<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Computer connecting to Wi-Fi - 802.1x - MAC auth. in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/computer-connecting-to-wi-fi-802-1x-mac-auth/m-p/4753025#M250322</link>
    <description>&lt;P&gt;Check whether your config looks like this:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;aaa authorization network &amp;lt;YOUR_LIST_HERE&amp;gt; local &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa attribute list&amp;nbsp;&amp;lt;YOUR_LIST_HERE&amp;gt; &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp; attribute type ssid "&amp;lt;YOUR_SSID_HERE&amp;gt; "&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;username &amp;lt;DEVICE_MAC&amp;gt; mac aaa attribute list &amp;lt;YOUR_LIST_HERE&amp;gt;&amp;nbsp; description WHATEVER&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;wlan&amp;nbsp;&amp;lt;YOUR_WLAN_PROF_HERE&amp;gt; 16 &amp;lt;YOUR_SSID_HERE&amp;gt;&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN&gt;&amp;nbsp; mac-filtering&amp;nbsp;&amp;lt;YOUR_LIST_HERE&amp;gt; &lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jan 2023 15:03:38 GMT</pubDate>
    <dc:creator>JPavonM</dc:creator>
    <dc:date>2023-01-11T15:03:38Z</dc:date>
    <item>
      <title>Computer connecting to Wi-Fi - 802.1x - MAC auth.</title>
      <link>https://community.cisco.com/t5/wireless/computer-connecting-to-wi-fi-802-1x-mac-auth/m-p/4752965#M250318</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Discovered something strange, and unexpected today.&lt;/P&gt;&lt;P&gt;We have multiple SSIDs. Regular company computers connect to a 802.1x enabled WLAN.&lt;/P&gt;&lt;P&gt;Then we have different SSID/network using PSK and MAC auth.&lt;/P&gt;&lt;P&gt;What I see is that if a computer is added to the list of devices that is allowed to connec to the PSK/MAC auth. network, it will no longer connect to the 802.1x network.&lt;BR /&gt;The same computer can connect to other SSIDs/networks that &lt;U&gt;only&lt;/U&gt; use PSK, while still being on the "allowed-list" for the PSK/MAC auth network.&lt;BR /&gt;So, this seems only to be a problem when connecting to the 802.1x based network.&lt;/P&gt;&lt;P&gt;Is this expected behaviour?&lt;/P&gt;&lt;P&gt;We're running Cisco 9800-CL 17.3.5b.&lt;/P&gt;&lt;P&gt;/Kenneth&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 12:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/computer-connecting-to-wi-fi-802-1x-mac-auth/m-p/4752965#M250318</guid>
      <dc:creator>kenneth.gregersen</dc:creator>
      <dc:date>2023-01-11T12:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Computer connecting to Wi-Fi - 802.1x - MAC auth.</title>
      <link>https://community.cisco.com/t5/wireless/computer-connecting-to-wi-fi-802-1x-mac-auth/m-p/4752973#M250319</link>
      <description>&lt;P&gt;&lt;BR /&gt;&amp;nbsp;- This page will give you a number of tools and commands for client debugging :&amp;nbsp;&lt;A href="https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity" target="_blank"&gt;https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity&lt;/A&gt;&amp;nbsp;, note that client RA Traces , can be analyzed with :&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank"&gt;https://cway.cisco.com/wireless-debug-analyzer/&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Besides that it's good practice to have a checkup of the current controller configuration&amp;nbsp;&lt;SPAN&gt;with the CLI command :&lt;/SPAN&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;show&amp;nbsp; tech&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;wireless&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;, have the output analyzed by&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://cway.cisco.com/tools/WirelessAnalyzer/" target="_blank" rel="noopener nofollow noreferrer" data-saferedirecturl="https://www.google.com/url?q=https://cway.cisco.com/tools/WirelessAnalyzer/&amp;amp;source=gmail&amp;amp;ust=1662270212514000&amp;amp;usg=AOvVaw1v8X824xUFwNwiDM_o5Fxf"&gt;https://cway.cisco.com/&lt;WBR /&gt;tools/WirelessAnalyzer/&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; , please note do not use classical&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;show tech-support&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;(short version) , use the command denoted in green for Wireless Analyzer.&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Checkout all advisories!&amp;nbsp; All items&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;red-flagged&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;should be corrected. For future use :&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;WirelessAnalyzer&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;can also make you aware of the RF environment such as coverage holes , APs under heavy load , APs undergoing frequent channel changes and so on. It is advised to use WirelessAnalyzer on a&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;regular basis&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;afterwards (even when current issues get resolved)&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 13:17:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/computer-connecting-to-wi-fi-802-1x-mac-auth/m-p/4752973#M250319</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-01-11T13:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Computer connecting to Wi-Fi - 802.1x - MAC auth.</title>
      <link>https://community.cisco.com/t5/wireless/computer-connecting-to-wi-fi-802-1x-mac-auth/m-p/4753025#M250322</link>
      <description>&lt;P&gt;Check whether your config looks like this:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;aaa authorization network &amp;lt;YOUR_LIST_HERE&amp;gt; local &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;aaa attribute list&amp;nbsp;&amp;lt;YOUR_LIST_HERE&amp;gt; &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp; attribute type ssid "&amp;lt;YOUR_SSID_HERE&amp;gt; "&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;username &amp;lt;DEVICE_MAC&amp;gt; mac aaa attribute list &amp;lt;YOUR_LIST_HERE&amp;gt;&amp;nbsp; description WHATEVER&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;wlan&amp;nbsp;&amp;lt;YOUR_WLAN_PROF_HERE&amp;gt; 16 &amp;lt;YOUR_SSID_HERE&amp;gt;&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN&gt;&amp;nbsp; mac-filtering&amp;nbsp;&amp;lt;YOUR_LIST_HERE&amp;gt; &lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 15:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/computer-connecting-to-wi-fi-802-1x-mac-auth/m-p/4753025#M250322</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2023-01-11T15:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Computer connecting to Wi-Fi - 802.1x - MAC auth.</title>
      <link>https://community.cisco.com/t5/wireless/computer-connecting-to-wi-fi-802-1x-mac-auth/m-p/4753088#M250327</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;It looks like this, and it seems to be OK.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;aaa authorization network MY-MAC-PSK-NETWORK local &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;aaa attribute list MY-MAC-PSK-NETWORK_FILTER&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;attribute type ssid "MY-MAC-PSK-NETWORK-SSID"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;!&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;!&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;username [MAC_ADDRESS] mac aaa attribute list MY-MAC-PSK-NETWORK_FILTER wlan-profile-name MY-MAC-PSK-NETWORK-SSID description "SOME DESCRIPTION"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;username [MAC_ADDRESS] mac aaa attribute list MY-MAC-PSK-NETWORK_FILTER wlan-profile-name MY-MAC-PSK-NETWORK-SSID description "SOME DESCRIPTION"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;username [MAC_ADDRESS] mac aaa attribute list MY-MAC-PSK-NETWORK_FILTER wlan-profile-name MY-MAC-PSK-NETWORK-SSID description "SOME DESCRIPTION" &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;!&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;!&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;wlan MY-MAC-PSK-NETWORK-NAME 205 MY-MAC-PSK-NETWORK-SSID&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;assisted-roaming dual-list&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;assisted-roaming prediction&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;no chd&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;mac-filtering MY-MAC-PSK-NETWORK_FILTER&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;peer-blocking drop&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;no security ft adaptive&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;security wpa psk set-key ascii 0 ********&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;no security wpa akm dot1x&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;security wpa akm psk&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;no shutdown&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Keep in mind that both the PSK/MAC auth. WLAN and the 802.1x WLANs are working as expected.&lt;/P&gt;&lt;P&gt;The problem is that when I add a computer to the PSK/MAC auth. list, it's no longer able to connect to the 802.1x based WLAN&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 17:35:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/computer-connecting-to-wi-fi-802-1x-mac-auth/m-p/4753088#M250327</guid>
      <dc:creator>kenneth.gregersen</dc:creator>
      <dc:date>2023-01-11T17:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Computer connecting to Wi-Fi - 802.1x - MAC auth.</title>
      <link>https://community.cisco.com/t5/wireless/computer-connecting-to-wi-fi-802-1x-mac-auth/m-p/4753210#M250330</link>
      <description>&lt;P&gt;i believe that is a Local auth Limitation, you need to have an External Radius to handle this kind of condition (like ISE)&lt;/P&gt;
&lt;P&gt;depends on the code running check the documentation :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/wireless-web-authentication.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/wireless-web-authentication.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 20:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/computer-connecting-to-wi-fi-802-1x-mac-auth/m-p/4753210#M250330</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-01-11T20:58:07Z</dc:date>
    </item>
  </channel>
</rss>

