<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061207#M269901</link>
    <description>&lt;P&gt;Disable and re-enable the SSID.&amp;nbsp; IF the clients are able to connect after that then it could be CSCwi18057/CSCwk17514.&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jun 2024 23:14:48 GMT</pubDate>
    <dc:creator>Leo Laohoo</dc:creator>
    <dc:date>2024-06-12T23:14:48Z</dc:date>
    <item>
      <title>Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061099#M269888</link>
      <description>&lt;P&gt;I'm trying to migrate from Cisco 5520 WLC to Cisco 9800 WLC. I configured the WLAN with 802.1x and the AP is in FlexConnect mode.&lt;/P&gt;&lt;P&gt;When the client is trying to connect I see it associate with the WLC, but then it gets stuck in authenticating status. I'm not seeing anything on the ISE side meaning nothing reaches ISE. I'm not seeing the client get an IP either. WLC logs show the client being deleted with the reason&amp;nbsp;&lt;SPAN&gt;L2AUTH_CONNECT_TIMEOUT. It seems like it might be all related to DHCP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;WLC - 9800 version 17.9.4a&lt;BR /&gt;Switch - 9300 version 17.9.4a&lt;BR /&gt;WLC only has the Management/AP Management SVI VLAN 5. Clients are using VLAN 100 which is only a layer 2 VLAN on the WLC. The switch has IP helpers for VLAN 100. The Policy only has Central Authentication enabled.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Edit: Added client trace output&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 20:18:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061099#M269888</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2024-04-08T20:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061196#M269899</link>
      <description>&lt;P&gt;What are the model of APs?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 22:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061196#M269899</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2024-04-08T22:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061198#M269900</link>
      <description>&lt;P&gt;The AP model is C9120AXI-B&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 22:14:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061198#M269900</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2024-04-08T22:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061207#M269901</link>
      <description>&lt;P&gt;Disable and re-enable the SSID.&amp;nbsp; IF the clients are able to connect after that then it could be CSCwi18057/CSCwk17514.&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 23:14:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061207#M269901</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2024-06-12T23:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061362#M269903</link>
      <description>&lt;P&gt;It doesn’t look like I’m hitting that bug. I’m not seeing those error logs.&lt;BR /&gt;&lt;BR /&gt;I did go ahead and make the SSID PSK and the client was able to grab an IP and connect without issues. So I have something funky with my 802.1x config(s)&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 02:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061362#M269903</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2024-04-09T02:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061871#M269911</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - Have the attached client trace analyzed with :&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank"&gt;Wireless Debug Analyzer&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; If that one doesn't work then use client debugging according to&amp;nbsp;&lt;A href="https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity" target="_blank"&gt;https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity&lt;/A&gt;&amp;nbsp; &amp;nbsp;and use those as input for&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank"&gt;Wireless Debug Analyzer&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; A summarizing view of client behavior can be obtained from :&amp;nbsp;&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc5" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#anc5&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;STRONG&gt;- Important :&lt;/STRONG&gt; have a checkup of your 9800 WLC configuration with the CLI command &lt;FONT color="#008000"&gt;&lt;STRONG&gt;show tech &lt;U&gt;wireless&lt;/U&gt;&lt;/STRONG&gt; &lt;/FONT&gt;and feed the output from that into :&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 07:46:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061871#M269911</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-04-09T07:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061939#M269912</link>
      <description>&lt;P&gt;Sorry can you check if you can ping radius server from AP since you use flex connect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 08:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5061939#M269912</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-09T08:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063426#M270079</link>
      <description>&lt;P&gt;I can ping from the AP to the radius server&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;AP&amp;gt;#ping &amp;lt;RADIUS IP&amp;gt;&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to &amp;lt;RADIUS IP&amp;gt;, timeout is 2 seconds&lt;/P&gt;&lt;P&gt;PING &amp;lt;RADIUS IP&amp;gt;&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 20.580/20.958/21.818 ms&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 17:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063426#M270079</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2024-04-09T17:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063586#M270082</link>
      <description>&lt;P&gt;Since you mentioned that "&lt;SPAN&gt;The Policy only has Central Authentication enabled", your authentication is supposed to be done via controller. It looks you are missing some AAA configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have you defined aaa authentication method using the correct radius group and server ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have you mapped authentication method in WLAN profile ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If yes, can you verify reachability of radius servers and status in WLC.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 19:10:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063586#M270082</guid>
      <dc:creator>PSM</dc:creator>
      <dc:date>2024-04-09T19:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063643#M270083</link>
      <description>&lt;P&gt;I did confirm I could reach the radius server from the WLC, AP, and switch the WLC was connected which also has the SVIs for the client networks. I mapped the authentication method in the WLAN profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been able to get it to work. I believe the issue was the aaa authentication config. I went back through the 802.1x WLAN guide for the 9800.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 03:08:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063643#M270083</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2024-04-10T03:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063807#M270085</link>
      <description>&lt;P&gt;So an update... I narrowed down my issue.&lt;/P&gt;&lt;P&gt;The radius/ISE server is configured to authenticate users on the 802.1x WLAN with MSCHAPv2 or PEAP (EAP-TLS). When the client auth side is set to MSCHAPv2 the client isn't able to authenticate or even get an IP, but when I change the client side network auth to PEAP (EAP-TLS) Machine Auth it works as expected.&lt;BR /&gt;&lt;BR /&gt;I did notice when the client was failing to authenticate while configured for MSCHAPv2 under the client information &amp;gt; General &amp;gt; Security it did not show an EAP type&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 04:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063807#M270085</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2024-04-10T04:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063815#M270087</link>
      <description>&lt;P&gt;CSCwf14041: C9120 stops forwarding EAP-Identity-Request to client intermittently&lt;/P&gt;
&lt;P&gt;CSCwh68219: 91xx AP not processing EAP-TLS server Hello&lt;/P&gt;
&lt;P&gt;CSCwi75798: 9120 didn't receive/transfer EAP response&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 04:37:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063815#M270087</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2024-04-10T04:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063822#M270089</link>
      <description>&lt;P&gt;Yikes…&lt;/P&gt;&lt;P&gt;Definitely matching for the first and last bug. I’ll double check if it changing it to PEAP helps at all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 04:47:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5063822#M270089</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2024-04-10T04:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5064205#M270105</link>
      <description>&lt;P&gt;Can I see&lt;/P&gt;
&lt;P&gt;Policy set and authc policy and authz policy you config in ISE.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 08:59:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5064205#M270105</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-04-10T08:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5065211#M270118</link>
      <description>&lt;P&gt;I changed to PEAP-MSCHAPv2 and it worked. Which makes it sound like I was hitting&amp;nbsp;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCwf14041" target="_blank" rel="noopener"&gt;CSCwf14041&lt;/A&gt;. &amp;nbsp;I changed back to EAP-MSCHAPv2 and now that works.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 17:41:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5065211#M270118</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2024-04-10T17:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5065585#M270124</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1416133"&gt;@Chris Terry&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;SPAN&gt;I changed back to EAP-MSCHAPv2 and now that works.&lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;EAP will work temporarily and then it will stop when the process crashes in the AP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An alternative fix is to regularly/daily reboot the AP.&amp;nbsp; Some people use EEM (or PI script) to reboot the AP.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 23:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5065585#M270124</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2024-04-10T23:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5067505#M270228</link>
      <description>&lt;P&gt;If it uses PEAP-MSCHAPv2 instead of EAP-MSCHAPv2 would it still run into that issue, or is it EAP as a whole that eventually has issues?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 17:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5067505#M270228</guid>
      <dc:creator>Chris Terry</dc:creator>
      <dc:date>2024-04-12T17:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 9800 Clients Can't Connect to FlexConnect 802.1x WLAN</title>
      <link>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5067805#M270232</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1416133"&gt;@Chris Terry&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;SPAN&gt;is it EAP as a whole that eventually has issues?&lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;It is an AP "buffer" thing.&amp;nbsp; It will work, usually after a reboot, and when the buffer gets filled up things go wrong and the multi-CPU of the AP is not fast enough to flush the buffer so "sometimes it may work" and may not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2024 23:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-9800-clients-can-t-connect-to-flexconnect-802-1x-wlan/m-p/5067805#M270232</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2024-04-12T23:31:25Z</dc:date>
    </item>
  </channel>
</rss>

