<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Client AAA Authentication Failure in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/client-aaa-authentication-failure/m-p/1849448#M69293</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well if you get a reject from the radius server, WLC is doing nothing wrong but you should check on your radius server what is the reason of the reject. There has to be a message there &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Nov 2011 10:32:10 GMT</pubDate>
    <dc:creator>Nicolas Darchis</dc:creator>
    <dc:date>2011-11-18T10:32:10Z</dc:date>
    <item>
      <title>Client AAA Authentication Failure</title>
      <link>https://community.cisco.com/t5/wireless/client-aaa-authentication-failure/m-p/1849447#M69292</link>
      <description>&lt;P&gt;Hi, I have configured a WLAN for AAA authentication and have configured AAA/Radius authentication on the WLC, however the clients don't get authenticated when they try to join. I have run a debug and I am getting an authentication rejected message from the radius server. Below is the output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-Challenge received from RADIUS server 10.24.12.32 for mobile x.x.x.x receiveId = 5&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_4: Nov 18 15:52:47.915: x.x.x.x Processing Access-Challenge for mobile x.x.x.x&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_4: Nov 18 15:52:47.915: x.x.x.x WARNING: updated EAP-Identifier 1 ===&amp;gt; 27 for STA x.x.x.x&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_4: Nov 18 15:52:47.915: x.x.x.x Sending EAP Request from AAA to mobile x.x.x.x (EAP Id 27)&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_4: Nov 18 15:52:47.935: x.x.x.x Received EAPOL EAPPKT from mobile x.x.x.x&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_4: Nov 18 15:52:47.935: x.x.x.x Received EAP Response from mobile x.x.x.x (EAP Id 27, EAP Type 3)&lt;/P&gt;&lt;P&gt;*aaaQueueReader: Nov 18 15:52:47.935: apfVapRadiusInfoGet: WLAN(1) dynamic int attributes srcAddr:0x0, gw:0x0, mask:0x0, vlan:0, dpPort:0, srcPort:0&lt;/P&gt;&lt;P&gt;*aaaQueueReader: Nov 18 15:52:47.935: x.x.x.x Successful transmission of Authentication Packet (id 76) to 10.24.12.32:1812, proxy state x.x.x.x-00:00&lt;/P&gt;&lt;P&gt;*radiusTransportThread: Nov 18 15:52:47.938: ****Enter processIncomingMessages: response code=3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;****Enter processRadiusResponse: response code=3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*radiusTransportThread: Nov 18 15:52:47.938: x.x.x.x Access-Reject received from RADIUS server 10.24.12.32 for mobile x.x.x.x receiveId = 5&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-aaa-authentication-failure/m-p/1849447#M69292</guid>
      <dc:creator>hadisharifi</dc:creator>
      <dc:date>2021-07-04T04:05:46Z</dc:date>
    </item>
    <item>
      <title>Client AAA Authentication Failure</title>
      <link>https://community.cisco.com/t5/wireless/client-aaa-authentication-failure/m-p/1849448#M69293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well if you get a reject from the radius server, WLC is doing nothing wrong but you should check on your radius server what is the reason of the reject. There has to be a message there &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Nov 2011 10:32:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-aaa-authentication-failure/m-p/1849448#M69293</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-11-18T10:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Client AAA Authentication Failure</title>
      <link>https://community.cisco.com/t5/wireless/client-aaa-authentication-failure/m-p/1849449#M69294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply, I checked the logs and it shows the correct username who has attempted to login and then for the same user it shows the machine name trying to login. Could it be something to do with the client's configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any specific config that needs to be made on the clients who are mostly windows based devices, the user doesn't get prompted to enter a username or password even when 802.1X is selected for the Authentication.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Nov 2011 14:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-aaa-authentication-failure/m-p/1849449#M69294</guid>
      <dc:creator>hadisharifi</dc:creator>
      <dc:date>2011-11-18T14:08:08Z</dc:date>
    </item>
    <item>
      <title>Client AAA Authentication Failure</title>
      <link>https://community.cisco.com/t5/wireless/client-aaa-authentication-failure/m-p/1849450#M69295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take packet capture at the Radius server port, filter for Radius packets with shared secret configured on Wireshark, it should tell why it is failing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Van&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Nov 2011 07:52:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-aaa-authentication-failure/m-p/1849450#M69295</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2011-11-22T07:52:02Z</dc:date>
    </item>
  </channel>
</rss>

