<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AP Mab Authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343918#M749</link>
    <description>&lt;P&gt;Hm ok so it doesn't look to be an auth issue. Can you ping either of the APs? Can you see the APs discovering the WLC? Please show the outputs of these commands:&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show ap join stats summary all&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show sysinfo&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the APs, do you see logs of them discovering/trying to join the WLC? How are you helping them to find it, are they in the same subnet or using Option 43?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ric&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Mar 2018 10:47:07 GMT</pubDate>
    <dc:creator>Ric Beeching</dc:creator>
    <dc:date>2018-03-07T10:47:07Z</dc:date>
    <item>
      <title>AP Mab Authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343716#M744</link>
      <description>&lt;P&gt;HI Expert,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I configured MAB on the switchport&amp;nbsp;which connected to AP(model 3700 and Model 3800), ISE configured as AAA Radius server for authentication. My question as below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Switch showed authentication status as Unauth&lt;/P&gt;
&lt;P&gt;3750X#show authentication sessions&lt;/P&gt;
&lt;P&gt;Interface MAC Address Method Domain Status Fg Session ID&lt;BR /&gt;Gi1/0/17 7c0e.ceea.60e4 mab DATA Unauth 0A4FF7EC0000031891F5A5F4&lt;BR /&gt;Gi1/0/8 002a.1034.afa8 mab DATA Unauth 0A4FF7EC0000031991F7354C&lt;/P&gt;
&lt;P&gt;Session count = 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Both APs configured as static IP, ISE got authentication passed log. but AP can't join WLC as expected and mab authentication status on switch keep Unauthen&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May I know the reason or way how to fix this issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anthony&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 15:20:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343716#M744</guid>
      <dc:creator>jielfu</dc:creator>
      <dc:date>2021-07-05T15:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: AP Mab Authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343743#M745</link>
      <description>&lt;P&gt;Could you paste the output of your AAA config?&amp;nbsp;&lt;STRONG&gt;show run | i aaa|radius&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and also the running config of the interface with MAB. Are you running LW mode APs or FlexConnect local switch?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ric&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 04:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343743#M745</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2018-03-07T04:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: AP Mab Authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343770#M746</link>
      <description>&lt;P&gt;Hi Ric,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the responce, please refer to below output, Ap 3700 is running in Local mode, and AP 3800 is running on Flexconnect Mode.&lt;/P&gt;
&lt;P&gt;3750X#show run | in aaa| radius&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa group server radius WLtest&lt;BR /&gt;aaa authentication dot1x default group WLtest&lt;BR /&gt;aaa authorization network default group WLtest &lt;BR /&gt;aaa accounting dot1x default start-stop group WLtest&lt;BR /&gt;aaa session-id common&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3750X#show run | be aaa group&lt;BR /&gt;&lt;BR /&gt;aaa group server radius WLtest&lt;BR /&gt;server-private 10.79.247.10 key cisco&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3750X#show run int gigabitEthernet 1/0/17&lt;BR /&gt;&lt;BR /&gt;interface GigabitEthernet1/0/17&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Description to 3700&lt;BR /&gt;switchport access vlan 112&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication host-mode multi-host&lt;BR /&gt;authentication order mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3750X#show run int gigabitEthernet 1/0/8 &lt;BR /&gt;&lt;BR /&gt;interface GigabitEthernet1/0/8&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;Description to 3800&lt;/SPAN&gt;&lt;BR /&gt;switchport access vlan 112&lt;BR /&gt;switchport mode access&lt;BR /&gt;authentication host-mode multi-host&lt;BR /&gt;authentication order mab&lt;BR /&gt;authentication port-control auto&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 06:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343770#M746</guid>
      <dc:creator>jielfu</dc:creator>
      <dc:date>2018-03-07T06:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: AP Mab Authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343802#M747</link>
      <description>Thanks,&lt;BR /&gt;&lt;BR /&gt;Can you add the following global command (check if it is there first or not):&lt;BR /&gt;&lt;BR /&gt;conf t&lt;BR /&gt;dot1x system-auth-control&lt;BR /&gt;end&lt;BR /&gt;&lt;BR /&gt;and then also do a debug aaa authentication and post the output as the AP tries to auth. Do you see any auths come through on the RADIUS server?&lt;BR /&gt;</description>
      <pubDate>Wed, 07 Mar 2018 07:17:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343802#M747</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2018-03-07T07:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: AP Mab Authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343808#M748</link>
      <description>&lt;P&gt;Yes,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Command, dot1x system-auth-control configured in SW already&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I attached the screenshot from Radius server, it showed authentication pass&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 07:23:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343808#M748</guid>
      <dc:creator>jielfu</dc:creator>
      <dc:date>2018-03-07T07:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: AP Mab Authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343918#M749</link>
      <description>&lt;P&gt;Hm ok so it doesn't look to be an auth issue. Can you ping either of the APs? Can you see the APs discovering the WLC? Please show the outputs of these commands:&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show ap join stats summary all&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show sysinfo&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the APs, do you see logs of them discovering/trying to join the WLC? How are you helping them to find it, are they in the same subnet or using Option 43?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ric&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 10:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3343918#M749</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2018-03-07T10:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: AP Mab Authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3344086#M750</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I removed all of MAB commands line under the interface, then both APs can join WLC accordingly, so i isolate the issue from the wireless part, and focus on MAB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anthony&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 14:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3344086#M750</guid>
      <dc:creator>jielfu</dc:creator>
      <dc:date>2018-03-07T14:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: AP Mab Authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3344128#M751</link>
      <description>Odd!&lt;BR /&gt;&lt;BR /&gt;Can you debug aaa authentication and aaa authorization as you plug the AP in / bounce the port?&lt;BR /&gt;&lt;BR /&gt;Ric&lt;BR /&gt;</description>
      <pubDate>Wed, 07 Mar 2018 14:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3344128#M751</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2018-03-07T14:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: AP Mab Authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3344523#M752</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks Ric,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are few outputs I got below,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3750X#debug aaa authentication&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3750X#debug aaa authorization&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;3750X#clear authentication sessions interface gigabitEthernet 1/0/17&lt;BR /&gt;3750X#&lt;BR /&gt;Mar 8 01:59:06.725: AAA/AUTHOR: auth_need : user= 'wifiadmin' ruser= '3750X'rem_addr= '10.79.96.123' priv= 15 list= '' AUTHOR-TYPE= 'commands'&lt;BR /&gt;Mar 8 01:59:06.851: AAA/AUTHEN/8021X (00000000): Pick method list 'default' &lt;BR /&gt;Mar 8 01:59:06.859: AAA/AUTHEN(00000000): There is no General DBReply Method Index details may not be specified&lt;BR /&gt;Mar 8 01:59:06.867: ERROR: AAA/ATTR: invalid attribute prefix: "ACS"&lt;BR /&gt;Mar 8 01:59:06.884: AAA/AUTHOR (0x0): Pick method list 'default'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anthony&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 02:07:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3344523#M752</guid>
      <dc:creator>jielfu</dc:creator>
      <dc:date>2018-03-08T02:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: AP Mab Authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3344679#M753</link>
      <description>Thanks,&lt;BR /&gt;&lt;BR /&gt;Just comparing to my switch. What software are you running on it? Have you tried a different switch? Can you also try authentication host-mode single-host on the 3700?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Ric</description>
      <pubDate>Thu, 08 Mar 2018 09:41:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3344679#M753</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2018-03-08T09:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: AP Mab Authentication</title>
      <link>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3345288#M754</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SW software version as below,&lt;/P&gt;
&lt;P&gt;Well, if all of the command lines we are talking about above working on your switch, I thought it should be software/hardware issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Switch Ports Model SW Version SW Image &lt;BR /&gt;------ ----- ----- ---------- ---------- &lt;BR /&gt;* 1 30 WS-C3750X-24P 15.2(3)E C3750E-UNIVERSALK9-M&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anthony&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 02:06:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ap-mab-authentication/m-p/3345288#M754</guid>
      <dc:creator>jielfu</dc:creator>
      <dc:date>2018-03-09T02:06:16Z</dc:date>
    </item>
  </channel>
</rss>

