<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with cisco ISE as proxy radius in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694589#M246498</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Perform client debugging on the WLC for the involved 'users' aka &lt;STRONG&gt;mac addresses&lt;/STRONG&gt; , you can have these analyzed with :&amp;nbsp;&lt;A href="https://cway.cisco.com/tools/WirelessDebugAnalyzer/" target="_blank"&gt;https://cway.cisco.com/tools/WirelessDebugAnalyzer/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Sep 2022 12:53:51 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2022-09-27T12:53:51Z</dc:date>
    <item>
      <title>Issues with cisco ISE as proxy radius</title>
      <link>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694520#M246481</link>
      <description>&lt;P&gt;I have problems with cisco ISE as proxy radius and WLC version 8.3.143.0. ISE sends the authentication request to the external radius, receives the access accept and returns it to the wlc. Aparently everything is working, I put the&amp;nbsp;On Access-Accept, continue to Authorization Policy&amp;nbsp;option in the&amp;nbsp;&lt;SPAN&gt;ISE external RADIUS sequence, and In the authorization profile I assign&amp;nbsp; the vlan 555.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;H3&gt;&lt;SPAN&gt;Steps&lt;/SPAN&gt;&lt;/H3&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11017&lt;/TD&gt;&lt;TD&gt;RADIUS created a new session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15049&lt;/TD&gt;&lt;TD&gt;Evaluating Policy Group&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15008&lt;/TD&gt;&lt;TD&gt;Evaluating Service Selection Policy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - Network Access.UserName&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - Radius.Called-Station-ID&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11358&lt;/TD&gt;&lt;TD&gt;Received request for RADIUS server sequence.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11361&lt;/TD&gt;&lt;TD&gt;Valid incoming authentication request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11355&lt;/TD&gt;&lt;TD&gt;Start forwarding request to remote RADIUS server&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11365&lt;/TD&gt;&lt;TD&gt;Modify attributes before sending request to external radius server&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11100&lt;/TD&gt;&lt;TD&gt;RADIUS-Client about to send request - ( port = 1812 )&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11101&lt;/TD&gt;&lt;TD&gt;RADIUS-Client received response&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11357&lt;/TD&gt;&lt;TD&gt;Successfully forwarded request to current remote RADIUS server&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24715&lt;/TD&gt;&lt;TD&gt;ISE has not confirmed locally previous successful machine authentication for user in Active Directory&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15036&lt;/TD&gt;&lt;TD&gt;Evaluating Authorization Policy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24209&lt;/TD&gt;&lt;TD&gt;Looking up Endpoint in Internal Endpoints IDStore -&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24211&lt;/TD&gt;&lt;TD&gt;Found Endpoint in Internal Endpoints IDStore&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - DEVICE.Device Type&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15016&lt;/TD&gt;&lt;TD&gt;Selected Authorization Profile - vlan-555&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;22081&lt;/TD&gt;&lt;TD&gt;Max sessions policy passed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;22080&lt;/TD&gt;&lt;TD&gt;New accounting session created in Session cache&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11002&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Accept&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;When I look in the wlc I see the user associated but not authenticated in spite of the fact that the user has been assigned to the rigth vlan and it has no ip address (there is a dhcp server in this vlan&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nataliacas_2-1664271924651.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/163519i0B2DBD64C8B9F571/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nataliacas_2-1664271924651.png" alt="nataliacas_2-1664271924651.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please any idea of what is happening&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 10:35:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694520#M246481</guid>
      <dc:creator>nataliacas</dc:creator>
      <dc:date>2022-09-27T10:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with cisco ISE as proxy radius</title>
      <link>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694554#M246485</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/204463-Configure-Maximum-Concurrent-User-Sessio.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-22/204463-Configure-Maximum-Concurrent-User-Sessio.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 11:39:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694554#M246485</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-09-27T11:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with cisco ISE as proxy radius</title>
      <link>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694579#M246494</link>
      <description>&lt;P&gt;thanks but I don´t have any problem with the number of concurrent sessions&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 12:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694579#M246494</guid>
      <dc:creator>nataliacas</dc:creator>
      <dc:date>2022-09-27T12:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with cisco ISE as proxy radius</title>
      <link>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694589#M246498</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Perform client debugging on the WLC for the involved 'users' aka &lt;STRONG&gt;mac addresses&lt;/STRONG&gt; , you can have these analyzed with :&amp;nbsp;&lt;A href="https://cway.cisco.com/tools/WirelessDebugAnalyzer/" target="_blank"&gt;https://cway.cisco.com/tools/WirelessDebugAnalyzer/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 12:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694589#M246498</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-09-27T12:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with cisco ISE as proxy radius</title>
      <link>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694625#M246499</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still have no idea where the problem is&amp;nbsp;&lt;/P&gt;&lt;P&gt;TimeTaskTranslated&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:20.214&lt;/TD&gt;&lt;TD&gt;*apfMsConnTask_5&lt;/TD&gt;&lt;TD&gt;Client made new Association to AP/BSSID BSSID 0c:27:24:76:84:ef AP T2-200-10-PA08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:20.214&lt;/TD&gt;&lt;TD&gt;*apfMsConnTask_5&lt;/TD&gt;&lt;TD&gt;The WLC/AP has found from client association request Information Element that claims PMKID Caching support&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:20.214&lt;/TD&gt;&lt;TD&gt;*apfMsConnTask_5&lt;/TD&gt;&lt;TD&gt;The Reassociation Request from the client comes with 0 PMKID&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:20.214&lt;/TD&gt;&lt;TD&gt;*apfMsConnTask_5&lt;/TD&gt;&lt;TD&gt;Client is entering the 802.1x or PSK Authentication state&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:20.214&lt;/TD&gt;&lt;TD&gt;*apfMsConnTask_5&lt;/TD&gt;&lt;TD&gt;Client has successfully cleared AP association phase&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:20.214&lt;/TD&gt;&lt;TD&gt;*apfMsConnTask_5&lt;/TD&gt;&lt;TD&gt;WLC/AP is sending an Association Response to the client with status code 0 = Successful association&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:20.216&lt;/TD&gt;&lt;TD&gt;*Dot1x_NW_MsgTask_7&lt;/TD&gt;&lt;TD&gt;Client will be required to Reauthenticate in 1800&lt;BR /&gt;seconds&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:20.216&lt;/TD&gt;&lt;TD&gt;*Dot1x_NW_MsgTask_7&lt;/TD&gt;&lt;TD&gt;WLC/AP is sending EAP-Identity-Request to the client&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:20.241&lt;/TD&gt;&lt;TD&gt;*Dot1x_NW_MsgTask_7&lt;/TD&gt;&lt;TD&gt;Client sent EAP-Identity-Response to WLC/AP&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:20.252&lt;/TD&gt;&lt;TD&gt;*Dot1x_NW_MsgTask_7&lt;/TD&gt;&lt;TD&gt;RADIUS Server permitted access&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:20.252&lt;/TD&gt;&lt;TD&gt;*Dot1x_NW_MsgTask_7&lt;/TD&gt;&lt;TD&gt;Client will be required to Reauthenticate in 1800&lt;BR /&gt;seconds&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:37.696&lt;/TD&gt;&lt;TD&gt;*spamApTask4&lt;/TD&gt;&lt;TD&gt;Client delete code: AP idle timeout, AP triggered client deauth&lt;BR /&gt;That can be due to possible reasons: Wired guest client has expired (no traffic)/ Default event for AP side triggered client delete. Normal scenarios would be idle timeout, AP radio issues, channel changes, etc.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:37.697&lt;/TD&gt;&lt;TD&gt;*spamApTask4&lt;/TD&gt;&lt;TD&gt;Client expiration timer code set for 1 seconds. The reason: Dissasociation or deauthentication received from client, this is valid on 802.11w scenario. Also, generic termination clause, reason would be provided by pervious log message&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:38.557&lt;/TD&gt;&lt;TD&gt;*apfReceiveTask&lt;/TD&gt;&lt;TD&gt;Client session has timed out&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Sep 27 15:08:38.557&lt;/TD&gt;&lt;TD&gt;*apfReceiveTask&lt;/TD&gt;&lt;TD&gt;Client session has timed out&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 27 Sep 2022 13:56:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694625#M246499</guid>
      <dc:creator>nataliacas</dc:creator>
      <dc:date>2022-09-27T13:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with cisco ISE as proxy radius</title>
      <link>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694628#M246500</link>
      <description>&lt;P&gt;&lt;SPAN&gt;it says "Normal scenarios would be idle timeout, AP radio issues, channel changes, etc." but I don´t have this problem with other users and SSID´s that are authenticated in ISE directly&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 13:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694628#M246500</guid>
      <dc:creator>nataliacas</dc:creator>
      <dc:date>2022-09-27T13:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with cisco ISE as proxy radius</title>
      <link>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694718#M246501</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Try to disable fast roaming (802.11r) or related settings, for the SSID , check if it can help for this type of client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 14:25:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694718#M246501</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-09-27T14:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with cisco ISE as proxy radius</title>
      <link>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694741#M246502</link>
      <description>&lt;P&gt;I have fast transition disable,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 15:01:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694741#M246502</guid>
      <dc:creator>nataliacas</dc:creator>
      <dc:date>2022-09-27T15:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with cisco ISE as proxy radius</title>
      <link>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694758#M246503</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Make sure client wireless drivers are up to date, for controller look at&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html&lt;/A&gt;&amp;nbsp;, upgrade advises 8.3.x is old , &lt;EM&gt;take care of access point model restrictions if any.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 15:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/issues-with-cisco-ise-as-proxy-radius/m-p/4694758#M246503</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-09-27T15:24:00Z</dc:date>
    </item>
  </channel>
</rss>

