<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC not integrating with Radius Server in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-not-integrating-with-radius-server/m-p/1896115#M8005</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the certificate on the cleint machine still valid and also on the radius server.&amp;nbsp; I would also try to restart the IAS service or reboot the box just to make sure its not hung.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Mar 2012 12:40:56 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2012-03-06T12:40:56Z</dc:date>
    <item>
      <title>WLC not integrating with Radius Server</title>
      <link>https://community.cisco.com/t5/wireless/wlc-not-integrating-with-radius-server/m-p/1896114#M8004</link>
      <description>&lt;P&gt;Hello world,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the following situation:&lt;/P&gt;&lt;P&gt;One WLC 2000 Series (software version 7.0.230.0) with multiple SSID`s, one is with 802.1x integrated with a Radius Server.&lt;/P&gt;&lt;P&gt;Everything worked fine until fiew days ago, when users were unable to logon via they`re certificates on Windows XP.&lt;/P&gt;&lt;P&gt;The infrastracture didn`t suffer modifications.&lt;/P&gt;&lt;P&gt;What i have checked: Radius certification isn`t expired, client certification isn`t expired, the password between controller and Radius is correct.&lt;/P&gt;&lt;P&gt;There are no ACL`s between the WLC and the remote Server. I can ping the devices, other SSIDs on the same controller (wpa/psk) are working correct.&lt;/P&gt;&lt;P&gt;The AP`s are 1242.&lt;/P&gt;&lt;P&gt;I have tried deleting the SSID, configure it back. The OS on Windows Server is&amp;nbsp; 2003 Standard. The AP`s are configured H-Reap.&lt;/P&gt;&lt;P&gt;I have increased the Server Timeout from Radius Authentication Servers from 2 to 30 sec.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The message logs recived on WLC Trap Logs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS server X.X.X.X:1812 failed to respond to request (ID 161) for client xx.xx.xx.xx.xx.xx/ user 'unknown'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The message from the debug dot1x aaa enable:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_CALLING_STATION_ID(31) index=1&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_CALLED_STATION_ID(30) index=2&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_NAS_PORT(5) index=3&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_INT_CISCO_AUDIT_SESSION_ID(7) index=4&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_NAS_IP_ADDRESS(4) index=5&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_NAS_IDENTIFIER(32) index=6&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_VAP_ID(1) index=7&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_SERVICE_TYPE(6) index=8&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_FRAMED_MTU(12) index=9&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_NAS_PORT_TYPE(61) index=10&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_EAP_MESSAGE(79) index=11&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_RAD_STATE(24) index=12&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Adding AAA_ATT_MESS_AUTH(80) index=13&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df AAA EAP Packet created request = 0x1cff348c.. !!!!&lt;/P&gt;&lt;P&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df Sending EAP Attribute (code=2, length=6, id=10) for mobile xx.xx.xx.xx.xx.xx.&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00000000: 02 0a 00 06 0d 00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ......&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.318: 00:15:e9:33:75:df [BE-req] Sending auth request to 'RADIUS' (proto 0x140001)&lt;BR /&gt;*radiusTransportThread: Mar 06 09:37:07.328: 00:15:e9:33:75:df [BE-resp] AAA response 'Interim Response'&lt;BR /&gt;*radiusTransportThread: Mar 06 09:37:07.328: 00:15:e9:33:75:df [BE-resp] Returning AAA response&lt;BR /&gt;*radiusTransportThread: Mar 06 09:37:07.328: 00:15:e9:33:75:df AAA Message 'Interim Response' received for mobile xx.xx.xx.xx.xx.xx.&lt;BR /&gt;*Dot1x_NW_MsgTask_7: Mar 06 09:37:07.329: 00:15:e9:33:75:df Skipping AVP (0/27) for mobile xx.xx.xx.xx.xx.xx.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The messages on Windows 2003 Standard:&lt;/P&gt;&lt;P&gt;User Y was denied access.&lt;/P&gt;&lt;P&gt;Fully-Qualified-User-Name = xx.domain.com/Users_T/user&lt;/P&gt;&lt;P&gt;NAS-IP-Address = X.X&amp;gt;X.X&lt;/P&gt;&lt;P&gt;NAS-Identifier = Cisco_&lt;/P&gt;&lt;P&gt;Called-Station-Identifier = ---------------------&lt;/P&gt;&lt;P&gt;Calling-Station-Identifier = ---------------------&lt;/P&gt;&lt;P&gt;Client-Friendly-Name = ---------------------&lt;/P&gt;&lt;P&gt;Client-IP-Address = ---------------------&lt;/P&gt;&lt;P&gt;NAS-Port-Type = Wireless - IEEE 802.11&lt;/P&gt;&lt;P&gt;NAS-Port = 1&lt;/P&gt;&lt;P&gt;Proxy-Policy-Name = Use Windows authentication for all users&lt;/P&gt;&lt;P&gt;Authentication-Provider = Windows &lt;/P&gt;&lt;P&gt;Authentication-Server = &amp;lt;undetermined&amp;gt; &lt;/P&gt;&lt;P&gt;Policy-Name = Wireless Policy&lt;/P&gt;&lt;P&gt;Authentication-Type = EAP&lt;/P&gt;&lt;P&gt;EAP-Type = Smart Card or other certificate&lt;/P&gt;&lt;P&gt;Reason-Code = 262&lt;/P&gt;&lt;P&gt;Reason = The supplied message is incomplete.&amp;nbsp; The signature was not verified.User Y was denied access.&lt;BR /&gt;Fully-Qualified-User-Name = xx.domain.com/Users_T/user&lt;/P&gt;&lt;P&gt;NAS-IP-Address = X.X&amp;gt;X.X&lt;BR /&gt;NAS-Identifier = Cisco_&lt;BR /&gt;Called-Station-Identifier = ---------------------&lt;BR /&gt;Calling-Station-Identifier = ---------------------&lt;BR /&gt;Client-Friendly-Name = ---------------------&lt;BR /&gt;Client-IP-Address = ---------------------&lt;BR /&gt;NAS-Port-Type = Wireless - IEEE 802.11&lt;BR /&gt;NAS-Port = 1&lt;BR /&gt;Proxy-Policy-Name = Use Windows authentication for all users&lt;BR /&gt;Authentication-Provider = Windows &lt;BR /&gt;Authentication-Server = &amp;lt;undetermined&amp;gt; &lt;BR /&gt;Policy-Name = Wireless Policy&lt;BR /&gt;Authentication-Type = EAP&lt;BR /&gt;EAP-Type = Smart Card or other certificate&lt;BR /&gt;Reason-Code = 262&lt;BR /&gt;Reason = The supplied message is incomplete.&amp;nbsp; The signature was not verified. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone help why i cannot log the users via 802.1x ?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:43:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-not-integrating-with-radius-server/m-p/1896114#M8004</guid>
      <dc:creator>Calin Cristea</dc:creator>
      <dc:date>2021-07-04T04:43:55Z</dc:date>
    </item>
    <item>
      <title>WLC not integrating with Radius Server</title>
      <link>https://community.cisco.com/t5/wireless/wlc-not-integrating-with-radius-server/m-p/1896115#M8005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the certificate on the cleint machine still valid and also on the radius server.&amp;nbsp; I would also try to restart the IAS service or reboot the box just to make sure its not hung.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 12:40:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-not-integrating-with-radius-server/m-p/1896115#M8005</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-03-06T12:40:56Z</dc:date>
    </item>
    <item>
      <title>WLC not integrating with Radius Server</title>
      <link>https://community.cisco.com/t5/wireless/wlc-not-integrating-with-radius-server/m-p/1896116#M8006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The certificate is still valid on the pc, i even renew it. On the server aswell.&lt;/P&gt;&lt;P&gt; I have restarted the IAS Service, The IAS Server, the controller, access point...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 13:32:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-not-integrating-with-radius-server/m-p/1896116#M8006</guid>
      <dc:creator>Calin Cristea</dc:creator>
      <dc:date>2012-03-06T13:32:00Z</dc:date>
    </item>
    <item>
      <title>WLC not integrating with Radius Server</title>
      <link>https://community.cisco.com/t5/wireless/wlc-not-integrating-with-radius-server/m-p/1896117#M8007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay that is good..... this is what I would do next.&amp;nbsp; I would create a test ssid that uses PEAP MSchapv2 and create a new policy in IAS that is basic.&amp;nbsp; Allow 802.1x wireless and user group only and see if you can reconfigure one of the XP machines for PEAP.&amp;nbsp; Can you also post a screen shot of your polices (connection and network) so we can review it.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 13:52:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-not-integrating-with-radius-server/m-p/1896117#M8007</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-03-06T13:52:21Z</dc:date>
    </item>
  </channel>
</rss>

