<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 9800-cl login with radius - shell:priv-lvl=15 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992187#M265048</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Not related to your original post but regarding to the console message :&lt;BR /&gt;&amp;nbsp;&lt;FONT color="#FF6600"&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;%SYS-5-CONFIG_P: Configured programmatically by process SE_webui_wsma_http from console as&lt;/FONT&gt; ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Take care and note :&amp;nbsp;&lt;A href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-cmdij-FzZAeXAy" target="_blank"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-cmdij-FzZAeXAy&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe12578" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe12578&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jan 2024 18:30:24 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2024-01-08T18:30:24Z</dc:date>
    <item>
      <title>9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992143#M265040</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've setup radius for admins to logon to our 9800 (with ISE) but when I logon to the web admin portal I cant see any admin options.&amp;nbsp; Just Monitoring and Dashboard.&lt;/P&gt;&lt;P&gt;CLI seems fine.&lt;/P&gt;&lt;P&gt;This is whats setup on the 9800:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;aaa new-model
aaa group server radius ISE
server name ise-1
server name ise-2
aaa authentication login default local
aaa authentication login radius-authe-method group ISE local
aaa authentication dot1x ISE group ISE
aaa authorization exec default local
aaa authorization exec radius-autho-method group ISE

radius server ise-1
address ipv4 10.52.7.106 auth-port 1812 acct-port 1813
key password
!
radius server ise-2
address ipv4 10.52.7.104 auth-port 1812 acct-port 1813
key password

line con 0
logging synchronous
stopbits 1
line vty 0 4
authorization exec radius-autho-method
login authentication radius-authe-method
transport input ssh
line vty 5 15
authorization exec radius-autho-method
login authentication radius-authe-method
transport input ssh
line vty 16 50
transport input ssh

ip http authentication aaa login-authentication radius-authe-method
ip http authentication aaa exec-authorization radius-autho-method
&lt;/LI-CODE&gt;&lt;P&gt;ISE has this on the profile:&lt;/P&gt;&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;cisco-av-pair = shell:priv-lvl=15&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 17:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992143#M265040</guid>
      <dc:creator>robbyde0100</dc:creator>
      <dc:date>2024-01-08T17:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992154#M265042</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/264783"&gt;@robbyde0100&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That config looks ok to me,&amp;nbsp; do you want to try to remove the following lines? you have already VTY covered so shouldn't be a problem.&lt;/P&gt;
&lt;P&gt;aaa authentication login default local&lt;BR /&gt;aaa authorization exec default local&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 17:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992154#M265042</guid>
      <dc:creator>Ruben Cocheno</dc:creator>
      <dc:date>2024-01-08T17:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992162#M265043</link>
      <description>&lt;P&gt;Thanks for getting back to me, I did&lt;/P&gt;&lt;P&gt;no aaa authentication login default local&lt;BR /&gt;no aaa authorization exec default local&lt;/P&gt;&lt;P&gt;Then logged on but had the same&lt;/P&gt;&lt;P&gt;.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cisco error 9800 2.png" style="width: 506px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206663iA12FA97495EB8115/image-size/large?v=v2&amp;amp;px=999" role="button" title="cisco error 9800 2.png" alt="cisco error 9800 2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I do see this on the console:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cisco error 9800.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206665iF3649ED0E4919D1A/image-size/large?v=v2&amp;amp;px=999" role="button" title="cisco error 9800.png" alt="cisco error 9800.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 17:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992162#M265043</guid>
      <dc:creator>robbyde0100</dc:creator>
      <dc:date>2024-01-08T17:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992168#M265044</link>
      <description>&lt;P&gt;show user&amp;nbsp;&lt;BR /&gt;check the user appear in which VTY line&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;also can you confirm that that you access WLC via ISE user or access WLC via Local user&amp;nbsp;&lt;BR /&gt;I know it hard if you use same username in both ISE and local but you can add privilege 15 to local username and hence you can full access to WLC if you use ISE or local.&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 17:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992168#M265044</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-08T17:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992173#M265045</link>
      <description>&lt;LI-CODE lang="markup"&gt;aaa authorization exec radius-autho-method group ISE LOCAL
&lt;/LI-CODE&gt;
&lt;P&gt;you need also to add LOCAL to end of authz&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:01:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992173#M265045</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-08T18:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992178#M265046</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;P&gt;I cant logon with the local 9800 admin account anymore.&lt;BR /&gt;&lt;BR /&gt;Show users shows&lt;/P&gt;&lt;P&gt;9800#sh users&lt;BR /&gt;Line User Host(s) Idle Location&lt;BR /&gt;* 1 vty 0 robd idle 00:00:00 laptop.domain.com&lt;/P&gt;&lt;P&gt;I'm using domain auth so using my domain admin to logon to ise which is ok, shows a successful auth in ISE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there config missing here for http:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;line vty 0 4
 authorization exec radius-autho-method
 login authentication radius-authe-method
 transport input ssh&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:10:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992178#M265046</guid>
      <dc:creator>robbyde0100</dc:creator>
      <dc:date>2024-01-08T18:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992184#M265047</link>
      <description>&lt;P&gt;I dislike deal with authc and authz of Cisco&amp;nbsp;&lt;BR /&gt;so you still can access to WLC ? via VTY SSH ?&lt;BR /&gt;MHM&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:27:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992184#M265047</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-08T18:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992187#M265048</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Not related to your original post but regarding to the console message :&lt;BR /&gt;&amp;nbsp;&lt;FONT color="#FF6600"&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;%SYS-5-CONFIG_P: Configured programmatically by process SE_webui_wsma_http from console as&lt;/FONT&gt; ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Take care and note :&amp;nbsp;&lt;A href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-cmdij-FzZAeXAy" target="_blank"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-cmdij-FzZAeXAy&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe12578" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe12578&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:30:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992187#M265048</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-01-08T18:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992192#M265049</link>
      <description>&lt;P&gt;I can logon via ssh with my domain account and get to config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just the web gui that doesn't work. I could log a tac.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992192#M265049</guid>
      <dc:creator>robbyde0100</dc:creator>
      <dc:date>2024-01-08T18:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992198#M265050</link>
      <description>&lt;PRE&gt;debug radius&lt;/PRE&gt;
&lt;P&gt;can you check by debug if radius return the AV priv 15 or not ?&lt;BR /&gt;MHM&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 19:07:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992198#M265050</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-08T19:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992504#M265076</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Its fixed!!&lt;/P&gt;&lt;P&gt;So in ISE there are two options that look the same:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cisco error 9800 both 9.png" style="width: 201px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206751i48C2A13AB5A8B3FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="cisco error 9800 both 9.png" alt="cisco error 9800 both 9.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This one doesnt work (guest should have given it away):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cisco error 9800 broken 8.png" style="width: 765px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206750i482132DFF5127478/image-size/large?v=v2&amp;amp;px=999" role="button" title="cisco error 9800 broken 8.png" alt="cisco error 9800 broken 8.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This one does work:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cisco error 9800 working 7.png" style="width: 706px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/206752i7BD133F5C84D1021/image-size/large?v=v2&amp;amp;px=999" role="button" title="cisco error 9800 working 7.png" alt="cisco error 9800 working 7.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 08:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992504#M265076</guid>
      <dc:creator>robbyde0100</dc:creator>
      <dc:date>2024-01-09T08:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992647#M265079</link>
      <description>&lt;P&gt;thanks a lot for update us&amp;nbsp;&lt;BR /&gt;glad the issue solved&amp;nbsp;&lt;BR /&gt;have a nice day&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 09:58:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992647#M265079</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-09T09:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: 9800-cl login with radius - shell:priv-lvl=15</title>
      <link>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992680#M265082</link>
      <description>&lt;P&gt;Thanks for all your help, really appreciate it.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 10:53:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9800-cl-login-with-radius-shell-priv-lvl-15/m-p/4992680#M265082</guid>
      <dc:creator>robbyde0100</dc:creator>
      <dc:date>2024-01-09T10:53:47Z</dc:date>
    </item>
  </channel>
</rss>

