<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local Authentication Server does not update policy on AP in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/local-authentication-server-does-not-update-policy-on-ap/m-p/5344663#M287325</link>
    <description>&lt;P&gt;Are you using ISE as authenitcation server , have to check the policy rules ?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Nov 2025 10:06:31 GMT</pubDate>
    <dc:creator>srimal99</dc:creator>
    <dc:date>2025-11-05T10:06:31Z</dc:date>
    <item>
      <title>Local Authentication Server does not update policy on AP</title>
      <link>https://community.cisco.com/t5/wireless/local-authentication-server-does-not-update-policy-on-ap/m-p/5343649#M287251</link>
      <description>&lt;P&gt;I have a Cisco 9800 WLC running 17.12.5 and I have 1 central site (local mode APs where the WLC resides) and about 10 remote sites with APs in FlexConnect Mode and Local Authentication. Each remote site has a local authentication server with the authentication server at the central site as the backup.&lt;BR /&gt;At some of the remote sites local authentication works 100%, but at some sites it does not. I have verified the Policy Profile, Flex Profile and Site Tags at the "non-working" sites and compared them to the working sites and they are exactly the same except for Name and IPs which are specific to the site.&lt;BR /&gt;Clients at the "non-working" sites authenticate with the servers at the central site and not the server locally to the site. If we remove the backup authentication server all together clients at the non-working site still authenticate with the central site authentication server. We have verified "Central DHCP", "Central Authentication" &amp;amp; "Central Switching" are all disabled&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 08:57:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-authentication-server-does-not-update-policy-on-ap/m-p/5343649#M287251</guid>
      <dc:creator>Toy Thompson</dc:creator>
      <dc:date>2025-10-31T08:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Local Authentication Server does not update policy on AP</title>
      <link>https://community.cisco.com/t5/wireless/local-authentication-server-does-not-update-policy-on-ap/m-p/5343652#M287252</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1807043"&gt;@Toy Thompson&lt;/a&gt;&amp;nbsp; &amp;nbsp; Verify the controller's &lt;STRONG&gt;configuration&lt;/STRONG&gt; with the CLI command : &lt;FONT color="#008000"&gt;&lt;STRONG&gt;show tech wireless&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; and feed the output from that into&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-config-analyzer/" target="_blank"&gt;Wireless Config Analyzer&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Use the full command as outlined in green , it does not work with &lt;FONT color="#FF0000"&gt;&lt;EM&gt;show tech-support&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 09:15:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-authentication-server-does-not-update-policy-on-ap/m-p/5343652#M287252</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-10-31T09:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Local Authentication Server does not update policy on AP</title>
      <link>https://community.cisco.com/t5/wireless/local-authentication-server-does-not-update-policy-on-ap/m-p/5344017#M287278</link>
      <description>&lt;P&gt;Hi Mark. I have analyzed the output of the command with the analyzer. The analyzer did not provide any issues relating to the configuration of the profiles. I also manually compared the various profiles and tags in the analyzer itself and they are all pretty much identical except for the native and client vlans of the different sites. what did stand out is that the config analyzer only reports authentication information going to and from the backup aaa server however we validated the clients actually authenticate to the local aaa servers for remote sites that are working but no traffic shows for any of the remote site aaa servers?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 08:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-authentication-server-does-not-update-policy-on-ap/m-p/5344017#M287278</guid>
      <dc:creator>Toy Thompson</dc:creator>
      <dc:date>2025-11-03T08:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Local Authentication Server does not update policy on AP</title>
      <link>https://community.cisco.com/t5/wireless/local-authentication-server-does-not-update-policy-on-ap/m-p/5344072#M287279</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1807043"&gt;@Toy Thompson&lt;/a&gt;&amp;nbsp; &amp;nbsp; Then you will have to debug&amp;nbsp; the &lt;FONT color="#FF6600"&gt;&lt;EM&gt;"&lt;STRONG&gt;none-working&lt;/STRONG&gt;" clients&lt;/EM&gt;&lt;/FONT&gt; according to :&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity" target="_blank"&gt;https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; These resulting debugs , so called &lt;STRONG&gt;RadioActive Traces&lt;/STRONG&gt; can be analyzed with:&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank"&gt;Wireless Debug Analyzer&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Nov 2025 13:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-authentication-server-does-not-update-policy-on-ap/m-p/5344072#M287279</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-11-03T13:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Local Authentication Server does not update policy on AP</title>
      <link>https://community.cisco.com/t5/wireless/local-authentication-server-does-not-update-policy-on-ap/m-p/5344663#M287325</link>
      <description>&lt;P&gt;Are you using ISE as authenitcation server , have to check the policy rules ?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Nov 2025 10:06:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/local-authentication-server-does-not-update-policy-on-ap/m-p/5344663#M287325</guid>
      <dc:creator>srimal99</dc:creator>
      <dc:date>2025-11-05T10:06:31Z</dc:date>
    </item>
  </channel>
</rss>

