<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cisco wlc 3504 ssid authentication windows AD in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/cisco-wlc-3504-ssid-authentication-windows-ad/m-p/4580602#M240145</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Below you will find the output of your debug file when processed by :&amp;nbsp;&amp;nbsp;&lt;A href="https://cway.cisco.com/tools/WirelessDebugAnalyzer/" target="_blank" rel="noopener"&gt;https://cway.cisco.com/tools/WirelessDebugAnalyzer/&lt;/A&gt;&amp;nbsp;, you may want to disabled fast roaming (for a test) , &lt;EM&gt;check if that can help. &lt;/EM&gt;And since the&amp;nbsp; &lt;FONT color="#FF0000"&gt;radius error&lt;/FONT&gt; , check the radius server&lt;STRONG&gt; logs&lt;/STRONG&gt; too&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showTime-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowTimeFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show Time&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showTask-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowTaskFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show Task&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showTranslated-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowTranslatedFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show Translated&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showOriginal-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowOriginalFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show Original&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showPriorFC-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowPriorFCFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show Prior First Connection&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showAll-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowAllFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show All&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR /&gt;
&lt;P&gt;TimeTaskTranslated&lt;/P&gt;
&lt;TABLE class="table table--striped table--wrapped table--bordered"&gt;
&lt;THEAD&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;Client made new Association to AP/BSSID BSSID 84:f1:47:c5:58:e8 AP 3F-AP4-Corridor4&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;The Reassociation Request from the client comes with 0 PMKID&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;The Reassociation Request from the client comes with 0 PMKID&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;Client is entering the 802.1x or PSK Authentication state&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;Client has successfully cleared AP association phase&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;WLC/AP is sending an Association Response to the client with status code 0 = Successful association&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.972&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;Client will be required to Reauthenticate in 1800&lt;BR /&gt;seconds&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.972&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;WLC/AP is sending EAP-Identity-Request to the client&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.992&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;WLC/AP is sending EAP-Identity-Request to the client&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:45:10.084&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;Client sent EAP-Identity-Response to WLC/AP&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:45:10.087&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;&lt;FONT color="#FF0000"&gt;RADIUS Server denied access&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:45:14.946&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;WLC/AP is sending EAP-Identity-Request to the client&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
    <pubDate>Tue, 29 Mar 2022 10:50:15 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2022-03-29T10:50:15Z</dc:date>
    <item>
      <title>cisco wlc 3504 ssid authentication windows AD</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-3504-ssid-authentication-windows-ad/m-p/4580574#M240142</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;need help with windows 10 clients trying to connect SSID using AD authentication not working&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 09:52:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-3504-ssid-authentication-windows-ad/m-p/4580574#M240142</guid>
      <dc:creator>edwincharles</dc:creator>
      <dc:date>2022-03-29T09:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: cisco wlc 3504 ssid authentication windows AD</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-3504-ssid-authentication-windows-ad/m-p/4580592#M240143</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Go through these:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/211277-WLC-with-LDAP-Authentication-Configurati.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/211277-WLC-with-LDAP-Authentication-Configurati.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/108008-ldap-web-auth-wlc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/108008-ldap-web-auth-wlc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Dont forget to rate helpful posts&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 10:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-3504-ssid-authentication-windows-ad/m-p/4580592#M240143</guid>
      <dc:creator>Sandeep Choudhary</dc:creator>
      <dc:date>2022-03-29T10:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: cisco wlc 3504 ssid authentication windows AD</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-3504-ssid-authentication-windows-ad/m-p/4580596#M240144</link>
      <description>&lt;P&gt;I saw some informations on the log that called my attention and I´d like you to take a look:&lt;/P&gt;&lt;P&gt;site 'default-group', interface 'savc-guest-interface'&lt;/P&gt;&lt;P&gt;Assigning flex webauth ACL ID :65535 for vlan : 8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the interface for this SSID is named guest for some reason or it is intended to be guest network? Also, take care with default group. It may trick you on some things like WLAN ID, for example. Ideally, avoid use it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, you problem is related to this log:&lt;/P&gt;&lt;P&gt;Processing Access-Reject for mobile 00:28:f8:d3:13:cd&lt;BR /&gt;Entering Backend Auth Failure state (id=-1) for mobile 00:28:f8:d3:13:cd&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And for that, you need to look at the Authenticion server. There might be the answer on why client had been refused. It can be wrong certificate, wrong credentials and so on and so forth.&lt;/P&gt;&lt;P&gt;The fact is, whatever it might be, the answers is on the authentication server or on the client.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 10:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-3504-ssid-authentication-windows-ad/m-p/4580596#M240144</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-03-29T10:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: cisco wlc 3504 ssid authentication windows AD</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-3504-ssid-authentication-windows-ad/m-p/4580602#M240145</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Below you will find the output of your debug file when processed by :&amp;nbsp;&amp;nbsp;&lt;A href="https://cway.cisco.com/tools/WirelessDebugAnalyzer/" target="_blank" rel="noopener"&gt;https://cway.cisco.com/tools/WirelessDebugAnalyzer/&lt;/A&gt;&amp;nbsp;, you may want to disabled fast roaming (for a test) , &lt;EM&gt;check if that can help. &lt;/EM&gt;And since the&amp;nbsp; &lt;FONT color="#FF0000"&gt;radius error&lt;/FONT&gt; , check the radius server&lt;STRONG&gt; logs&lt;/STRONG&gt; too&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showTime-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowTimeFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show Time&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showTask-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowTaskFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show Task&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showTranslated-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowTranslatedFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show Translated&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showOriginal-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowOriginalFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show Original&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showPriorFC-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowPriorFCFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show Prior First Connection&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;DIV class="form-group form-group--inline"&gt;&lt;LABEL class="checkbox"&gt;&lt;INPUT id="showAll-filter" class="ng-untouched ng-pristine ng-valid" type="checkbox" data-auto-id="Results-ShowAllFilter-Checkbox" /&gt;&lt;SPAN class="checkbox__label"&gt;Show All&lt;/SPAN&gt;&lt;/LABEL&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR /&gt;
&lt;P&gt;TimeTaskTranslated&lt;/P&gt;
&lt;TABLE class="table table--striped table--wrapped table--bordered"&gt;
&lt;THEAD&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;Client made new Association to AP/BSSID BSSID 84:f1:47:c5:58:e8 AP 3F-AP4-Corridor4&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;The Reassociation Request from the client comes with 0 PMKID&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;The Reassociation Request from the client comes with 0 PMKID&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;Client is entering the 802.1x or PSK Authentication state&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;Client has successfully cleared AP association phase&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.967&lt;/TD&gt;
&lt;TD&gt;*apfMsConnTask_7&lt;/TD&gt;
&lt;TD&gt;WLC/AP is sending an Association Response to the client with status code 0 = Successful association&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.972&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;Client will be required to Reauthenticate in 1800&lt;BR /&gt;seconds&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.972&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;WLC/AP is sending EAP-Identity-Request to the client&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:44:40.992&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;WLC/AP is sending EAP-Identity-Request to the client&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:45:10.084&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;Client sent EAP-Identity-Response to WLC/AP&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:45:10.087&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;&lt;FONT color="#FF0000"&gt;RADIUS Server denied access&lt;/FONT&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Mar 29 12:45:14.946&lt;/TD&gt;
&lt;TD&gt;*Dot1x_NW_MsgTask_5&lt;/TD&gt;
&lt;TD&gt;WLC/AP is sending EAP-Identity-Request to the client&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 29 Mar 2022 10:50:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-3504-ssid-authentication-windows-ad/m-p/4580602#M240145</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-03-29T10:50:15Z</dc:date>
    </item>
  </channel>
</rss>

