<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4862776#M257472</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &lt;A href="https://community.cisco.com/t5/cisco-digital-network-architecture-dna/9800-wlc-netconf-failing-with-dna/td-p/4554567" target="_blank"&gt;https://community.cisco.com/t5/cisco-digital-network-architecture-dna/9800-wlc-netconf-failing-with-dna/td-p/4554567&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For first setup, you need to use local auth&lt;/P&gt;
&lt;P class="p1"&gt;aaa authentication login default local&lt;/P&gt;
&lt;P class="p1"&gt;aaa authorization exec default local&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jun 2023 20:40:12 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2023-06-26T20:40:12Z</dc:date>
    <item>
      <title>NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho</title>
      <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4862751#M257470</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I am trying to add our WLC 9800 in DNA Center, but for some reason we're the NETCONF isn't working. NETCONF is already configured on the WLC with the SNMP community is fine until here. When I go to the DNA Center and try to validate the credencials I can see this:&lt;/P&gt;&lt;P&gt;CLI (check mark OK)&lt;BR /&gt;SNMP (check mark OK)&lt;BR /&gt;NETCONF (X in red color)&lt;/P&gt;&lt;P&gt;As I mentioned before, the NETCONF is configured and to be able to access the WLC we use TACACs throughout Cisco ISE, all of our accounts have the 15 priviledge.&lt;/P&gt;&lt;P&gt;I was able to catch this log on the wlc 9800&lt;/P&gt;&lt;P&gt;%5-authentication failed: chassis 1 R0/0: dmiauthd: Authentication failure for netconf over ssh&lt;/P&gt;&lt;P&gt;And below you can find my configuration about AAA authentication.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa group server tacacs+ SRV_Tacacs&lt;BR /&gt;server name Serv_Tacacs_172.16.21.11&lt;BR /&gt;server name Serv_Tacacs_172.21.11.11&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login Tacacs-authentication group SRV_Tacacs local&lt;BR /&gt;aaa authorization exec Tacacs-authorization group SRV_Tacacs if-authenticated&lt;BR /&gt;aaa authorization network default local&lt;BR /&gt;aaa accounting exec Tacacs_Authorization_Accounting start-stop group SRV_Tacacs&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;ip http authentication aaa login-authentication Tacacs-authentication&lt;BR /&gt;ip http authentication aaa exec-authorization Tacacs-authorization&lt;BR /&gt;commands configure include aaa attribute list&lt;BR /&gt;commands configure include aaa attribute&lt;BR /&gt;commands configure include aaa&lt;BR /&gt;commands exec include show aaa local&lt;BR /&gt;commands exec include show aaa&lt;BR /&gt;wireless aaa policy default-aaa-policy&lt;BR /&gt;aaa-override&lt;/P&gt;&lt;P&gt;I am not sure if I have to add or modify something else on ISE side or on the WLC.&lt;/P&gt;&lt;P&gt;Any thought?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 19:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4862751#M257470</guid>
      <dc:creator>Scott12</dc:creator>
      <dc:date>2023-06-26T19:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho</title>
      <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4862759#M257471</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I think NETCONF has limitation where is only works with&lt;/SPAN&gt; "default" &lt;SPAN&gt;AAA method lists for login and authorization, make sure you are only using default method list and not others, give it a try. Share result after change. &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 20:20:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4862759#M257471</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2023-06-26T20:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho</title>
      <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4862776#M257472</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &lt;A href="https://community.cisco.com/t5/cisco-digital-network-architecture-dna/9800-wlc-netconf-failing-with-dna/td-p/4554567" target="_blank"&gt;https://community.cisco.com/t5/cisco-digital-network-architecture-dna/9800-wlc-netconf-failing-with-dna/td-p/4554567&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For first setup, you need to use local auth&lt;/P&gt;
&lt;P class="p1"&gt;aaa authentication login default local&lt;/P&gt;
&lt;P class="p1"&gt;aaa authorization exec default local&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 20:40:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4862776#M257472</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-06-26T20:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho</title>
      <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4863329#M257511</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Let see if I understood, what I have to do is remove my tacacs configuration and use the local auth, then reconfigure the tacacs authentication, is it?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 16:22:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4863329#M257511</guid>
      <dc:creator>Scott12</dc:creator>
      <dc:date>2023-06-27T16:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho</title>
      <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4863337#M257514</link>
      <description>&lt;P&gt;Yeah, for discovery use only local. Then, after discovery you can push the proper&amp;nbsp; tacacs config to device during the provisioning&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 16:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4863337#M257514</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-06-27T16:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho</title>
      <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4863430#M257532</link>
      <description>&lt;P&gt;Ok gotcha, I will go ahead and will modify the tacacs config, I will put the aaa local and finally add again the tacacs config.&lt;/P&gt;&lt;P&gt;I come back tomorrow and I will put it here my inputs.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 18:47:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/4863430#M257532</guid>
      <dc:creator>Scott12</dc:creator>
      <dc:date>2023-06-27T18:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho</title>
      <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/5227142#M278002</link>
      <description>&lt;P&gt;Did you fix this issue by adding the local authentication ? could you please update the status here ? I am also facing the same issue&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 09:42:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/5227142#M278002</guid>
      <dc:creator>AseebKatteri6492</dc:creator>
      <dc:date>2024-11-21T09:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho</title>
      <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/5228080#M278068</link>
      <description>&lt;P&gt;As already provided, you can directly go to the &lt;A href="https://themagistvapp.com.co/" target="_self"&gt;:&lt;/A&gt;&lt;A href="https://community.cisco.com/t5/cisco-catalyst-center/9800-wlc-netconf-failing-with-dna/td-p/4554567" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/cisco-catalyst-center/9800-wlc-netconf-failing-with-dna/td-p/4554567&lt;/A&gt;&amp;nbsp;to resolve your issue.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Aug 2025 21:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/5228080#M278068</guid>
      <dc:creator>shanewatson5091</dc:creator>
      <dc:date>2025-08-17T21:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho</title>
      <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/5230576#M278288</link>
      <description>&lt;P&gt;Im facing the same issue as well, and I already did:&lt;/P&gt;
&lt;P&gt;add aaa login default local:&lt;BR /&gt;aaa authentication login default group ISE-Tacacs+ local&lt;BR /&gt;aaa authentication login Tacacs-Auth local group ISE-Tacacs+&lt;BR /&gt;aaa authorization exec default group ISE-Tacacs+ local &lt;BR /&gt;aaa authorization exec Tacacs-Autho local group ISE-Tacacs+&lt;/P&gt;
&lt;P&gt;My vtys line:&lt;/P&gt;
&lt;P&gt;line vty 0 4&lt;BR /&gt;authorization exec Tacacs-Autho&lt;BR /&gt;accounting exec Tacacs-Autho-VTY&lt;BR /&gt;logging synchronous&lt;BR /&gt;login authentication Tacacs-Auth&lt;BR /&gt;length 0&lt;BR /&gt;transport input ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt;authorization exec Tacacs-Autho&lt;BR /&gt;accounting exec Tacacs-Autho-VTY&lt;BR /&gt;logging synchronous&lt;BR /&gt;login authentication Tacacs-Auth&lt;BR /&gt;transport input ssh&lt;/P&gt;
&lt;P&gt;in wlc logs:&lt;/P&gt;
&lt;P&gt;%DMI-5-AUTHENTICATION_FAILED: Chassis 1 R0/0: dmiauthd: Authentication failure from X.X.X.X:32568 for netconf over ssh.&lt;/P&gt;
&lt;P&gt;Netconf still not working&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 14:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/5230576#M278288</guid>
      <dc:creator>Jrmonegro</dc:creator>
      <dc:date>2024-11-29T14:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho</title>
      <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/5230577#M278289</link>
      <description>&lt;P&gt;Is it work? remove tacacs configuration, and use only local for discovery process then add again tacacs config?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 14:13:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/5230577#M278289</guid>
      <dc:creator>Jrmonegro</dc:creator>
      <dc:date>2024-11-29T14:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: NETCONF isn't working with DNAC + WLC 9800 + TACACs auth,autho</title>
      <link>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/5230676#M278310</link>
      <description>&lt;P&gt;In order for this to work, you need&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;authorization exec default &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;on your vty lines.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2024 19:15:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/netconf-isn-t-working-with-dnac-wlc-9800-tacacs-auth-autho/m-p/5230676#M278310</guid>
      <dc:creator>liviu.gheorghe</dc:creator>
      <dc:date>2024-11-29T19:15:55Z</dc:date>
    </item>
  </channel>
</rss>

