<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fortinac and WLC 9800 controller in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236673#M278881</link>
    <description>&lt;P&gt;Try to reduce the Session time out&amp;nbsp; and see if that makes difference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FlavioMiranda_0-1734109333349.jpeg" style="width: 855px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/235914iC2DB381FE22DEF6D/image-dimensions/855x633?v=v2" width="855" height="633" role="button" title="FlavioMiranda_0-1734109333349.jpeg" alt="FlavioMiranda_0-1734109333349.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Dec 2024 17:02:47 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2024-12-13T17:02:47Z</dc:date>
    <item>
      <title>Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236197#M278820</link>
      <description>&lt;P&gt;New network tech here, just implemented a NAC system along with a WLC9800 model. My NAC system put all unknown devices into a quarantine VLAN for example VLan 100 they go through a portal page and register as either guest or a domain user which will get either a guest or domain vlan address. Portal page works perfect and registration goes fine. The issue im seeing is either after registration the client sits for almost 30 minutes before It changes the client to the correct VLAN or I can manually go in the WLC and delete that client and it will instantly get the address that it should based off the registration. Any idea where to start this troubleshooting, with the old WLC things seem to switch over pretty quickly but having issue since new one was implemented. Any ideas where to start to investigate this???&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 19:05:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236197#M278820</guid>
      <dc:creator>terrance-mccallum</dc:creator>
      <dc:date>2024-12-12T19:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236224#M278821</link>
      <description>&lt;P&gt;NAC return CoA re-auth or port bounce ?&lt;/P&gt;
&lt;P&gt;since vlan is change you need to port bounce&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 19:59:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236224#M278821</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-12T19:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236542#M278869</link>
      <description>&lt;P&gt;I don't think there is no port bounce config, I do see a COA server key in the WLC but im not quite sure it's working. Is there a method to test this manually to see if this is working?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 12:12:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236542#M278869</guid>
      <dc:creator>terrance-mccallum</dc:creator>
      <dc:date>2024-12-13T12:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236561#M278870</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1698500"&gt;@terrance-mccallum&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;You probably have the features "support for CoA" and "AAA overide" enable, right?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 12:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236561#M278870</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-13T12:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236574#M278871</link>
      <description>&lt;P&gt;Correct, and I also can run the " show aaa server detail " command and see my radius server list and shows enabled. however I am not seeing any vlan change when made in the NAC system, unless I delete the client from the WLC completely it will then come back with the assigned VLAN, If not mistaken in old WLC the NAC would do this step automatically when a change was made, however now it is not.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 13:17:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236574#M278871</guid>
      <dc:creator>terrance-mccallum</dc:creator>
      <dc:date>2024-12-13T13:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236580#M278872</link>
      <description>&lt;P&gt;On the link below, Cisco show how to implement a similar setup using ISE but I believe you can check the WLC part which should be the same.&lt;/P&gt;
&lt;P&gt;At the end of this document, they show how you can get a Radioactive Trace that can be helpfull for you. You can share the logs here, if possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is possible to enable the &lt;CODE class="cCN_CmdName" style="white-space: pre-wrap; font-style: unset; font-weight: unset; font-family: unset;"&gt;&lt;STRONG&gt;Radioactive traces&lt;/STRONG&gt;&lt;/CODE&gt; to ensure successful transfer of the RADIUS attributes to the WLC. In order to do so, do these steps:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;From the controller GUI, navigate to &lt;CODE class="cCN_CmdName" style="white-space: pre-wrap; font-style: unset; font-weight: unset; font-family: unset;"&gt;&lt;STRONG&gt;Troubleshooting &amp;gt; Radioactive Trace &amp;gt; +Add&lt;/STRONG&gt;&lt;/CODE&gt;.&lt;/LI&gt;
&lt;LI&gt;Enter the Mac Address of the wireless client.&lt;/LI&gt;
&lt;LI&gt;Select &lt;CODE class="cCN_CmdName" style="white-space: pre-wrap; font-style: unset; font-weight: unset; font-family: unset;"&gt;&lt;STRONG&gt;Start&lt;/STRONG&gt;&lt;/CODE&gt;.&lt;/LI&gt;
&lt;LI&gt;Connect the client with the WLAN.&lt;/LI&gt;
&lt;LI&gt;Navigate to &lt;CODE class="cCN_CmdName" style="white-space: pre-wrap; font-style: unset; font-weight: unset; font-family: unset;"&gt;&lt;STRONG&gt;Stop &amp;gt; Generate &amp;gt; Choose 10 minutes &amp;gt; Apply to Device &amp;gt; Select the trace file to download the log&lt;/STRONG&gt;&lt;/CODE&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 13:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236580#M278872</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-13T13:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236631#M278875</link>
      <description>&lt;P&gt;attached&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 15:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236631#M278875</guid>
      <dc:creator>terrance-mccallum</dc:creator>
      <dc:date>2024-12-13T15:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236665#M278877</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems like the radius communication is fine&lt;/P&gt;
&lt;P&gt;2024/12/13 10:15:31.287576879 {wncd_x_R0-5}{1}: [aaa-attr-inf] [24831]: (info): [ Applied attribute : tunnel-type 0 13 [vlan] ]&lt;BR /&gt;2024/12/13 10:15:31.287578693 {wncd_x_R0-5}{1}: [aaa-attr-inf] [24831]: (info): [ Applied attribute : tunnel-medium-type 0 6 [ALL_802] ]&lt;BR /&gt;2024/12/13 10:15:31.287580124 {wncd_x_R0-5}{1}: [aaa-attr-inf] [24831]: (info): [ Applied attribute :tunnel-private-group-id 0 "48" ]&lt;BR /&gt;2024/12/13 10:15:31.287581563 {wncd_x_R0-5}{1}: [aaa-attr-inf] [24831]: (info): [ Applied attribute : username 0 "e40d366921f7" ]&lt;BR /&gt;2024/12/13 10:15:31.287587016 {wncd_x_R0-5}{1}: [aaa-attr-inf] [24831]: (info): [ Applied attribute : timeout 0 28800 (0x7080) ]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you took the action of remove the client?&lt;/P&gt;
&lt;TABLE class="table"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;2024/12/13 10:19:02.121&lt;/TD&gt;
&lt;TD&gt;client-orch-sm&lt;/TD&gt;
&lt;TD&gt;Controller initiated client deletion with code: CO_CLIENT_DELETE_REASON_ADMIN_RESET. Explanation: Administrator removed the client, or in some scenarios, AAA server requested client delete. Actions: None required&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;If you did, can you take the debug but not interfere to compare?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 16:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236665#M278877</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-13T16:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236667#M278878</link>
      <description>&lt;P&gt;No, I feel like that's the issue it's not doing that step, but if i manually go and delete it, it will then get the correct address and everything works fine. I dont' know why its' not doing the delete even though it's being told to do so.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 16:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236667#M278878</guid>
      <dc:creator>terrance-mccallum</dc:creator>
      <dc:date>2024-12-13T16:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236669#M278879</link>
      <description>&lt;P&gt;To add to that, If i let this device sit for a long time up to like 20 minutes it will eventually go through almost like it fails out and at some points tries again and works at that point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 16:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236669#M278879</guid>
      <dc:creator>terrance-mccallum</dc:creator>
      <dc:date>2024-12-13T16:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236671#M278880</link>
      <description>&lt;P&gt;this seems to be some kind of time out.&amp;nbsp; 30 minutes is 1800 seconds which seems to be the session time out for your WLC&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 17:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236671#M278880</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-13T17:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236673#M278881</link>
      <description>&lt;P&gt;Try to reduce the Session time out&amp;nbsp; and see if that makes difference&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FlavioMiranda_0-1734109333349.jpeg" style="width: 855px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/235914iC2DB381FE22DEF6D/image-dimensions/855x633?v=v2" width="855" height="633" role="button" title="FlavioMiranda_0-1734109333349.jpeg" alt="FlavioMiranda_0-1734109333349.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 17:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236673#M278881</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-13T17:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236674#M278882</link>
      <description>&lt;P&gt;I send you PM&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 17:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236674#M278882</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-12-13T17:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236687#M278883</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp; &amp;nbsp;wrote :&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;EM&gt;&amp;gt;&lt;U&gt;I send you PM&lt;/U&gt;&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- What's wrong with sharing knowledge in the community ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 17:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236687#M278883</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-12-13T17:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236688#M278884</link>
      <description>&lt;P&gt;So I attempted a quick change and instantly loss around half or my wireless connections in my district&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 17:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236688#M278884</guid>
      <dc:creator>terrance-mccallum</dc:creator>
      <dc:date>2024-12-13T17:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236690#M278885</link>
      <description>&lt;P&gt;Looks like this may be a after hours test&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 17:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236690#M278885</guid>
      <dc:creator>terrance-mccallum</dc:creator>
      <dc:date>2024-12-13T17:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236691#M278886</link>
      <description>&lt;P&gt;No man, you can not do this changes in live environment doring business hours.&amp;nbsp; Any change on the WLAN will disconnect all the clients.&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;you should do this in a test SSID only for a few clients.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 17:25:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236691#M278886</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-13T17:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236697#M278887</link>
      <description>&lt;P&gt;Sure. Any change made on the WLAN will disconnect all clients. But, this time out session may help you.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 17:36:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236697#M278887</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-12-13T17:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236702#M278888</link>
      <description>&lt;P&gt;Perfect, I think it very well will. Going to try it after hours to see how things go. I'll update after testing.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 17:51:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5236702#M278888</guid>
      <dc:creator>terrance-mccallum</dc:creator>
      <dc:date>2024-12-13T17:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinac and WLC 9800 controller</title>
      <link>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5237579#M278973</link>
      <description>&lt;P&gt;So built a test SSID and got to make some changes with everything above and changed my timeout session to 300 which is basically 5 minutes and sure enough after 5 minutes I have a successful connection. However the Fortinac engineer says this should happeen instantly upon connection and the the reason it's working after the timeout is it fails and tries the process over again and works sucessfully the second time. Which then points me in the direction of a COA server key. I found it inside the WLC however password is hidden, is there a way to test the COA to see if it's working properly? Im thinking that it's not and after the timeout the machine basically fails out and comes back as a new connection and works because the address was there for it the first time but it couldn't get it due to a bad COA.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 18:26:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/fortinac-and-wlc-9800-controller/m-p/5237579#M278973</guid>
      <dc:creator>terrance-mccallum</dc:creator>
      <dc:date>2024-12-16T18:26:09Z</dc:date>
    </item>
  </channel>
</rss>

