<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: C9800 Admin access through GUI with MFA in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5123344#M272284</link>
    <description>&lt;P&gt;Unfortunately I have no access to Entra ID MFA service so I can't check them, BUT this is working for CLI access.&lt;/P&gt;
&lt;P&gt;THE problem is that C9800 GUI is not poping up a windoes asking to enter teh coed I'm receiving from the MS Authenticator App, so the authentication fail becuase I don't have any mean to enter the MFA code.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jun 2024 11:33:57 GMT</pubDate>
    <dc:creator>JPavonM</dc:creator>
    <dc:date>2024-06-03T11:33:57Z</dc:date>
    <item>
      <title>C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5121820#M272199</link>
      <description>&lt;P&gt;Hi wireless colleagues,&lt;/P&gt;
&lt;P&gt;After multiple tries with the configurations I have managed to enable MFA on the C9800 for admin access through CLI by using TACACS+. The integration is done via ISE with NPS as Proxy RADIUS to Entra ID MFA Service in the cloud.&lt;/P&gt;
&lt;P&gt;Now, I've created a RADIUS Policy cloned from the TACACS+ one on ISE, and similar in the C9800 configuration, but the problem is that when I enter my credentials on the GUI login page, the MS Authenticator App returns me the code (like it happen on CLI access), but before that the GUI timeouts the session and returns me "&lt;SPAN&gt;Wrong Credentials. Please Login again&lt;/SPAN&gt;", but tehre aren't any pop-up asking for the code.&lt;/P&gt;
&lt;P&gt;I doubt this is related to a timeout as it is set to 30 seconds.&lt;/P&gt;
&lt;P&gt;Have any of you managed to have this integration working on C9800 GUI access with ISE+NPS+EntraID for MFA?&lt;/P&gt;
&lt;P&gt;Below you can find the log record for the failure if it could be of any help.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavonM_0-1717152702011.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/219743i4FA6D7ED929518B8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavonM_0-1717152702011.png" alt="JPavonM_0-1717152702011.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 10:53:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5121820#M272199</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-05-31T10:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5121825#M272200</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;- Check NPS (radius server) &lt;STRONG&gt;logs&lt;/STRONG&gt; for this failing authentication and also check the &lt;STRONG&gt;C9800's &lt;U&gt;logs ,&amp;nbsp;&lt;BR /&gt;&lt;/U&gt;&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;EM&gt;&amp;nbsp; &amp;nbsp;(just after trying to use the GUI)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 10:59:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5121825#M272200</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-05-31T10:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5121875#M272202</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;that does not return any clue about what is happening on the C9800:&lt;BR /&gt;&lt;STRONG&gt;C9800:&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE&gt;May 31 2024 11:49:33.719 UTC: %WEBSERVER-5-SESS_TIMEOUT: Chassis 1 Session timeout from host x.y.z.1 by user 'user1' using crypto cipher 'ECDHE-RSA-AES128-GCM-SHA256'&lt;BR /&gt;May 31 2024 11:49:38.319 UTC: %HA_EM-6-LOG: catchall: show banner loginMay 31 2024 11:49:38.297 UTC: %WEBSERVER-5-LOGIN_FAILED: Chassis 1 Login Un-Successful from host x.y.z.1&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;ISE:&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE&gt;11001 Received RADIUS Access-Request&lt;BR /&gt;11017 RADIUS created a new session&lt;BR /&gt;11117 Generated a new session ID&lt;BR /&gt;15049 Evaluating Policy Group&lt;BR /&gt;15008 Evaluating Service Selection Policy&lt;BR /&gt;15048 Queried PIP - Radius.NAS-Port-Type&lt;BR /&gt;15048 Queried PIP - Network Access.Protocol&lt;BR /&gt;15048 Queried PIP - DEVICE.Location&lt;BR /&gt;15048 Queried PIP - DEVICE.Device Type&lt;BR /&gt;15041 Evaluating Identity Policy&lt;BR /&gt;15048 Queried PIP - Network Access.UserName&lt;BR /&gt;15048 Queried PIP - Network Access.AuthenticationMethod&lt;BR /&gt;22072 Selected identity source sequence - ISE_NS_ENTRA_AD_Sequence&lt;BR /&gt;15013 Selected Identity Source - NPS_ENTRAID_MFA_Proxy&lt;BR /&gt;24638 Passcode cache is not enabled in the RADIUS token identity store configuration - NPS_ENTRAID_MFA_Proxy&lt;BR /&gt;24609 RADIUS token identity store is authenticating against the primary server - NPS_ENTRAID_MFA_Proxy&lt;BR /&gt;11100 RADIUS-Client about to send request - ( port = 1812 )&lt;BR /&gt;11101 RADIUS-Client received response (step latency=2565 ms Step latency=2565 ms)&lt;BR /&gt;24615 RADIUS token identity store received access challenge response&lt;BR /&gt;11006 Returned RADIUS Access-Challenge&lt;BR /&gt;11041 RADIUS PAP session timed out (step latency=120000 ms Step latency=120000 ms)&lt;BR /&gt;5416 RADIUS PAP session cleaned up&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 11:54:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5121875#M272202</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-05-31T11:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5122023#M272206</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Ok , but I was also asking about the&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;-&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;NPS_ENTRAID_MFA_Proxy&lt;/STRONG&gt;&amp;nbsp; (radius server) logs&amp;nbsp; &amp;nbsp;&lt;U&gt;and&lt;/U&gt; if&amp;nbsp; the logs from&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Entra ID MFA Service&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp; for the attempted authentications ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 13:41:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5122023#M272206</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-05-31T13:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5123293#M272278</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't have any interpreter for NPS Logs working with MFA Extension, and the online interpreter I'm using for standard NPS Logs does not return useful information.&lt;/P&gt;
&lt;PRE&gt;"NPSMFA","IAS",06/03/2024,11:58:48,1,"user1","domain.net/Administrators/User1",,,,,,"10.1.1.231",,0,"10.1.1.161","isepsn001",,,,,,,1,"Cisco WLC - Superuser - Proxy RADIUS Auth - AAD MFA",0,"311 1 10.1.1.159 06/01/2024 20:28:24 15",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"Use Windows authentication for all users",1,,,,&lt;BR /&gt;"NPSMFA","IAS",06/03/2024,11:58:48,11,,"domain.net/Administrators/User1",,,,,,,,0,"10.1.1.161","isepsn001",,,,,,,1,"Cisco WLC - Superuser - Proxy RADIUS Auth - AAD MFA",0,"311 1 10.1.1.159 06/01/2024 20:28:24 15",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"Use Windows authentication for all users",1,,,,&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 10:08:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5123293#M272278</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-06-03T10:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5123297#M272279</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - It comes down to that you also need to be able to view the logs from the&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;U&gt;&lt;STRONG&gt;Entra ID MFA Service in the cloud&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; and check &lt;EM&gt;the status of the particular attempted authentication(s)&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;M.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 10:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5123297#M272279</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-06-03T10:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5123344#M272284</link>
      <description>&lt;P&gt;Unfortunately I have no access to Entra ID MFA service so I can't check them, BUT this is working for CLI access.&lt;/P&gt;
&lt;P&gt;THE problem is that C9800 GUI is not poping up a windoes asking to enter teh coed I'm receiving from the MS Authenticator App, so the authentication fail becuase I don't have any mean to enter the MFA code.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 11:33:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5123344#M272284</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-06-03T11:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5123351#M272285</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;gt;...&lt;SPAN&gt;Unfortunately&lt;FONT color="#FF6600"&gt;&lt;EM&gt; I have&lt;U&gt;&lt;STRONG&gt; no access&lt;/STRONG&gt;&lt;/U&gt; to Entra ID MFA service&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;- Following the arguments you mentioned later (too) , this should be considered &lt;STRONG&gt;essential&lt;/STRONG&gt; (to be able to query it)&amp;nbsp; ; perhaps contact provider (support) for the service and ask for the info's that you need.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- For the rest check controller&lt;U&gt;&lt;STRONG&gt; logs&lt;/STRONG&gt;&lt;/U&gt; when the GUI attempt fails ;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- What is the controller&amp;nbsp; software version ?&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;-&lt;FONT color="#FF6600"&gt; Found&lt;/FONT&gt;&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj28151" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj28151&lt;/A&gt;&amp;nbsp;;&amp;nbsp; not sure if it that is indicative ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 11:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5123351#M272285</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-06-03T11:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5127871#M272490</link>
      <description>&lt;P&gt;The solution pointed out in the bug that&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;shared is the workaround I'm using at this time, having first an ISE policy to match NAS-Port-Type virtual plus NAS-Port-Id containing the string "tty", and a second policy only with NAS-Port-Type, as that is the only difference between both requests from IOS-XE:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 07:36:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5127871#M272490</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-06-10T07:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5155730#M274096</link>
      <description>&lt;P&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/R6BGArNQ/TECSEC-3416.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/R6BGArNQ/TECSEC-3416.pdf&lt;/A&gt;&amp;nbsp;says "Web UI uses CLI commands in the background" so I think it's a limitation in the GUI coding - probably needs an enhancement request via your account team.&amp;nbsp; Frankly it's shocking that this could have been overlooked!&amp;nbsp; I expect that the new UK Telecoms Security Act will make this mandatory so Cisco might be forced to review it...&lt;/P&gt;</description>
      <pubDate>Sun, 04 Aug 2024 23:24:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5155730#M274096</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-08-04T23:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5325448#M285854</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/324840"&gt;@JPavonM&lt;/a&gt;&amp;nbsp;Does the above workaround prompt for inline MFA on C9800 GUI ?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 04:30:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5325448#M285854</guid>
      <dc:creator>Farooq Mohammed</dc:creator>
      <dc:date>2025-08-29T04:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: C9800 Admin access through GUI with MFA</title>
      <link>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5325543#M285859</link>
      <description>&lt;P&gt;We are using Notifications in the Auth App, but when I was also testing TOTP codes inline, yes it was working.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 09:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/c9800-admin-access-through-gui-with-mfa/m-p/5325543#M285859</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2025-08-29T09:41:18Z</dc:date>
    </item>
  </channel>
</rss>

