>&lt;P&gt;attached the full debug with 3 retries.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 15:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371231#M171917</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2018-04-23T15:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371279#M171918</link>
      <description>&lt;P&gt;Attached the capture on the radius server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 16:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371279#M171918</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2018-04-23T16:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371283#M171922</link>
      <description>&lt;P&gt;Rafa,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;debug is not complete, for example could not seen the debug aaa all enable output, however with the debug provided i can see the client being blacklisted, lets first remove any "exclusion" configuration from the SSID, also from the NPS for testing can you increase the timeout timers?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="table table--bordered table--wrap table--row--highlight table--nowrap--col--1"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH class="ng-scope"&gt;Time&lt;/TH&gt;
&lt;TH class="ng-scope"&gt;Task&lt;/TH&gt;
&lt;TH class="ng-scope"&gt;Translated&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:15:13.067&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*DHCP Socket Task&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Received DHCP request from client&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:15:13.067&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*DHCP Socket Task&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Sending DHCP Discover to DHCP Server CP through gateway 172.16.64.1 on VLAN selected relay 2 - NONE (server address 0.0.0.0,local address 0.0.0.0, gateway 172.16.95.254, VLAN 908, port 1)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:15:13.068&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*DHCP Socket Task&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Received DHCP offer from server and transmitting to client&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:15:13.072&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*DHCP Socket Task&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Received DHCP request from client&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:15:13.072&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*DHCP Socket Task&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Sending DHCP Request to DHCP Server CP through gateway 172.16.64.1 requesting 172.16.64.66 on VLAN sending REQUEST to 172.16.95.254 (len 374, port 1, vlan 908)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:15:13.073&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*DHCP Socket Task&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Received DHCP ACK, assigning IP Address 172.16.64.66&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:15:13.073&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*DHCP Socket Task&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Received DHCP ACK from DHCP server&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:16:30.598&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*ewmwebWebauth1&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Client expiration timer code set for 10 seconds. The reason: Client deleted as it was blacklisted&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:16:40.626&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*apfReceiveTask&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Client disassociation event has occured. Possible reasons may be due to AP Radio Reset usually due to channel change or wlan was manually disabled or Client unable to get valid DHCP IP for WLAN using DHCP required&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:16:40.626&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*apfReceiveTask&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Client has been deauthenticated&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:16:40.626&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*apfReceiveTask&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Client expiration timer code set for 60 seconds. The reason: Client entry deleted after the exclusion timer expired (client was blacklisted)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="ng-scope"&gt;
&lt;TD class="ng-binding ng-scope"&gt;Apr 23 11:16:40.626&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;*apfReceiveTask&lt;/TD&gt;
&lt;TD class="ng-binding ng-scope"&gt;Client session has timed out&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Mon, 23 Apr 2018 16:35:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371283#M171922</guid>
      <dc:creator>CTSCloud.Europe</dc:creator>
      <dc:date>2018-04-23T16:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371286#M171925</link>
      <description>&lt;P&gt;Rafael,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the access reject came from the NPS server side.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 16:38:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371286#M171925</guid>
      <dc:creator>CTSCloud.Europe</dc:creator>
      <dc:date>2018-04-23T16:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371302#M171928</link>
      <description>&lt;P&gt;attached&amp;nbsp;new debug client&amp;nbsp;f0:4f:7c:da:22:09&lt;/P&gt;
&lt;P&gt;The NPS is Rejecting the request.&lt;/P&gt;
&lt;P&gt;I saw in other posts, something about the Dial-In Profile&amp;nbsp;and Service Type = Login.&lt;/P&gt;
&lt;P&gt;But I don't see this in NPS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 17:07:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371302#M171928</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2018-04-23T17:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371322#M171929</link>
      <description>Rafael,

i saw the capture and agree with the NPS is the one that is rejecting the authentication, i am not sure if NPS has a debug / log tool but let's investigate both of us, &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Mon, 23 Apr 2018 17:42:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371322#M171929</guid>
      <dc:creator>H-H</dc:creator>
      <dc:date>2018-04-23T17:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371427#M171930</link>
      <description>&lt;P&gt;Hello H-H,&lt;/P&gt;
&lt;P&gt;I installed the NPS following the the&amp;nbsp;Document ID: 115988.&lt;/P&gt;
&lt;P&gt;For some reason I dont know why the WLC with its IP was missing on the Conditions tab in the connection request policy created for wifi purpouse.&lt;/P&gt;
&lt;P&gt;Its working now.&lt;/P&gt;
&lt;P&gt;Thanks for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 20:27:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371427#M171930</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2018-04-23T20:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371463#M171931</link>
      <description>&lt;P&gt;Rafael,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;great to know that everything is working now.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 21:23:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3371463#M171931</guid>
      <dc:creator>H-H</dc:creator>
      <dc:date>2018-04-23T21:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Web Auth with Microsoft NPS</title>
      <link>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3385820#M171932</link>
      <description>&lt;P&gt;Complementing the configuration for &lt;STRONG&gt;Web Radius Authentication&lt;/STRONG&gt; with Microsoft NPS, its important be aware the protocol used in the Network policy&amp;nbsp;must be PAP instead of PEAP.&lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2018 00:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/web-auth-with-microsoft-nps/m-p/3385820#M171932</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2018-05-19T00:46:18Z</dc:date>
    </item>
  </channel>
</rss>

