<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Freeradius in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/freeradius/m-p/5488484#M297727</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;We operate a local AD with an NPS for the Meraki AP'S, which also works so far for all users.&lt;BR /&gt;Now we want to split the whole thing into 4 SSIDs, i.e. only certain users are allowed to log on to the corresponding SSID.&lt;BR /&gt;For this we want to switch from NPS to Freeradius 3.0 under ubuntu Server 24.04. The installation itself works without any problems, which I can check with the NTRadPing tool.&lt;BR /&gt;However, as soon as I integrate the radius in the dashboard, I get the message that the radius is accessible, but the login data is not correct. Messagetext.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Authentication failed while testing on one of your access points. This means the RADIUS server was reached but your credentials were incorrect. The test was stopped to prevent this account from being locked out due to multiple failed attempts. Please try again with different username and/or password."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;But the User and the Password are correct.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have already copied the corresponding configuration from &lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/Freeradius%3A_Configure_freeradius_to_work_with_EAP-TLS_authentication" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/Freeradius%3A_Configure_freeradius_to_work_with_EAP-TLS_authentication&lt;/A&gt; , but unfortunately without success.&lt;BR /&gt;Is anyone familiar with this issue and knows where I can start?&lt;/P&gt;&lt;P&gt;Translated with DeepL.com (free version)&lt;/P&gt;</description>
    <pubDate>Wed, 19 Mar 2025 06:46:13 GMT</pubDate>
    <dc:creator>School_admin</dc:creator>
    <dc:date>2025-03-19T06:46:13Z</dc:date>
    <item>
      <title>Freeradius</title>
      <link>https://community.cisco.com/t5/wireless/freeradius/m-p/5488484#M297727</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;We operate a local AD with an NPS for the Meraki AP'S, which also works so far for all users.&lt;BR /&gt;Now we want to split the whole thing into 4 SSIDs, i.e. only certain users are allowed to log on to the corresponding SSID.&lt;BR /&gt;For this we want to switch from NPS to Freeradius 3.0 under ubuntu Server 24.04. The installation itself works without any problems, which I can check with the NTRadPing tool.&lt;BR /&gt;However, as soon as I integrate the radius in the dashboard, I get the message that the radius is accessible, but the login data is not correct. Messagetext.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Authentication failed while testing on one of your access points. This means the RADIUS server was reached but your credentials were incorrect. The test was stopped to prevent this account from being locked out due to multiple failed attempts. Please try again with different username and/or password."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;But the User and the Password are correct.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have already copied the corresponding configuration from &lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/Freeradius%3A_Configure_freeradius_to_work_with_EAP-TLS_authentication" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/Freeradius%3A_Configure_freeradius_to_work_with_EAP-TLS_authentication&lt;/A&gt; , but unfortunately without success.&lt;BR /&gt;Is anyone familiar with this issue and knows where I can start?&lt;/P&gt;&lt;P&gt;Translated with DeepL.com (free version)&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 06:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/freeradius/m-p/5488484#M297727</guid>
      <dc:creator>School_admin</dc:creator>
      <dc:date>2025-03-19T06:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Freeradius</title>
      <link>https://community.cisco.com/t5/wireless/freeradius/m-p/5488485#M297728</link>
      <description>&lt;P&gt;Hi &lt;A class="" href="https://community.meraki.com/t5/user/viewprofilepage/user-id/123678" target="_self"&gt;&lt;SPAN class=""&gt;School_admin,&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Welcome to Meraki Community &lt;SPAN class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Have you taken packet captures while performing the RADIUS Test Tool button?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Wireshark filter - &lt;STRONG&gt;&lt;EM&gt;ip.addr==192.168.128.254 &amp;amp;&amp;amp; radius &lt;/EM&gt;&lt;/STRONG&gt;(replace 192.168.128.254 with your RADIUS server IP)&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Error message &lt;STRONG&gt;&lt;EM&gt;"the radius is accessible, but the login data is not correct"&lt;/EM&gt; :&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Have you tried with different login credentials? Do you have more than 1 AP in your network?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Is the credentials only failing while using the RADIUS Test Button or when connecting with a client device?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN class=""&gt;(1) Can you ping successfully the RADIUS Server? - &lt;A href="https://documentation.meraki.com/MR/Wireless_Troubleshooting/MR_RADIUS_Troubleshooting" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/MR/Wireless_Troubleshooting/MR_RADIUS_Troubleshooting&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;(2) Make sure the routing and firewalls are allowing communication to and from port 1812 - &lt;A href="https://community.meraki.com/t5/Wireless/RADIUS-servers-testing/td-p/43865" target="_blank"&gt;https://community.meraki.com/t5/Wireless/RADIUS-servers-testing/td-p/43865&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;(3) Check the RADIUS logs to see why it's failing.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;(4) The Authentication method in use seems to be EAP-TLS: Certificate-based authentication - &lt;A href="https://www.freeradius.org/documentation/freeradius-server/4.0.0/tutorials/eap-tls.html" target="_blank" rel="noopener nofollow noreferrer"&gt;https://www.freeradius.org/documentation/freeradius-server/4.0.0/tutorials/eap-tls.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;(5) Make sure this AP Is added to the RADIUS Server as Client - &lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/Freeradius%3A_Adding_a_gateway_AP_as_a_RADIUS_client" target="_self" rel="nofollow noopener noreferrer"&gt;Freeradius: Adding a gateway AP as a RADIUS client&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;(6) Is the credentials only failing while using the RADIUS Test Button or when connecting with a client device?&lt;/P&gt;&lt;P&gt;(7) Additional troubleshooting guides - &lt;SPAN class=""&gt;&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/RADIUS_Issue_Resolution_Guide/TS-flow-radius" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/RADIUS_Issue_Resolution_Guide/TS-flow-radius&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=Xmm6RKhkfy4" target="_self" rel="nofollow noopener noreferrer"&gt;Troubleshooting RADIUS server with the MX, Switch and MR using the Cisco Meraki Dashboard&lt;/A&gt;&lt;/P&gt;&lt;P&gt;(8) &lt;A href="https://tzali.com/my-blog/f/using-freeradius-with-cisco-meraki" target="_self" rel="nofollow noopener noreferrer"&gt;Using FreeRADIUS with Cisco Meraki&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you have additional questions, please don't hesitate to contact us.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 08:38:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/freeradius/m-p/5488485#M297728</guid>
      <dc:creator>allik</dc:creator>
      <dc:date>2025-03-19T08:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: Freeradius</title>
      <link>https://community.cisco.com/t5/wireless/freeradius/m-p/5488486#M297729</link>
      <description>&lt;P&gt;Good morning,&lt;BR /&gt;First of all, thanks for the relevant information and sorry that I'm only getting back to you now as I have too many things to do at the moment.&lt;/P&gt;&lt;P&gt;Unfortunately, Wireshark does not currently work via the dashboard.&lt;/P&gt;&lt;P&gt;To 1&lt;BR /&gt;The Freeradius is in the same network as the access point and the port is also enabled.&lt;BR /&gt;To 2&lt;BR /&gt;Not applicable as the radius and AP are in the same network&lt;BR /&gt;To 3 and 4&lt;BR /&gt;I'll have another look today as I didn't know the link until now.&lt;BR /&gt;To 5&lt;BR /&gt;All clients are entered accordingly&lt;/P&gt;&lt;P&gt;Re 6&lt;BR /&gt;When testing via the dashboard, there is just this error message.&lt;/P&gt;&lt;DIV class=""&gt;Completed testing&lt;SPAN&gt; &lt;/SPAN&gt;connectivity to&lt;SPAN&gt; &lt;/SPAN&gt;RADIUS&lt;SPAN&gt; &lt;/SPAN&gt;server at&lt;SPAN&gt; xx&lt;/SPAN&gt;.xx.xx.xx:1812&lt;/DIV&gt;&lt;DIV class=""&gt;Authentication failed while testing on one of your access points. This means the RADIUS server was reached but your credentials were incorrect. The test was stopped to prevent this account from being locked out due to multiple failed attempts. Please try again with different username and/or password." &lt;SPAN&gt;So the connection between the APs and the RAdius looks good in the dashboard.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;The user name and password are also requested on the client. Then I have to enter a password again, which makes me a bit nervous.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regarding the other points&lt;BR /&gt;I will also work through them again today.&lt;/P&gt;&lt;P&gt;Translated with DeepL.com (free version)&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 07:51:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/freeradius/m-p/5488486#M297729</guid>
      <dc:creator>School_admin</dc:creator>
      <dc:date>2025-03-20T07:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: Freeradius</title>
      <link>https://community.cisco.com/t5/wireless/freeradius/m-p/5488487#M297730</link>
      <description>&lt;P&gt;Hi &lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" href="https://community.meraki.com/t5/user/viewprofilepage/user-id/123678" target="_self"&gt;&lt;SPAN class=""&gt;School_admin&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Additional info from one of the documentation - &lt;A href="https://documentation.meraki.com/MR/Wireless_Troubleshooting/MR_RADIUS_Troubleshooting" target="_self" rel="nofollow noopener noreferrer"&gt;MR RADIUS Troubleshooting&lt;/A&gt;:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"If using an EAP type that requires a client-side certificate such as EAP-TLS, the test will fail because the AP does not have the certificate installed. It is recommended to test with a real client device. MR access points support the EAP types listed &lt;/SPAN&gt;&lt;U&gt;&lt;A title="https://documentation.meraki.com/MR/Encryption_and_Authentication/Wireless_Encryption_and_Authentication_Overview#WPA2-Enterprise_with_802.1X_Authentication" href="https://documentation.meraki.com/MR/Encryption_and_Authentication/Wireless_Encryption_and_Authentication_Overview#WPA2-Enterprise_with_802.1X_Authentication" target="_blank" rel="internal noopener nofollow noreferrer"&gt;here&lt;/A&gt;&lt;/U&gt;&lt;SPAN&gt;."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have you tested with a real client device?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you in advance &lt;SPAN class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2025 08:36:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/freeradius/m-p/5488487#M297730</guid>
      <dc:creator>allik</dc:creator>
      <dc:date>2025-03-24T08:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: Freeradius</title>
      <link>https://community.cisco.com/t5/wireless/freeradius/m-p/5488488#M297731</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;sorry for the late reply, but now I was able to capture the corresponding logs via the dashboard and see that the RADIUS request is made with the error: Duplicate Request from Client to Server. I then get the same message from the server to the client (MR57).&lt;BR /&gt;This is probably a timing problem, but I don't know where I can set this on the Freeradius.&lt;/P&gt;&lt;P&gt;Does anyone have such problems and how could they be solved?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Translated with DeepL.com (free version)&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2025 14:24:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/freeradius/m-p/5488488#M297731</guid>
      <dc:creator>School_admin</dc:creator>
      <dc:date>2025-03-24T14:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: Freeradius</title>
      <link>https://community.cisco.com/t5/wireless/freeradius/m-p/5488489#M297732</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;when I use a Windows client I get the same error messages as in the dashboard.&lt;BR /&gt;but now I was able to capture the corresponding logs via the dashboard and see that the RADIUS request is made with the error: Duplicate Request from Client to Server. I then get the same message from the server to the client (MR57).&lt;BR /&gt;This is probably a timing problem, but I don't know where I can set this on the Freeradius.&lt;/P&gt;&lt;P&gt;I Use &lt;SPAN&gt;EAP-TLS&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Translated with DeepL.com (free version)&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2025 14:26:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/freeradius/m-p/5488489#M297732</guid>
      <dc:creator>School_admin</dc:creator>
      <dc:date>2025-03-24T14:26:54Z</dc:date>
    </item>
  </channel>
</rss>

