<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC 2504 with Tacacs.net AAA not working in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-2504-with-tacacs-net-aaa-not-working/m-p/3705842#M5464</link>
    <description>&lt;P&gt;Hi guys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem where my wlc will not authenticate via tacacs.net , the server is reachable from the controller and Authentication, Accounting and Authorization has been setup and enabled on the WLC priority is Tacacs/Local.&amp;nbsp; On the tacacs server we have an entry for the whole management network and our switches and routers work just fine with no issue. Tacacs.net version 1.31&lt;/P&gt;
&lt;P&gt;When we test and do a packet capture on the firewall we can see packet towards the server but nothing back, just strange that switches would work and not the WLC, see debug below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advanced&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(Cisco Controller) &amp;gt;*aaaQueueReader: Sep 12 12:30:19.075: AuthenticationRequest: 0x2c618510&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;*aaaQueueReader: Sep 12 12:30:19.075:&amp;nbsp;&amp;nbsp; Callback.....................................0x114d0740&lt;BR /&gt;&lt;BR /&gt;*aaaQueueReader: Sep 12 12:30:19.075:&amp;nbsp;&amp;nbsp; protocolType.................................0x00020030&lt;BR /&gt;&lt;BR /&gt;*aaaQueueReader: Sep 12 12:30:19.075:&amp;nbsp;&amp;nbsp; proxyState...................................00:00:0B:DF:00:00-00:00&lt;BR /&gt;&lt;BR /&gt;*aaaQueueReader: Sep 12 12:30:19.075:&amp;nbsp;&amp;nbsp; Packet contains 5 AVPs (not shown)&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:19.176: Selected Tplus server xx.xx.xx (port:49, fd:0) to send the message&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:19.177: Setup the Tplus socket for server xx.xx.xx.xx (port:49)&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:19.177: Connecting to tacacs server xx.xx.xx on port=49 on sockFd= 76&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:19.177: Tplus server (xx.xx.xx.xx) start polling for 5sec&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.176: Tplus server (xx.xx.xx.xx) connect timeout: 150:Operation now in progress&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Failed to setup the Tplus socket for server xx.xx.xx.xx!&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Failed to send the Tplus message to xx.xx.xx.xx(port:49, fd:76)&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Failed to send Auth msg (session_id:0, seq_no:1) to server xx.xx.xx.xx(port 49)&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Tx Tried Cnt: 1, try on next available Tplus auth server&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: No Auth response from : xx.xx.xx.xx (req session_id:0, seq_no:1). Try next Auth server&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: No Auth response from: xx.xx.xx.xx (req session_id:0, seq_no:1), Tx Tried Cnt:1. Exhausted all servers&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Failed to send Auth msg (session_id:0, seq_no:1) to server xx.xx.xx.xx(port 49)&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Tx Tried Cnt: 1, try on next available Tplus auth server&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: No Auth response from : xx.xx.xx.xx (req session_id:0, seq_no:1). Try next Auth server&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: No Auth response from: xx.xx.xx.xx (req session_id:0, seq_no:1), Tx Tried Cnt:1. Exhausted all servers&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Failed to send Auth msg (session_id:0, seq_no:1) to server xx.xx.xx.xx(port 49)&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Tx Tried Cnt: 1, try on next available Tplus auth server&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: None of the Tplus Auth servers (Tx Tried Cnt:1) are responding. Drop the auth request(session_id:0, seq_no:1)! &lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: ReProcessAuthentication previous proto 30, next proto 20008&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Unable to find requested user entry for john&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: 00:00:0b:df:00:00 Returning AAA Error 'Authentication Failed' (-4) for mobile 00:00:0b:df:00:00&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: AuthorizationResponse: 0x2bdd8c84&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; structureSize................................92&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; resultCode...................................-4&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocolUsed.................................0x00000008&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; proxyState...................................00:00:0B:DF:00:00-00:00&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packet contains 0 AVPs:&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 16:10:45 GMT</pubDate>
    <dc:creator>ryno.robile1</dc:creator>
    <dc:date>2021-07-05T16:10:45Z</dc:date>
    <item>
      <title>WLC 2504 with Tacacs.net AAA not working</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-with-tacacs-net-aaa-not-working/m-p/3705842#M5464</link>
      <description>&lt;P&gt;Hi guys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem where my wlc will not authenticate via tacacs.net , the server is reachable from the controller and Authentication, Accounting and Authorization has been setup and enabled on the WLC priority is Tacacs/Local.&amp;nbsp; On the tacacs server we have an entry for the whole management network and our switches and routers work just fine with no issue. Tacacs.net version 1.31&lt;/P&gt;
&lt;P&gt;When we test and do a packet capture on the firewall we can see packet towards the server but nothing back, just strange that switches would work and not the WLC, see debug below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advanced&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(Cisco Controller) &amp;gt;*aaaQueueReader: Sep 12 12:30:19.075: AuthenticationRequest: 0x2c618510&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;*aaaQueueReader: Sep 12 12:30:19.075:&amp;nbsp;&amp;nbsp; Callback.....................................0x114d0740&lt;BR /&gt;&lt;BR /&gt;*aaaQueueReader: Sep 12 12:30:19.075:&amp;nbsp;&amp;nbsp; protocolType.................................0x00020030&lt;BR /&gt;&lt;BR /&gt;*aaaQueueReader: Sep 12 12:30:19.075:&amp;nbsp;&amp;nbsp; proxyState...................................00:00:0B:DF:00:00-00:00&lt;BR /&gt;&lt;BR /&gt;*aaaQueueReader: Sep 12 12:30:19.075:&amp;nbsp;&amp;nbsp; Packet contains 5 AVPs (not shown)&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:19.176: Selected Tplus server xx.xx.xx (port:49, fd:0) to send the message&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:19.177: Setup the Tplus socket for server xx.xx.xx.xx (port:49)&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:19.177: Connecting to tacacs server xx.xx.xx on port=49 on sockFd= 76&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:19.177: Tplus server (xx.xx.xx.xx) start polling for 5sec&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.176: Tplus server (xx.xx.xx.xx) connect timeout: 150:Operation now in progress&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Failed to setup the Tplus socket for server xx.xx.xx.xx!&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Failed to send the Tplus message to xx.xx.xx.xx(port:49, fd:76)&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Failed to send Auth msg (session_id:0, seq_no:1) to server xx.xx.xx.xx(port 49)&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Tx Tried Cnt: 1, try on next available Tplus auth server&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: No Auth response from : xx.xx.xx.xx (req session_id:0, seq_no:1). Try next Auth server&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: No Auth response from: xx.xx.xx.xx (req session_id:0, seq_no:1), Tx Tried Cnt:1. Exhausted all servers&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Failed to send Auth msg (session_id:0, seq_no:1) to server xx.xx.xx.xx(port 49)&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Tx Tried Cnt: 1, try on next available Tplus auth server&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: No Auth response from : xx.xx.xx.xx (req session_id:0, seq_no:1). Try next Auth server&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: No Auth response from: xx.xx.xx.xx (req session_id:0, seq_no:1), Tx Tried Cnt:1. Exhausted all servers&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Failed to send Auth msg (session_id:0, seq_no:1) to server xx.xx.xx.xx(port 49)&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Tx Tried Cnt: 1, try on next available Tplus auth server&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: None of the Tplus Auth servers (Tx Tried Cnt:1) are responding. Drop the auth request(session_id:0, seq_no:1)! &lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: ReProcessAuthentication previous proto 30, next proto 20008&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: Unable to find requested user entry for john&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: 00:00:0b:df:00:00 Returning AAA Error 'Authentication Failed' (-4) for mobile 00:00:0b:df:00:00&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177: AuthorizationResponse: 0x2bdd8c84&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; structureSize................................92&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; resultCode...................................-4&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocolUsed.................................0x00000008&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; proxyState...................................00:00:0B:DF:00:00-00:00&lt;BR /&gt;&lt;BR /&gt;*tplusTransportThread: Sep 12 12:30:24.177:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packet contains 0 AVPs:&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 16:10:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-with-tacacs-net-aaa-not-working/m-p/3705842#M5464</guid>
      <dc:creator>ryno.robile1</dc:creator>
      <dc:date>2021-07-05T16:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 2504 with Tacacs.net AAA not working</title>
      <link>https://community.cisco.com/t5/wireless/wlc-2504-with-tacacs-net-aaa-not-working/m-p/3706570#M5465</link>
      <description>&lt;P&gt;Ok, got it partially working. Last question has anybody successfully setup a Cisco WLC to use free Tacacs.net ? getting authentication error Do i need to setup roles how do i do this on tacacs.net ?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 19:07:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-2504-with-tacacs-net-aaa-not-working/m-p/3706570#M5465</guid>
      <dc:creator>ryno.robile1</dc:creator>
      <dc:date>2018-09-13T19:07:12Z</dc:date>
    </item>
  </channel>
</rss>

