<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows laptop not able to join 802.1x SSID on C9800-CL in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5326522#M285986</link>
    <description>&lt;P&gt;Can I see RadioTrace of bad in wlc&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Tue, 02 Sep 2025 17:43:28 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-09-02T17:43:28Z</dc:date>
    <item>
      <title>Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324643#M285796</link>
      <description>&lt;P&gt;I am in the middle of migrating WLC 5520 (8.10.190.0) to C9800-CL (17.12.05) while APs remain the same (3802i). AAA servers are ISE 3.4 patch 2. We use centralized switching (no Flex mode). I have an 802.1X SSID allowing both EAP-TLS and PEAP+MSCHAPv2. The SSID on WLC 5520 works for pretty much all devices we have. The same SSID on C9800-CL works for most devices I tested so far but one particular Windows laptop.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The same laptop connects to the SSID on 5520 without any issues using EAP-TLS. Tried different Windows builds (10 and 11) and updated Wi-Fi NIC driver to the latest. Machine certificate is fine. Tried manually adding network with EAP-TLS, and PEAP + MSCHAPv2. None worked with the new C9800-CL.&lt;/LI&gt;&lt;LI&gt;There is no logs for this particular laptop/MAC on ISE meaning the Authenticator (C9800-CL) is not sending Radius request to Authentication Server (ISE) when the Supplicant client tries to join the SSID.&lt;/LI&gt;&lt;LI&gt;I did some packet captures on the C9800-CL by providing “Inner Filter MAC” and did a comparison between a successful connection and a failed one.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;It’s interesting to notice the captured packets are between the C9800-CL and the AP, but 802.1X authentication is between the supplicant (laptop) and the AP (BSSID MAC). On a successful connection, after the supplicant sends Response with Identity (host/xxxxxx), the AP sends a EAP-TLS Request, and after quite a few EAP packets exchange authentication succeeds.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SimonZ_0-1756240489592.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250999i0EEDD2F35634368C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SimonZ_0-1756240489592.png" alt="SimonZ_0-1756240489592.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On a failed connection, after the supplicant sends Response with Identity (host/xxxxxx), the AP just sends a Failure EAP packet and never sends a 802.1X proposal:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SimonZ_1-1756240489596.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251000i3A0564093B57CDFF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SimonZ_1-1756240489596.png" alt="SimonZ_1-1756240489596.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This explains why ISE never sees a Radius request for this particular laptop. I’ve tested 5 Windows laptops and a few iOS/Android devices so far, and found only one problematic laptop, but I don’t know how many more out of about 1000 laptops may experience the same issue.&lt;/P&gt;&lt;P&gt;A TAC ticket is going nowhere, and the engineer insists something is wrong with the laptop but doesn’t know what exactly is wrong. I’ve seen some similar issues online and it seems nobody was able to explain why there is no logs on Radius servers. Has anyone seen this?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 20:45:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324643#M285796</guid>
      <dc:creator>Simon Z</dc:creator>
      <dc:date>2025-08-26T20:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324646#M285797</link>
      <description>&lt;P&gt;I see same issue month ago' but what can I say' engineer leave us with many Q and dont reply to our comment.&lt;/P&gt;
&lt;P&gt;Anyway' what I understand'&lt;/P&gt;
&lt;P&gt;There are two inner and outer authc&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The identity wlc receive for outer authc is wrong and this make authc failed.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 21:11:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324646#M285797</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-26T21:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324649#M285798</link>
      <description>&lt;P&gt;My understanding is PEAP + MSCHAPv2, PEAP + EAP-TLS etc. use outer and inner authc, but EAP-TLS alone uses only one layer. I am thinking a compatibility issue between 3802 AP and C9800-CL but according to this &lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html" target="_self"&gt;matrix&lt;/A&gt; they are supported.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 21:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324649#M285798</guid>
      <dc:creator>Simon Z</dc:creator>
      <dc:date>2025-08-26T21:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324650#M285799</link>
      <description>&lt;P&gt;Yes correct eap-tls use only one authc&lt;/P&gt;
&lt;P&gt;Let take it as reference&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Connect laptop to wlc 5500 and capture traffic and connect it to wlc 9800 and capture traffic&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then identity response open both packet and share it here let me check different&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 21:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324650#M285799</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-26T21:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324653#M285800</link>
      <description>&lt;P&gt;It may not be easy to do packet capture on 5520. Wireshark on the laptop seems not be able to capture all 802.11 traffic as the Wi-Fi card doesn't support "Monitor mode". I am going to try if I can do it on the AP.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 21:38:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324653#M285800</guid>
      <dc:creator>Simon Z</dc:creator>
      <dc:date>2025-08-26T21:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324723#M285806</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/546389"&gt;@Simon Z&lt;/a&gt;&amp;nbsp; &amp;nbsp; Use client debugging for this&amp;nbsp; windows laptop using instructions from&amp;nbsp;&lt;A href="https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity" target="_blank"&gt;https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; These so called&lt;STRONG&gt; RadioActive Traces&lt;/STRONG&gt; can be analyzed with&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank"&gt;Wireless Debug Analyzer&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Outputs from commands mentioned in&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#toc-hId-866973845" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217738-monitor-catalyst-9800-kpis-key-performa.html#toc-hId-866973845&lt;/A&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; can also be useful&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Validate the configuration of your new&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;C9800-CL controller using the CLI command&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;FONT color="#008000"&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; show tech wireless&lt;/STRONG&gt; &lt;/FONT&gt;and feed the output from that&amp;nbsp; into&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; M.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 06:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324723#M285806</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-08-27T06:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324879#M285815</link>
      <description>&lt;P&gt;Wireless Debug Analyzer shows a simple reason: Cred Fail. For whatever reason, the WLC/AP and the client don't try any of the 802.1X protocols. As soon as the client provides Identity as host/&amp;lt;FQDM&amp;gt;, WLC/AP says Failure.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-27 101247.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251029iC1B25CC0604A1C76/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-08-27 101247.jpg" alt="Screenshot 2025-08-27 101247.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Wireless Config Analyzer shows 1 error 16 warnings - none seems related to the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 14:43:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324879#M285815</guid>
      <dc:creator>Simon Z</dc:creator>
      <dc:date>2025-08-27T14:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324885#M285816</link>
      <description>&lt;P&gt;Unfortunately the only way to do packet capture on 5520 is to use an AP as monitor AP, which I don't have one handy now. When I try "&lt;SPAN&gt;config ap packet-dump&lt;/SPAN&gt;" it says my AP doesn't support it.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 14:48:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324885#M285816</guid>
      <dc:creator>Simon Z</dc:creator>
      <dc:date>2025-08-27T14:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324889#M285817</link>
      <description>&lt;P&gt;In wlc 9800 there is EPC use it to share traffic between WLC abd ISE' let see if WLC is end authc or ISE&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Share ISE ver abd wlc ver&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 14:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324889#M285817</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-27T14:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324909#M285819</link>
      <description>&lt;P&gt;I specify 9800 as source and ISE as destination in EPC, then try to join the SSID on the problematic laptop. Nothing is captured. When I try on a good laptop, I see lots of Radius traffic.&lt;/P&gt;&lt;P&gt;9800 is v17.12.05. ISE is v3.4 patch 2.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 15:42:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324909#M285819</guid>
      <dc:creator>Simon Z</dc:creator>
      <dc:date>2025-08-27T15:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324912#M285820</link>
      <description>&lt;P&gt;Good, now what is good laptop and bad laptop?&lt;/P&gt;
&lt;P&gt;What is OS for both laptop?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 15:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324912#M285820</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-27T15:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324917#M285821</link>
      <description>&lt;P&gt;The bad one is now&amp;nbsp; Win11 version 24H2 (a fresh install). Tried Win10 on it earlier. Same issue.&lt;/P&gt;&lt;P&gt;The good ones include Win10 (22H2), Win 11 (22H2 and 24H2).&lt;/P&gt;&lt;P&gt;They all have the latest Windows updates.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 16:10:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324917#M285821</guid>
      <dc:creator>Simon Z</dc:creator>
      <dc:date>2025-08-27T16:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324950#M285823</link>
      <description>&lt;P&gt;Ok in your original post you can capture traffic&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Capture both wifi good and bad&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Abd share the identity response from client I need to see it&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 17:23:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324950#M285823</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-27T17:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324955#M285824</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/546389"&gt;@Simon Z&lt;/a&gt;, although the 5520 doesn't support packet capture natively you can still achieve it via this flow:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/211342-packet-captures-on-aireos-wlc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/211342-packet-captures-on-aireos-wlc.html&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Since its Identity response you are after, give this a shot and compare against 9800, for AP side packet capture I would suggest to do an EPC on the switch where AP is connected and do the same for 5520 vs 9800.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 17:51:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324955#M285824</guid>
      <dc:creator>Parithosh Vema</dc:creator>
      <dc:date>2025-08-27T17:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324960#M285825</link>
      <description>&lt;P&gt;For a good connection, it's a bunch of EAP and TLSv1.2 packets:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SimonZ_0-1756318239354.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251039i301986FC43FFAC6E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SimonZ_0-1756318239354.png" alt="SimonZ_0-1756318239354.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I believe my issue is very similar to this one:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/wireless/reason-cred-fail-on-interface-capwap/td-p/4971126/page/2" target="_blank"&gt;https://community.cisco.com/t5/wireless/reason-cred-fail-on-interface-capwap/td-p/4971126/page/2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The OP claimed he fixed the issue by adding a Windows Registry key named TTLS (to apply to EAP-TTLS) and a DWORD named Tlsversion in&amp;nbsp;&lt;SPAN&gt;HKEY_LOCAL_MACHINE\&lt;/SPAN&gt;&lt;SPAN class=""&gt;SYSTEM&lt;/SPAN&gt;&lt;SPAN&gt;\CurrentControlSet\Services\RasMan\PPP\EAP\13. I believe the value fc0 forces Windows to use one of TLS 1.0, 1.1 or 1.2, not TLS 1.3. I did the same to no avail.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 18:30:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324960#M285825</guid>
      <dc:creator>Simon Z</dc:creator>
      <dc:date>2025-08-27T18:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324962#M285826</link>
      <description>&lt;P&gt;Friend only I need to see identity response for both cases&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 18:36:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324962#M285826</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-27T18:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324987#M285827</link>
      <description>&lt;P&gt;Sorry&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1788357"&gt;@Parithosh Vema&lt;/a&gt; I missed your post. I followed the instruction. I specified src/dst as 5520/AP and AP/5520 and this is what I got:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SimonZ_0-1756322012240.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251042i42313310FC766BC9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SimonZ_0-1756322012240.png" alt="SimonZ_0-1756322012240.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately there is no EAP traffic being captured. Not sure I used a wrong ACL. Apparently the client doesn't have an IP yet at this stage. I did notice there is some limitations by doing this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SimonZ_1-1756322192619.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251043i5E482F2D2B9DC487/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SimonZ_1-1756322192619.png" alt="SimonZ_1-1756322192619.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 19:21:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324987#M285827</guid>
      <dc:creator>Simon Z</dc:creator>
      <dc:date>2025-08-27T19:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324991#M285828</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;, right after client replied with Identity host/&amp;lt;FQDN&amp;gt;, The AP requests for EAP-TLS, the client then starts a TLSv1.2 handshake, and client and server start to identity each other with certificates.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SimonZ_0-1756323192382.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251044i87F56FB6A5BBD6EC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SimonZ_0-1756323192382.png" alt="SimonZ_0-1756323192382.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a failed connection, the AP simply says Failure.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 19:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324991#M285828</guid>
      <dc:creator>Simon Z</dc:creator>
      <dc:date>2025-08-27T19:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324993#M285829</link>
      <description>&lt;P&gt;I need to see how client reply for identity request&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to see how hostname and op in that packet&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 19:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5324993#M285829</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-27T19:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Windows laptop not able to join 802.1x SSID on C9800-CL</title>
      <link>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5325000#M285830</link>
      <description>&lt;P&gt;Client replies with this format: host/&amp;lt;hostname.xxx.org.local&amp;gt;, where xxx.org.local is our AD domain name. We have a CA infrastructure in the domain to issue certs to ISE and all clients.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-27 154153.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/251046iB03C39A9833C03D2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2025-08-27 154153.jpg" alt="Screenshot 2025-08-27 154153.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 19:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-laptop-not-able-to-join-802-1x-ssid-on-c9800-cl/m-p/5325000#M285830</guid>
      <dc:creator>Simon Z</dc:creator>
      <dc:date>2025-08-27T19:51:52Z</dc:date>
    </item>
  </channel>
</rss>

