<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with Shared NAR in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/issue-with-shared-nar/m-p/2229167#M217841</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sohail,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user wlan.test01 is getting the right group VIP_AD_GROUP. However, it seems your NAR setting are configured on user and group setup both. You need to disable NAR on the user&lt;STRONG&gt; wlan.test01&lt;/STRONG&gt; by editing the user and unchecking "&lt;STRONG&gt;only allow network access when&lt;/STRONG&gt;" the third screen shot shows that settings. Only enable NAR on groups like you have configured in first and second screen shots for VIP and CORP. Disable it on user setup and try again it should work without any issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Jul 2013 04:56:32 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-07-08T04:56:32Z</dc:date>
    <item>
      <title>Issue with Shared NAR</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-shared-nar/m-p/2229163#M217837</link>
      <description>&lt;P&gt;Hi All, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have WLC 5508 which is integrated to ACS 4.2 and MS AD. User Groups are mapped on ACS. Each groups is assigned to a SSID. Now, I want to restrict user of each group to come up with the corresponding SSID. I have 4 x SSIDs &amp;amp; Groups as&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Corp&lt;/P&gt;&lt;P&gt;- IT&lt;/P&gt;&lt;P&gt;- VIP&lt;/P&gt;&lt;P&gt;- Consultant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured Shared NARs for each Group with CLI as ANY and DNIC as corresponding SSID. For a user, who is a member of single group is authenticated successfully. But if a user is member of multiple groups, I am getting following error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="0" cellspacing="0" height="43" style="margin-left: 4.8pt; border-collapse: collapse; border: medium none; width: 1312px;"&gt;&lt;TBODY&gt;&lt;TR style="height: 15.0pt;"&gt;&lt;TD nowrap="nowrap" style="width: 54.8pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="73"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;Message-Type&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 76.5pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="102"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;User-Name&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 59.5pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="79"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;Group-Name&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 1.25in; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="120"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;Authen-Failure-Code&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 81.0pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="108"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;NAS-Port&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 63.0pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="84"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;NAS-IP-Address&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 94.5pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="126"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;Filter Information&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 45.0pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="60"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;EAP Type&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: .75in; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="72"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;EAP Type Name&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 45.0pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="60"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;Reason&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 117.0pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="156"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;Access Device&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 63.0pt; border: solid windowtext 1.0pt; border-left: none; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="84"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;Network Device Group&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15.0pt;"&gt;&lt;TD nowrap="nowrap" style="width: 54.8pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="73"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;SPAN style="color: #ff0000;"&gt;Authen failed&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 76.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="102"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;meraas\wlan.test01&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 59.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="79"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;VIP_AD_Group&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 211.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="282"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;Users Access Filtered&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 81.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="108"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;meraas\wlan.test01&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 63.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="84"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;172.30.1.10&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 157.5pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="210"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;SPAN style="color: #ff0000;"&gt;No Filters activated.&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 45.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="60"&gt;&lt;P align="right" style="margin-bottom: .0001pt; text-align: right; line-height: normal;"&gt;25&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: .75in; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="72"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;MS-PEAP&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 45.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="60"&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 117.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="156"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;EMAAR3-WL-CONTROLLER-01&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="nowrap" style="width: 63.0pt; border-top: none; border-left: none; border-bottom: solid windowtext 1.0pt; border-right: solid windowtext 1.0pt; padding: 0in 5.4pt 0in 5.4pt; height: 15.0pt;" valign="bottom" width="84"&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;WLC&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following are the screenshots of what I have configured on ACS on Shared NAR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have mapped 2 of the Shared NARs on User's Advanced settings to allow if any of the NARs results in permit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG src="https://community.cisco.com/" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following is the group mappings for the domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG src="https://community.cisco.com/" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Further, I have also configured NARs on each group for the users who member of only one group. That is working fine. But whenever a user who is member of 2 groups tries to authenticate, I am getting the mentioned error. Looking forward for help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sohail&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 07:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-shared-nar/m-p/2229163#M217837</guid>
      <dc:creator>Sohail Muhammad</dc:creator>
      <dc:date>2021-07-04T07:21:37Z</dc:date>
    </item>
    <item>
      <title>Issue with Shared NAR</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-shared-nar/m-p/2229164#M217838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sohail, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screen shots are not attached. Could you please post them again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wlan.test01 user is being assigned to VIP_AD_GROUP group on ACS and I'm sure that group is configured for some other SSID, that is why you're getting denied with User Access Filtered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please tell me Wlan.test01 user is part of what all AD groups?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Jul 2013 14:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-shared-nar/m-p/2229164#M217838</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-06T14:31:07Z</dc:date>
    </item>
    <item>
      <title>Issue with Shared NAR</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-shared-nar/m-p/2229165#M217839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/0/8/144809-4.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/0/8/144808-3.png" class="jive-image" /&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/0/8/144807-2.png" class="jive-image" /&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/0/8/144806-1.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Above are the screenshots. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sohail&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Jul 2013 04:06:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-shared-nar/m-p/2229165#M217839</guid>
      <dc:creator>Sohail Muhammad</dc:creator>
      <dc:date>2013-07-07T04:06:59Z</dc:date>
    </item>
    <item>
      <title>Issue with Shared NAR</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-shared-nar/m-p/2229166#M217840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;wlan.test01 is the member of VIP &amp;amp; Corp groups only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sohail&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Jul 2013 04:10:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-shared-nar/m-p/2229166#M217840</guid>
      <dc:creator>Sohail Muhammad</dc:creator>
      <dc:date>2013-07-07T04:10:39Z</dc:date>
    </item>
    <item>
      <title>Issue with Shared NAR</title>
      <link>https://community.cisco.com/t5/wireless/issue-with-shared-nar/m-p/2229167#M217841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sohail,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user wlan.test01 is getting the right group VIP_AD_GROUP. However, it seems your NAR setting are configured on user and group setup both. You need to disable NAR on the user&lt;STRONG&gt; wlan.test01&lt;/STRONG&gt; by editing the user and unchecking "&lt;STRONG&gt;only allow network access when&lt;/STRONG&gt;" the third screen shot shows that settings. Only enable NAR on groups like you have configured in first and second screen shots for VIP and CORP. Disable it on user setup and try again it should work without any issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 04:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issue-with-shared-nar/m-p/2229167#M217841</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-08T04:56:32Z</dc:date>
    </item>
  </channel>
</rss>

