<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius Timeout Issues - remote site in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511363#M304764</link>
    <description>&lt;P&gt;&amp;gt;&lt;SPAN&gt; latency is around 133-137ms back to the Radius server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This is not your issue.&lt;/P&gt;&lt;P&gt;What I have seen is RADIUS packets failing when an MTU squeeze happens (such as when using VPN).  Try reducing the MTU on the RADIUS server, or see if the PA has some option to help with MTU adjustment.  Remember - RADIUS is UDP based.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2023 20:09:21 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2023-10-11T20:09:21Z</dc:date>
    <item>
      <title>Radius Timeout Issues - remote site</title>
      <link>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511358#M304759</link>
      <description>&lt;P&gt;Currently trying to setup a wireless network on the other side of the planet, we're experiencing Radius server timeouts on client authentication, latency is around 133-137ms back to the Radius server. Tried increasing the radius server timemout from 1s to 10s but no change.&lt;/P&gt;&lt;P&gt;Is there anything else we can try other than a local PSK&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 11:28:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511358#M304759</guid>
      <dc:creator>Shewie</dc:creator>
      <dc:date>2023-10-11T11:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Timeout Issues - remote site</title>
      <link>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511359#M304760</link>
      <description>&lt;P&gt;Is this communication via the Internet or S2S VPN?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 11:34:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511359#M304760</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2023-10-11T11:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Timeout Issues - remote site</title>
      <link>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511360#M304761</link>
      <description>&lt;P&gt;It's over a Palo Alto S2S VPN, we can see the requests reaching our Radius server but nothing gets back&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 11:35:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511360#M304761</guid>
      <dc:creator>Shewie</dc:creator>
      <dc:date>2023-10-11T11:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Timeout Issues - remote site</title>
      <link>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511361#M304762</link>
      <description>&lt;DIV&gt;&lt;SPAN&gt;Strange, did you ever do a packet capture in Palo Alto?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Are the Proxy ID on the tunnel and routes on the VR configured correctly?&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 11 Oct 2023 11:38:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511361#M304762</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2023-10-11T11:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Timeout Issues - remote site</title>
      <link>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511362#M304763</link>
      <description>&lt;P&gt;Another thing, I don't know which Radius you are using (NPS, Freeradius), but did you add the AP IP with the Radius Client?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 11:42:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511362#M304763</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2023-10-11T11:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Timeout Issues - remote site</title>
      <link>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511363#M304764</link>
      <description>&lt;P&gt;&amp;gt;&lt;SPAN&gt; latency is around 133-137ms back to the Radius server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This is not your issue.&lt;/P&gt;&lt;P&gt;What I have seen is RADIUS packets failing when an MTU squeeze happens (such as when using VPN).  Try reducing the MTU on the RADIUS server, or see if the PA has some option to help with MTU adjustment.  Remember - RADIUS is UDP based.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 20:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511363#M304764</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2023-10-11T20:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Timeout Issues - remote site</title>
      <link>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511364#M304765</link>
      <description>&lt;P&gt;I have the same issue at a few of our SD-WAN sites with Radius and EAP-TLS certs.  My solution was to use the Meraki Cloud Radius Proxy for these sites - the request goes out directly across the internet (Not over SDWan where there is added VPN packet overhead) to the radius proxy and then onward into datacentre where the request is accepted and returned back to the cloud radius and onto the WAN site.&lt;/P&gt;&lt;P&gt;Note: The meraki radius test feature (where there is no added user certs packet overhead) worked fine at these sites where it was only using username/pw authentication&lt;/P&gt;&lt;P&gt;I found changing MTU size on NPS radius made no difference - you have little or no control on the MTU size across your ISP links etc&lt;/P&gt;&lt;P&gt;Some pings showing packet fragmentation and comparing against working sites may help you check if MTU is your issue&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 12:32:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511364#M304765</guid>
      <dc:creator>pjc</dc:creator>
      <dc:date>2023-10-12T12:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Timeout Issues - remote site</title>
      <link>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511365#M304766</link>
      <description>&lt;P&gt;Thanks everyone for the replies, we're just working through some of the suggestions and will report back if we make any progress&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 12:38:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511365#M304766</guid>
      <dc:creator>Shewie</dc:creator>
      <dc:date>2023-10-12T12:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Timeout Issues - remote site</title>
      <link>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511366#M304767</link>
      <description>&lt;P&gt;+1 for MTU, we had issues with this exact problem and Access-Rejects due to timeouts. Setting the relevant NPS policy (Windows server) with a Framed-MTU of 1344 fixed it for us&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 07:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/radius-timeout-issues-remote-site/m-p/5511366#M304767</guid>
      <dc:creator>Paccers</dc:creator>
      <dc:date>2023-10-13T07:02:15Z</dc:date>
    </item>
  </channel>
</rss>

