<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC 9800 AAA issue in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-9800-aaa-issue/m-p/4673131#M245288</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - &lt;FONT color="#FF6600"&gt;FYI&lt;/FONT&gt; :&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Aug 2022 06:40:41 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2022-08-22T06:40:41Z</dc:date>
    <item>
      <title>WLC 9800 AAA issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-aaa-issue/m-p/4673040#M245279</link>
      <description>&lt;P&gt;Hi everybody.&lt;BR /&gt;I have WLC 9800 (17.3.3, 17.3.5b, 17.6.3) and ISE 2.7 and WIndows&amp;nbsp;clients.&lt;BR /&gt;Authorization in the ISE occurs using PEAP-TLS. (eap-tls + ms-chap v2)&lt;BR /&gt;There are 2 different rules configured on the ISE side.&lt;BR /&gt;When connected, the computer is subject to Rule No. 1 with a specific ACL. After entering the username and password, the user should get a different ACL list according to a different rule, but this does not happen. On the ISE side, I see the correct identification, but the second policy does not apply. Everything works correctly on the WLC 8540. Has anyone encountered a similar problem?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 19:32:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-aaa-issue/m-p/4673040#M245279</guid>
      <dc:creator>malkovich072</dc:creator>
      <dc:date>2022-08-21T19:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800 AAA issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-aaa-issue/m-p/4673057#M245282</link>
      <description>&lt;LI-CODE lang="markup"&gt;When connected, the computer is subject to Rule No. 1 with a specific ACL. After entering the username and password, the user should get a different ACL list according to a different rule, but this does not happen. On the ISE side, I see the correct identification, but the second policy does not apply.&lt;/LI-CODE&gt;
&lt;P&gt;what rule the user get applied ? (or user not at all applied any policies ?&lt;/P&gt;
&lt;P&gt;what client device ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what you see the Logs in ISE ?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 22:13:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-aaa-issue/m-p/4673057#M245282</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-08-21T22:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800 AAA issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-aaa-issue/m-p/4673076#M245283</link>
      <description>&lt;P&gt;Your description is not very clear, remember “problem well stated is problem half solved”, so try again.&lt;BR /&gt;Let me rephrase what I understood. You are using&amp;nbsp;&lt;SPAN&gt;PEAP-EAP-TLS instead of just EAP-TLS or PEAP, your authentication is successful, but during authorization correct dynamic ACL is not getting enforced by ISE on clients, because of which client do not get correct permission, is this correct problem statement ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;since it’s wireless, the ACL name is pushed through ISE but the ACL itself exist on&amp;nbsp;the controller with exact same name, so share your policy details and ACL details and failed ISE log details. If your authentication is successful, I can rule out client (supplicant) misconfiguration.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 01:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-aaa-issue/m-p/4673076#M245283</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2022-08-22T01:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800 AAA issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-aaa-issue/m-p/4673117#M245287</link>
      <description>&lt;P&gt;Sounds like a COA issue.&lt;/P&gt;
&lt;P&gt;Do you have the ACL defined on 9800 WLC? It has to match what ISE is sending.&lt;/P&gt;
&lt;P&gt;Also it is mandatory that you enable AAA overide and NAC state in the policy profile. Refer the below document for more info.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 05:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-aaa-issue/m-p/4673117#M245287</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-08-22T05:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800 AAA issue</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-aaa-issue/m-p/4673131#M245288</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - &lt;FONT color="#FF6600"&gt;FYI&lt;/FONT&gt; :&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 06:40:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-aaa-issue/m-p/4673131#M245288</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-08-22T06:40:41Z</dc:date>
    </item>
  </channel>
</rss>

