<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC 9800  Error in authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-9800-error-in-authentication/m-p/5156785#M274215</link>
    <description>&lt;P&gt;hello!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tacacs&amp;nbsp;did not work because of the wrong group:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lizochkanovichenko_0-1723010269690.png" style="width: 492px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/225603i5939FF7414100302/image-dimensions/492x342?v=v2" width="492" height="342" role="button" title="lizochkanovichenko_0-1723010269690.png" alt="lizochkanovichenko_0-1723010269690.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I fixed it and TACACS worked.&lt;/P&gt;&lt;P&gt;Thank you for your time and help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Aug 2024 05:58:51 GMT</pubDate>
    <dc:creator>lizochkanovichenko</dc:creator>
    <dc:date>2024-08-07T05:58:51Z</dc:date>
    <item>
      <title>WLC 9800  Error in authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-error-in-authentication/m-p/5012968#M266290</link>
      <description>&lt;P&gt;Hello, dear Colleagues!&lt;/P&gt;&lt;P&gt;I've set up TACACS in WLC 9800 but when I connect from SSH I see the error:&amp;nbsp;&lt;/P&gt;&lt;P&gt;WLC9800&amp;gt;en&lt;BR /&gt;Password:&lt;BR /&gt;% Error in authentication.&lt;/P&gt;&lt;P&gt;And when I login in GUI I see only two menus - Dashboard and Monitoring.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lizochkanovichenko_0-1707140941183.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/209589i845DD8EA393BF5EB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lizochkanovichenko_0-1707140941183.png" alt="lizochkanovichenko_0-1707140941183.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My config:&amp;nbsp;&lt;/P&gt;&lt;P&gt;WLC9800#sh run aaa&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login TACAC-AUTH group ISE_TACACS local&lt;BR /&gt;aaa authentication enable default group ISE_TACACS enable&lt;BR /&gt;aaa authorization exec default local&lt;BR /&gt;aaa authorization exec TACAC-AUTHOR group ISE_TACACS local if-authenticated&lt;BR /&gt;aaa authorization commands 0 TACAC-AUTHOR local if-authenticated&lt;BR /&gt;aaa authorization commands 1 TACAC-AUTHOR local if-authenticated&lt;BR /&gt;aaa authorization commands 15 TACAC-AUTHOR local if-authenticated&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa accounting exec default start-stop group ISE_TACACS&lt;BR /&gt;aaa accounting commands 1 default start-stop group ISE_TACACS&lt;BR /&gt;aaa accounting commands 15 default start-stop group ISE_TACACS&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;BR /&gt;!&lt;BR /&gt;tacacs server TACACS-1&lt;BR /&gt;address ipv4 x.x.x.x&lt;BR /&gt;key password&lt;BR /&gt;tacacs server TACACS-2&lt;BR /&gt;address ipv4 x.x.x.x&lt;BR /&gt;key 7 password&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ ISE_TACACS&lt;BR /&gt;server name TACACS-1&lt;BR /&gt;server name TACACS-2&lt;BR /&gt;!&lt;BR /&gt;aaa local authentication TACAC-AUTH authorization TACAC-AUTHOR&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa session-id common&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;BR /&gt;exec-timeout 60 0&lt;BR /&gt;authorization commands 0 TACAC-AUTHOR&lt;BR /&gt;authorization commands 1 TACAC-AUTHOR&lt;BR /&gt;authorization commands 15 TACAC-AUTHOR&lt;BR /&gt;authorization exec TACAC-AUTHOR&lt;BR /&gt;logging synchronous&lt;BR /&gt;login authentication TACAC-AUTH&lt;BR /&gt;transport input ssh&lt;BR /&gt;transport output all&lt;/P&gt;&lt;P&gt;Can you tell me what's wrong or what settings are incorrect?&lt;BR /&gt;thank you in advance&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 13:55:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-error-in-authentication/m-p/5012968#M266290</guid>
      <dc:creator>lizochkanovichenko</dc:creator>
      <dc:date>2024-02-05T13:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800  Error in authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-error-in-authentication/m-p/5012992#M266293</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;FONT color="#FF6600"&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt;...% Error in authentication.&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp; - Check TACACS (radius) server logs for the particular authentication attempt&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &lt;EM&gt;&amp;nbsp; &amp;nbsp;&amp;gt;And when I login in GUI I see&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt; only two&lt;/STRONG&gt; menus&lt;/FONT&gt; - Dashboard and Monitoring.&amp;nbsp;&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp;- Presumably the authenticated user does not have sufficient privilege's&amp;nbsp; allocated (returned) , hence the restricted GUI view.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Review this documentation :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214490-configure-radius-and-tacacs-for-gui-and.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214490-configure-radius-and-tacacs-for-gui-and.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;Also have a checkup of the WLC 9800 controller configuration with the CLI command &lt;FONT color="#008000"&gt;&lt;STRONG&gt;show tech wireless&lt;/STRONG&gt;&lt;/FONT&gt; and feed the output into&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 14:23:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-error-in-authentication/m-p/5012992#M266293</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-02-05T14:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800  Error in authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-error-in-authentication/m-p/5013034#M266300</link>
      <description>&lt;P&gt;What is the admin access level?&lt;/P&gt;
&lt;P&gt;You can do the debug and get the user access level.&lt;/P&gt;
&lt;PRE&gt;LC-9800# terminal monitor&lt;BR /&gt;WLC-9800# debug tacacs&lt;BR /&gt;TACACS access control debugging is on&lt;BR /&gt;WLC-9800#&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;P&gt;Then look for "&lt;SPAN class="s1"&gt;&lt;STRONG&gt;AV priv-lvl=15&lt;/STRONG&gt;".&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you are using ISE, make sure to verify the Privilege level set for admin user&lt;/P&gt;
&lt;DIV id="tinyMceEditor_552194246cd2f7jaganchowdam_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaganchowdam_1-1707147240964.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/209600i738AAA244437A1C8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaganchowdam_1-1707147240964.png" alt="jaganchowdam_1-1707147240964.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;H3 id="toc-hId-1371738186"&gt;Read-Only User Restrictions&lt;/H3&gt;
&lt;P&gt;When TACACS+ or RADIUS is used for 9800 WebUI authentication, these restrictions exist:&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI&gt;Users with privilege level 0 exist but have no access to the GUI&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Users with privilege levels 1-14 can only view the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Monitor&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tab (this is equivalent to the privilege level of a read-only locally authenticated user)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Users with privilege level 15 have full access&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Users with privilege level 15 and a command set that allows specific commands only are not supported. The user can still be able to execute configuration changes through the WebUI&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Jagan Chowdam&lt;/P&gt;
&lt;P&gt;/**Please rate helpful responses **/&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 15:37:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-error-in-authentication/m-p/5013034#M266300</guid>
      <dc:creator>jagan.chowdam</dc:creator>
      <dc:date>2024-02-05T15:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 9800  Error in authentication</title>
      <link>https://community.cisco.com/t5/wireless/wlc-9800-error-in-authentication/m-p/5156785#M274215</link>
      <description>&lt;P&gt;hello!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tacacs&amp;nbsp;did not work because of the wrong group:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lizochkanovichenko_0-1723010269690.png" style="width: 492px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/225603i5939FF7414100302/image-dimensions/492x342?v=v2" width="492" height="342" role="button" title="lizochkanovichenko_0-1723010269690.png" alt="lizochkanovichenko_0-1723010269690.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I fixed it and TACACS worked.&lt;/P&gt;&lt;P&gt;Thank you for your time and help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 05:58:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-9800-error-in-authentication/m-p/5156785#M274215</guid>
      <dc:creator>lizochkanovichenko</dc:creator>
      <dc:date>2024-08-07T05:58:51Z</dc:date>
    </item>
  </channel>
</rss>

