<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAP not able to join WLC in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4856089#M257177</link>
    <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;I have the APs configured like in the example. An authorization Method under "AAA method list" is configured as well. The selected Authorization profile is existing and configured as in the example. It is also selected in the Mesh Profile.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/187696iA77D4C6B242353FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The config analyzer has not found a mesh config error.&lt;/P&gt;&lt;P&gt;I find it confusing, that the AP is able to find the configured Authentication Profile but fails to find the selected authorization Profile, because both are selected in the Mesh Profile:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CiscoAdminxyz_2-1686907863708.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/187698i9002556EE9C0AC81/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CiscoAdminxyz_2-1686907863708.png" alt="CiscoAdminxyz_2-1686907863708.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The Mesh Profile is applied to the AP by a site-tag.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2023 09:36:24 GMT</pubDate>
    <dc:creator>Cisco Admin xyz</dc:creator>
    <dc:date>2023-06-16T09:36:24Z</dc:date>
    <item>
      <title>MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4854064#M257073</link>
      <description>&lt;P&gt;Dear Cisco Community&lt;/P&gt;&lt;P&gt;I am having Trouble, joining a Cisco MAP (9124AXI) to a Cisco 9800-L WLC through a Cisco RAP (also 9124AXI). In the Web-Interface of the WLC (Monitoring -&amp;gt; AP Statistics -&amp;gt; myRAP -&amp;gt; Mesh -&amp;gt; Neighbor) I can see the RAP recognizes the MAP as neighbor AP:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cisco Case neighbor ap.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/187404iD3DC60A1ED9E26BD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cisco Case neighbor ap.png" alt="Cisco Case neighbor ap.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But the MAP never actually joins the WLC. It nevers shows a message about a successful join.&lt;/P&gt;&lt;P&gt;Under radioactive trace I collected some logs on the WLC of the MAP. These Logs show "authz_list: Not present under wlan configuration". But the MAC Address of the MAP is stored in the AAA List "Device Authentication" on the WLC under "AAA Advanced". An AAA Method List for Authentication as well as a AAA List for Authorization are configured.&lt;/P&gt;&lt;P&gt;I expect the map to show up on the WLC under Configuration -&amp;gt; Access Points -&amp;gt; All Access Points after a successful join. Is that assumption wrong? Will the MAP even after a successfull join not show up there?&lt;/P&gt;&lt;P&gt;Do you have any suggestions for Troubleshooting?&lt;/P&gt;&lt;P&gt;Thanks for any answers in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 18:21:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4854064#M257073</guid>
      <dc:creator>Cisco Admin xyz</dc:creator>
      <dc:date>2023-06-13T18:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4854602#M257111</link>
      <description>&lt;P&gt;Have you configured it as per the example at the end of&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/215100-join-mesh-aps-to-catalyst-9800-wireless.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/215100-join-mesh-aps-to-catalyst-9800-wireless.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;&lt;SPAN&gt;Authentication and&amp;nbsp;Authorization&amp;nbsp;methods are configured under the mesh profile and then the mesh profile is configured in the AP join profile.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;That error though suggests you might be referencing&amp;nbsp;authz_list that doesn't exist - check your config carefully and using&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;https://cway.cisco.com/wireless-config-analyzer/&lt;/A&gt;&amp;nbsp;with the output of "show tech wireless"&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 13:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4854602#M257111</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-06-14T13:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4856089#M257177</link>
      <description>&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;I have the APs configured like in the example. An authorization Method under "AAA method list" is configured as well. The selected Authorization profile is existing and configured as in the example. It is also selected in the Mesh Profile.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/187696iA77D4C6B242353FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The config analyzer has not found a mesh config error.&lt;/P&gt;&lt;P&gt;I find it confusing, that the AP is able to find the configured Authentication Profile but fails to find the selected authorization Profile, because both are selected in the Mesh Profile:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CiscoAdminxyz_2-1686907863708.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/187698i9002556EE9C0AC81/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CiscoAdminxyz_2-1686907863708.png" alt="CiscoAdminxyz_2-1686907863708.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The Mesh Profile is applied to the AP by a site-tag.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 09:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4856089#M257177</guid>
      <dc:creator>Cisco Admin xyz</dc:creator>
      <dc:date>2023-06-16T09:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4856132#M257185</link>
      <description>&lt;P&gt;And what version of software are you using?&lt;BR /&gt;Make sure you're using latest TAC recommended version as per link below to ensure you have known bugfixes.&lt;/P&gt;
&lt;P&gt;If you're sure the config is correct and you've checked the names match exactly, and software is up to date - then time for a TAC case.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 10:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4856132#M257185</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-06-16T10:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4856325#M257197</link>
      <description>&lt;P&gt;I checked the configuration multiple times against the tutorial you sent me in your first post. It seems correctly configured to me. So I will&amp;nbsp; try upgrading the WLC to a newer Version.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 14:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4856325#M257197</guid>
      <dc:creator>Cisco Admin xyz</dc:creator>
      <dc:date>2023-06-16T14:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4857891#M257274</link>
      <description>&lt;P&gt;Did you fix the problem?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 21:19:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4857891#M257274</guid>
      <dc:creator>LC.IT</dc:creator>
      <dc:date>2023-06-19T21:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4858030#M257280</link>
      <description>&lt;P&gt;Not yet. But I will upgrade the WLC. Possibly that will solve the issue. I post my solution here once I found it. Do you have the same weird behavior?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 05:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4858030#M257280</guid>
      <dc:creator>Cisco Admin xyz</dc:creator>
      <dc:date>2023-06-20T05:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4858395#M257294</link>
      <description>&lt;P&gt;Yes, same problem and same AP model but I have EWC here running version 17.9.3&lt;/P&gt;
&lt;P&gt;Today I will try version 17.6.4&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 10:53:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4858395#M257294</guid>
      <dc:creator>LC.IT</dc:creator>
      <dc:date>2023-06-20T10:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4858496#M257296</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1230356"&gt;@LC.IT&lt;/a&gt;&amp;nbsp;&amp;nbsp;If you intend to downgrade to 17.6 then use 17.6.5 - &lt;STRONG&gt;not&lt;/STRONG&gt; 17.6.4!&lt;/P&gt;
&lt;P&gt;Always refer to current TAC recommended list (below).&amp;nbsp; Note that TAC are currently saying:&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Cisco recommends&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;17.9.3 CCO image&amp;nbsp;for all deployments.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 11:33:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4858496#M257296</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-06-20T11:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4859932#M257371</link>
      <description>&lt;P&gt;Here just works running 17.9.3 with PSK authentication. EAP failing on 17.6.4 and 17.9.3.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 02:20:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4859932#M257371</guid>
      <dc:creator>LC.IT</dc:creator>
      <dc:date>2023-06-22T02:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4865031#M257653</link>
      <description>&lt;P&gt;I came here from a link on Reddit. We had a similar issue on 17.6.X. TAC found the issue which&lt;SPAN&gt;&amp;nbsp;was that we had the Mesh Bridge Group Name set which was causing the MAP to not auth using EAP. We removed the the Bridge Group name and rebooted the MAP and it connected.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 09:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4865031#M257653</guid>
      <dc:creator>Infinite Networks Anthony</dc:creator>
      <dc:date>2023-06-30T09:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: MAP not able to join WLC</title>
      <link>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4921326#M260573</link>
      <description>&lt;P&gt;Sorry for posting the actual solution so late.&lt;/P&gt;&lt;P&gt;The MAP was not able to join the WLC because of a misconfiguration of our switchport to which the RAP was connected. In our environment we use dot1x or MAB to authenticate devices with Cisco ISE.&lt;/P&gt;&lt;P&gt;We allowed the Ethernet and Radio MACs of the MAP and RAP to join via MAB. In the ISE login we were able to see that Cisco ISE successfully authenticated the RAP using MAB and never saw an authentication error regarding the MAP.&lt;/P&gt;&lt;P&gt;But the MAP was not able to get authenticated because of the following configuration on the Switchport to which the RAP and therefore also the MAP were connected to our LAN: "&lt;STRONG&gt;access-session host-mode multi-domain&lt;/STRONG&gt;" This Settings allows only allows for one Data and One Voice VLAN Device to be authenticated on that specific switchport.&lt;/P&gt;&lt;P&gt;Changing this setting to "&lt;STRONG&gt;access-session host-mode multi-host&lt;/STRONG&gt;" or "&lt;STRONG&gt;access-session host-mode multi-auth"&amp;nbsp;&lt;/STRONG&gt;solved the problem since it allows for more than one Data-VLAN Device to be authenticated. You can read more here:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/access-session-host-mode-option-for-an-ap-port/td-p/3810472" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/access-session-host-mode-option-for-an-ap-port/td-p/3810472&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Another possability would be to remove the dot1x and MAB configurations from the port entirely but this would not be that secure.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 09:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/map-not-able-to-join-wlc/m-p/4921326#M260573</guid>
      <dc:creator>Cisco Admin xyz</dc:creator>
      <dc:date>2023-09-11T09:29:41Z</dc:date>
    </item>
  </channel>
</rss>

