<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 1130 authentication debugging problems in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/1130-authentication-debugging-problems/m-p/1028955#M69630</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone help with debugging authentication on a 1130 access point using 12.4(3g)JA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically users are required to authenticate against a radius server, when connected to the SSID&lt;/P&gt;&lt;P&gt;'eduroam'. We are a large site with a lot of access points covering most of it. While all the access&lt;/P&gt;&lt;P&gt;points have pretty much the same configuration, two of them will not allow users to authenticate and&lt;/P&gt;&lt;P&gt;therefor will not pass traffic. The vlan assignments from the switch end appear to be ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The one I have picked for debugging is in a fairly isolated area, with no other wireless signals detected&lt;/P&gt;&lt;P&gt;with netstumbler. It is basic office space, so there should not be any other RF interference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've turned on a fair bit of debugging (see 'show debug' output below), however the logged messages&lt;/P&gt;&lt;P&gt;are fairly limited:&lt;/P&gt;&lt;P&gt;Apr 24 14:06:45 wapsumand  105675: Apr 24 13:06:44.871: AAA/BIND(00014F21): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:07:15 wapsumand  105676: Apr 24 13:07:14.859: %DOT11-7-AUTH_FAILED: Station 001c.b3c6.b49b Authentication failed&lt;/P&gt;&lt;P&gt;Apr 24 14:07:15 wapsumand  105677: Apr 24 13:07:14.867: AAA/BIND(00014F22): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:07:45 wapsumand  105678: Apr 24 13:07:44.866: %DOT11-7-AUTH_FAILED: Station 001c.b3c6.b49b Authentication failed&lt;/P&gt;&lt;P&gt;Apr 24 14:07:45 wapsumand  105679: Apr 24 13:07:44.875: AAA/BIND(00014F23): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:07:59 wapsumand  105680: Apr 24 13:07:58.522: AAA/BIND(00014F24): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:07:59 wapsumand  105681: Apr 24 13:07:59.209: %DOT11-7-AUTH_FAILED: Station 0018.de0d.893d Authentication failed&lt;/P&gt;&lt;P&gt;Apr 24 14:07:59 wapsumand  105682: Apr 24 13:07:59.237: AAA/BIND(00014F25): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:08:00 wapsumand  105683: Apr 24 13:07:59.941: AAA/BIND(00014F26): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:08:00 wapsumand  105684: Apr 24 13:08:00.638: AAA/BIND(00014F27): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:08:15 wapsumand  105685: Apr 24 13:08:14.861: %DOT11-7-AUTH_FAILED: Station 001c.b3c6.b49b Authentication failed&lt;/P&gt;&lt;P&gt;Apr 24 14:08:15 wapsumand  105686: Apr 24 13:08:14.870: AAA/BIND(00014F28): Bind i/f  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I expected to see more details of which radius server it is talking to, what is sent, what the&lt;/P&gt;&lt;P&gt;response is etc. The radius server itself is not logging much either. I have verified that there is&lt;/P&gt;&lt;P&gt;ping connectivity between the AP and server. Again, I've done the obvious and made sure the client&lt;/P&gt;&lt;P&gt;in question could authenticate using other APs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only difference I can see between these two faulty APs and the rest of the network is they are&lt;/P&gt;&lt;P&gt;much newer and previous APs are running IOS 12.3. I'm not aware of any major changes that would&lt;/P&gt;&lt;P&gt;cause these problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone see anything obviously wrong with the config, or suggest some more debugging options to&lt;/P&gt;&lt;P&gt;turn on, so I can really see what is going on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config is attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show version&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C1130 Software (C1130-K9W7-M), Version 12.4(3g)JA, RELEASE SOFTWARE (fc2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;General OS:&lt;/P&gt;&lt;P&gt;  TACACS+ authentication debugging is on&lt;/P&gt;&lt;P&gt;  AAA Authentication debugging is on&lt;/P&gt;&lt;P&gt;  AAA Authorization debugging is on&lt;/P&gt;&lt;P&gt;dot11/wlccp authenticator:&lt;/P&gt;&lt;P&gt;  state machine debugging is on&lt;/P&gt;&lt;P&gt;  process debugging is on&lt;/P&gt;&lt;P&gt;  Mac Authentication debugging is on&lt;/P&gt;&lt;P&gt;Radius protocol debugging is on&lt;/P&gt;&lt;P&gt;Radius packet protocol (authentication) debugging is on&lt;/P&gt;&lt;P&gt;dot11:&lt;/P&gt;&lt;P&gt;  IEEE 802.11 events debugging is on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 03 Jul 2021 22:46:23 GMT</pubDate>
    <dc:creator>davehartburn</dc:creator>
    <dc:date>2021-07-03T22:46:23Z</dc:date>
    <item>
      <title>1130 authentication debugging problems</title>
      <link>https://community.cisco.com/t5/wireless/1130-authentication-debugging-problems/m-p/1028955#M69630</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone help with debugging authentication on a 1130 access point using 12.4(3g)JA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically users are required to authenticate against a radius server, when connected to the SSID&lt;/P&gt;&lt;P&gt;'eduroam'. We are a large site with a lot of access points covering most of it. While all the access&lt;/P&gt;&lt;P&gt;points have pretty much the same configuration, two of them will not allow users to authenticate and&lt;/P&gt;&lt;P&gt;therefor will not pass traffic. The vlan assignments from the switch end appear to be ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The one I have picked for debugging is in a fairly isolated area, with no other wireless signals detected&lt;/P&gt;&lt;P&gt;with netstumbler. It is basic office space, so there should not be any other RF interference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've turned on a fair bit of debugging (see 'show debug' output below), however the logged messages&lt;/P&gt;&lt;P&gt;are fairly limited:&lt;/P&gt;&lt;P&gt;Apr 24 14:06:45 wapsumand  105675: Apr 24 13:06:44.871: AAA/BIND(00014F21): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:07:15 wapsumand  105676: Apr 24 13:07:14.859: %DOT11-7-AUTH_FAILED: Station 001c.b3c6.b49b Authentication failed&lt;/P&gt;&lt;P&gt;Apr 24 14:07:15 wapsumand  105677: Apr 24 13:07:14.867: AAA/BIND(00014F22): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:07:45 wapsumand  105678: Apr 24 13:07:44.866: %DOT11-7-AUTH_FAILED: Station 001c.b3c6.b49b Authentication failed&lt;/P&gt;&lt;P&gt;Apr 24 14:07:45 wapsumand  105679: Apr 24 13:07:44.875: AAA/BIND(00014F23): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:07:59 wapsumand  105680: Apr 24 13:07:58.522: AAA/BIND(00014F24): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:07:59 wapsumand  105681: Apr 24 13:07:59.209: %DOT11-7-AUTH_FAILED: Station 0018.de0d.893d Authentication failed&lt;/P&gt;&lt;P&gt;Apr 24 14:07:59 wapsumand  105682: Apr 24 13:07:59.237: AAA/BIND(00014F25): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:08:00 wapsumand  105683: Apr 24 13:07:59.941: AAA/BIND(00014F26): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:08:00 wapsumand  105684: Apr 24 13:08:00.638: AAA/BIND(00014F27): Bind i/f  &lt;/P&gt;&lt;P&gt;Apr 24 14:08:15 wapsumand  105685: Apr 24 13:08:14.861: %DOT11-7-AUTH_FAILED: Station 001c.b3c6.b49b Authentication failed&lt;/P&gt;&lt;P&gt;Apr 24 14:08:15 wapsumand  105686: Apr 24 13:08:14.870: AAA/BIND(00014F28): Bind i/f  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I expected to see more details of which radius server it is talking to, what is sent, what the&lt;/P&gt;&lt;P&gt;response is etc. The radius server itself is not logging much either. I have verified that there is&lt;/P&gt;&lt;P&gt;ping connectivity between the AP and server. Again, I've done the obvious and made sure the client&lt;/P&gt;&lt;P&gt;in question could authenticate using other APs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only difference I can see between these two faulty APs and the rest of the network is they are&lt;/P&gt;&lt;P&gt;much newer and previous APs are running IOS 12.3. I'm not aware of any major changes that would&lt;/P&gt;&lt;P&gt;cause these problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone see anything obviously wrong with the config, or suggest some more debugging options to&lt;/P&gt;&lt;P&gt;turn on, so I can really see what is going on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config is attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show version&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C1130 Software (C1130-K9W7-M), Version 12.4(3g)JA, RELEASE SOFTWARE (fc2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;General OS:&lt;/P&gt;&lt;P&gt;  TACACS+ authentication debugging is on&lt;/P&gt;&lt;P&gt;  AAA Authentication debugging is on&lt;/P&gt;&lt;P&gt;  AAA Authorization debugging is on&lt;/P&gt;&lt;P&gt;dot11/wlccp authenticator:&lt;/P&gt;&lt;P&gt;  state machine debugging is on&lt;/P&gt;&lt;P&gt;  process debugging is on&lt;/P&gt;&lt;P&gt;  Mac Authentication debugging is on&lt;/P&gt;&lt;P&gt;Radius protocol debugging is on&lt;/P&gt;&lt;P&gt;Radius packet protocol (authentication) debugging is on&lt;/P&gt;&lt;P&gt;dot11:&lt;/P&gt;&lt;P&gt;  IEEE 802.11 events debugging is on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 22:46:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/1130-authentication-debugging-problems/m-p/1028955#M69630</guid>
      <dc:creator>davehartburn</dc:creator>
      <dc:date>2021-07-03T22:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: 1130 authentication debugging problems</title>
      <link>https://community.cisco.com/t5/wireless/1130-authentication-debugging-problems/m-p/1028956#M69631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This appears to be a MAC authentication problem according to this document&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/wireless/ps430/products_tech_note09186a008024aa4f.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/wireless/ps430/products_tech_note09186a008024aa4f.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One tip they givr is to verify that the MAC address was entered using lowercase only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"When a MAC address authentication fails, check for the accuracy of the characters that are entered in the MAC address. Be sure that you have entered any alphabetic characters in a MAC address in lowercase."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bill&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Apr 2008 04:31:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/1130-authentication-debugging-problems/m-p/1028956#M69631</guid>
      <dc:creator>bcolvin</dc:creator>
      <dc:date>2008-04-27T04:31:18Z</dc:date>
    </item>
  </channel>
</rss>

