<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco Catalyst 9800 Controller Type 6 Key/Password in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5123039#M272254</link>
    <description>&lt;P&gt;We have Cisco 9800 wireless controller with radius authentication with NPS servers. Its working as expected.&lt;/P&gt;&lt;P&gt;Now, Im trying to copy the radius configurations from this controller to another one (Same model, same IOS version), it wont accept the radius type 6 key/password. Specifically, error is as below:&lt;/P&gt;&lt;P&gt;WLC-9800(config)#aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt;client 1.1.1.1 server-key 6 XXXXYYYYZZZ&lt;/P&gt;&lt;P&gt;%invalid encrypted key: XXXXYYYYZZZ&lt;/P&gt;&lt;P&gt;% Could not define per-client secret.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Key has been taken from the working configuration as it is.&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Saif&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Jun 2024 19:22:46 GMT</pubDate>
    <dc:creator>saifuddin.miyaji</dc:creator>
    <dc:date>2024-06-02T19:22:46Z</dc:date>
    <item>
      <title>Cisco Catalyst 9800 Controller Type 6 Key/Password</title>
      <link>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5123039#M272254</link>
      <description>&lt;P&gt;We have Cisco 9800 wireless controller with radius authentication with NPS servers. Its working as expected.&lt;/P&gt;&lt;P&gt;Now, Im trying to copy the radius configurations from this controller to another one (Same model, same IOS version), it wont accept the radius type 6 key/password. Specifically, error is as below:&lt;/P&gt;&lt;P&gt;WLC-9800(config)#aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt;client 1.1.1.1 server-key 6 XXXXYYYYZZZ&lt;/P&gt;&lt;P&gt;%invalid encrypted key: XXXXYYYYZZZ&lt;/P&gt;&lt;P&gt;% Could not define per-client secret.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Key has been taken from the working configuration as it is.&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Saif&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 19:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5123039#M272254</guid>
      <dc:creator>saifuddin.miyaji</dc:creator>
      <dc:date>2024-06-02T19:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Catalyst 9800 Controller Type 6 Key/Password</title>
      <link>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5123203#M272267</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Where or are the 2 controllers running the same ios-xe&lt;STRONG&gt; version&lt;/STRONG&gt; ?&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Is the target controller on an&lt;STRONG&gt; older version&lt;/STRONG&gt; perhaps ?&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Can you use the key , when it's entered &lt;STRONG&gt;without encryption&lt;/STRONG&gt; ?&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Can you use &lt;STRONG&gt;another key&lt;/STRONG&gt; ?&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Check controller &lt;STRONG&gt;logs&lt;/STRONG&gt; after trying the particular command&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 08:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5123203#M272267</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-06-03T08:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Catalyst 9800 Controller Type 6 Key/Password</title>
      <link>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5123517#M272288</link>
      <description>&lt;P&gt;Further to what Marce said - type 6 encryption relies on the AES key you have configured on that box:&lt;BR /&gt;1. Have you enabled AES encryption on the new WLC? "&lt;!--StartFragment --&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="cf0"&gt;password encryption aes&lt;/SPAN&gt;&lt;/FONT&gt;&lt;!--EndFragment --&gt;"&lt;BR /&gt;2. Have you configured the same AES key on both WLCs? "&lt;!--StartFragment --&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="cf0"&gt;key config-key password-encrypt &amp;lt;your-secure-AES-key&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;"&lt;/P&gt;
&lt;P&gt;If the AES master key is not &lt;STRONG&gt;identical&lt;/STRONG&gt; on both boxes then decryption of the type 6 encrypted key will fail. (radius must be able to access the original decrypted key to build the radius packets)&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 16:15:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5123517#M272288</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-06-03T16:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Catalyst 9800 Controller Type 6 Key/Password</title>
      <link>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5123533#M272291</link>
      <description>&lt;P&gt;Hi Marce and Rich,&lt;/P&gt;&lt;P&gt;Thank you for your valuable input on the subject.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Where or are the 2 controllers running the same ios-xe&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;version&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Is the target controller on an&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;older version&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;perhaps ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Both the controller are on different versions, but the difference is maginal. 17.3.8 (existing) and 17.9.4a (New controller)&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Can you use the key , when it's entered&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;without encryption&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Yes, it takes the command if no key type is specified and then converts it to type 7 in running config.&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Can you use&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;another key&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;It does not accept any key of type 6&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Check controller&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;logs&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;after trying the particular command&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am yet to check this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. Have you enabled AES encryption on the new WLC? "&lt;FONT face="courier new,courier"&gt;&lt;SPAN class=""&gt;password encryption aes&lt;/SPAN&gt;&lt;/FONT&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, it is enabled on both the controllers.&lt;BR /&gt;2. Have you configured the same AES key on both WLCs? "&lt;FONT face="courier new,courier"&gt;&lt;SPAN class=""&gt;key config-key password-encrypt &amp;lt;your-secure-AES-key&amp;gt;&lt;/SPAN&gt;&lt;/FONT&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No, I have no clue what was the key originally configured by the previous admin for passwrd-encrypt.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Saif&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 16:42:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5123533#M272291</guid>
      <dc:creator>saifuddin.miyaji</dc:creator>
      <dc:date>2024-06-03T16:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Catalyst 9800 Controller Type 6 Key/Password</title>
      <link>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5123568#M272293</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;EM&gt; &amp;nbsp; &amp;gt;....No,&lt;FONT color="#FF6600"&gt;&lt;U&gt; I have no clue&lt;/U&gt;&lt;/FONT&gt; what was the key originally configured by the previous admin for passwrd-encrypt.&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Then you need to &lt;STRONG&gt;reconfigure the passwords&lt;/STRONG&gt; from scratch (with new values),&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 17:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5123568#M272293</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-06-03T17:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Catalyst 9800 Controller Type 6 Key/Password</title>
      <link>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5124019#M272303</link>
      <description>&lt;P&gt;Marce is correct - if you don't know the original password then there is nothing you can do but choose a new password and configure that on both WLCs and the radius server.&lt;/P&gt;
&lt;P&gt;While you're about it you may want to reset your AES master key to something you know - use "&lt;SPAN class="cf0"&gt;no key config-key password-encrypt" to erase the old one but beware you will need to re-configure all your type 6 passwords so make sure you know what they are before doing that.&amp;nbsp; Again if you don't know them they will all need to be reset.&lt;/SPAN&gt;&lt;!--EndFragment --&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 22:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5124019#M272303</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-06-03T22:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Catalyst 9800 Controller Type 6 Key/Password</title>
      <link>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5124343#M272320</link>
      <description>&lt;P&gt;Thank you Rich and Marce,&lt;/P&gt;&lt;P&gt;Your suggestions have been useful in resolving this issue.&lt;/P&gt;&lt;P&gt;Saif&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 10:41:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-catalyst-9800-controller-type-6-key-password/m-p/5124343#M272320</guid>
      <dc:creator>saifuddin.miyaji</dc:creator>
      <dc:date>2024-06-04T10:41:47Z</dc:date>
    </item>
  </channel>
</rss>

