<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC 5502 Not Sending Message-Authenticator Attribute to ISE in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228473#M278109</link>
    <description>&lt;P&gt;disable Op of allow protocol will apply to these AP only not all device&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Mon, 25 Nov 2024 14:11:03 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-11-25T14:11:03Z</dc:date>
    <item>
      <title>WLC 5502 Not Sending Message-Authenticator Attribute to ISE</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228414#M278095</link>
      <description>&lt;P&gt;Hello team, I hope you're well&lt;/P&gt;
&lt;P&gt;I have a problem that when I enable the Require Message-Authenticator Attribute in the ISE, the network that uses the guest portal stops working because the ISE drops all connection requests because it does not have the Message Authenticator, however in the other WLCs I do not have this problem, only in this 5502, has anyone experienced this and gotten a workaround?&amp;nbsp;I have already checked the settings between the wlcs in order to find any difference and enable, but I have not identified it&lt;/P&gt;
&lt;P&gt;WLC Version&amp;nbsp;&lt;SPAN&gt;8.3.150.3&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 12:57:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228414#M278095</guid>
      <dc:creator>Vinicius Monteiro</dc:creator>
      <dc:date>2024-11-25T12:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5502 Not Sending Message-Authenticator Attribute to ISE</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228426#M278096</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - As per&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/wireless-lan-controller-software/200046-tac-recommended-aireos.html&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;you should&lt;U&gt; first&lt;/U&gt; upgrade to &lt;FONT color="#008000"&gt;&lt;STRONG&gt;8.10.196.0&lt;/STRONG&gt;&lt;/FONT&gt; and try again , &lt;FONT color="#FF6600"&gt;&lt;EM&gt;8.3.x is very old ,&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 13:10:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228426#M278096</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-11-25T13:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5502 Not Sending Message-Authenticator Attribute to ISE</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228432#M278098</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TEAP.JPG" style="width: 776px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/234483i6E8A1834A0E236F5/image-size/large?v=v2&amp;amp;px=999" role="button" title="TEAP.JPG" alt="TEAP.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;require Message-auth &amp;lt;&amp;lt;- dont select this op in ISE and I think it will work&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 13:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228432#M278098</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-11-25T13:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5502 Not Sending Message-Authenticator Attribute to ISE</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228455#M278105</link>
      <description>&lt;P&gt;Hi guys,&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804"&gt;@Mark Elsen&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&amp;nbsp;thanks for the suggestions&lt;/P&gt;
&lt;P&gt;Just to clarify in this environment I cannot apply an update as there are APs that are not supported in version 8.10 and not checking the option is also not an option as I am trying to mitigate CVE-2024-3596 Blast Radius, which ISE is vulnerable to&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 13:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228455#M278105</guid>
      <dc:creator>Vinicius Monteiro</dc:creator>
      <dc:date>2024-11-25T13:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5502 Not Sending Message-Authenticator Attribute to ISE</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228461#M278106</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1737313"&gt;@Vinicius Monteiro&lt;/a&gt;&amp;nbsp;wrote : &amp;gt;&lt;EM&gt;Just to clarify in this environment&lt;FONT color="#FF0000"&gt; I cannot apply an update &lt;/FONT&gt;as there are APs that are not supported in version 8.10&amp;nbsp;&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - This should be considered a&lt;FONT color="#FF0000"&gt; fatal showstopper&lt;/FONT&gt; these days ; the aireos models are EOL and using the last release made available has become&lt;STRONG&gt; mandatory&lt;/STRONG&gt; for this type&amp;nbsp; of controllers.&amp;nbsp; If not being able to use the extra features because of a bug then there is nothing more then &lt;FONT color="#FF0000"&gt;(anything more)&lt;/FONT&gt; then you can do , besides going back and &lt;STRONG&gt;not using&lt;/STRONG&gt; that feature.&lt;BR /&gt;If the restriction is due to certain older AP&amp;nbsp; models , that also means that it is time to&lt;FONT color="#008000"&gt;&lt;U&gt; modernize the wireless network ,&amp;nbsp;&lt;/U&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 14:00:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228461#M278106</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-11-25T14:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5502 Not Sending Message-Authenticator Attribute to ISE</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228473#M278109</link>
      <description>&lt;P&gt;disable Op of allow protocol will apply to these AP only not all device&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 14:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228473#M278109</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-11-25T14:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5502 Not Sending Message-Authenticator Attribute to ISE</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228866#M278150</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1737313"&gt;@Vinicius Monteiro&lt;/a&gt;&amp;nbsp;as per&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222287-blast-radius-cve-2024-3596-protocol-sp.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/222287-blast-radius-cve-2024-3596-protocol-sp.html&lt;/A&gt;&amp;nbsp;not all radius clients will send message authenticator on all requests and the option should &lt;STRONG&gt;only&lt;/STRONG&gt; be enabled where you know that the radius client will &lt;STRONG&gt;always&lt;/STRONG&gt; use message authenticator.&lt;/P&gt;
&lt;P&gt;As per&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk70846" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk70846&lt;/A&gt;&amp;nbsp;AireOS will only send&amp;nbsp;message authenticator for&amp;nbsp;&lt;SPAN&gt;EAP authentication flows which is strictly compliant with RFCs at the time of implementation.&amp;nbsp; AireOS is end of life and this will not be changed (and certainly not ever in 8.3.x which is years past end of support!).&amp;nbsp; As per the bug notes - if you need to protect that radius traffic (if it is exposed to interception for example across the internet) then you should transport it in IPSEC.&amp;nbsp; If the radius is only transmitted across secure network links and devices (which you control and which should not be exposed to interception) then there is no real risk to start with.&amp;nbsp; In that case you add it to your Risk Register and note that it is mitigated by transport over secure, controlled networks.&amp;nbsp; If that's not good enough for your security team then ask them for the cash to upgrade all the equipment to current, supported technology.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;nbsp;however in the other WLCs I do not have this problem, only in this 5502&lt;BR /&gt;I presume you mean 5520? &lt;BR /&gt;Are the other WLCs running the same version of code?&lt;BR /&gt;Are the radius flows all identical? (for example maybe the others are EAP?)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 08:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5502-not-sending-message-authenticator-attribute-to-ise/m-p/5228866#M278150</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2024-11-26T08:43:23Z</dc:date>
    </item>
  </channel>
</rss>

