<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC 4400: Web Authentication Using LDAP in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599635#M8596</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Nicolas!&lt;/P&gt;&lt;P&gt;Thank you very much for your advices!&lt;/P&gt;&lt;P&gt;Everything works now!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested the settings with the help of ldap browser, and then applied them to the controller&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Final WLC Ldap-server settings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simple Bind -&amp;nbsp; &lt;AUTHENTICATED&gt; (Anonymous doesn't work) &lt;BR /&gt;Bind Username - the user must be created in User Base DN folder (ex. OU=ORG)&lt;BR /&gt;User Base DN -&amp;nbsp; the core OU, that contains all users (ex. &lt;OU&gt;)&lt;BR /&gt;User Attribute - there can be two variants:&lt;BR /&gt;- sAMAccountName - &lt;USER1&gt; &lt;BR /&gt;- userPrincipalName - &amp;lt;&lt;A href="https://community.cisco.com/"&gt;user1@domain.local&lt;/A&gt;&amp;gt; &lt;BR /&gt;User Object Type - &lt;PERSON&gt;&lt;/PERSON&gt;&lt;/USER1&gt;&lt;/OU&gt;&lt;/AUTHENTICATED&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Mar 2011 12:42:03 GMT</pubDate>
    <dc:creator>Jaaazman777</dc:creator>
    <dc:date>2011-03-16T12:42:03Z</dc:date>
    <item>
      <title>WLC 4400: Web Authentication Using LDAP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599630#M8591</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;Dear all, I have some problems integrating WLC 4400 with AD using ldap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The the WLC LDAP Server and WLAN for Web Authentication are configured acoording to&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a0080a03e09.shtml#C2" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a0080a03e09.shtml#C2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I connect to SSID the laptop is given the ip address, then I can see the web-page with&lt;/P&gt;&lt;P&gt;login and pass - it seems to be OK, but when I enter login and pass it tells me, that&lt;/P&gt;&lt;P&gt;it's incorrect &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The attributes of the LDAP server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *.*.*.*&lt;/P&gt;&lt;P&gt;Port Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 389&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;User Base DN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ou=ORG,dc=domain,dc=local&lt;/P&gt;&lt;P&gt;User Attribute&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; userPrincipalName&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;User Object Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Person&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the test user is located in AD folder ORG, but this folder also contains a lot of subtrees&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are some questions:&lt;/P&gt;&lt;P&gt;1) Is it obligatory to use value "Authenticated" in the Simple Bind option or it can be Anonymous?&lt;/P&gt;&lt;P&gt;2) Is the Controller capable for searching the users located in User Base DN subtrees? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is some debug from the controller:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;667: LDAP_CLIENT: UID Search (base=.....&lt;/P&gt;&lt;P&gt;669: LDAP_CLIENT: ldap_search_ext_s returns 0 85&lt;/P&gt;&lt;P&gt;669: LDAP_CLIENT: Returned 1 msgs including 0 references&lt;/P&gt;&lt;P&gt;669: LDAP_CLIENT: Returned msg 1 type 0x65&lt;/P&gt;&lt;P&gt;669: LDAP_CLIENT : No matched DN&lt;/P&gt;&lt;P&gt;669: LDAP_CLIENT : Check result error 0 rc 1013&lt;/P&gt;&lt;P&gt;669: LDAP_CLIENT: Received no referrals in search result msg&lt;/P&gt;&lt;P&gt;669: LDAP_CLIENT: Received 1 attributes in search result msg&lt;/P&gt;&lt;P&gt;669: ldapAuthRequest [1] called lcapi_query base="ou=ORG,dc=domain,dc=local" type="Person" attr="userPrincipalName" user="test@domain.local" (rc = 0 - Success)&lt;/P&gt;&lt;P&gt;669: Handling LDAP response Authentication Failed&lt;/P&gt;&lt;P&gt;670: 00:1d:e0:a1:73:2f Returning AAA Error 'Authentication Failed' (-4) for mobile *MAC-address*&lt;/P&gt;&lt;P&gt;670: AuthorizationResponse: 0x31b6e2d0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 02:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599630#M8591</guid>
      <dc:creator>Jaaazman777</dc:creator>
      <dc:date>2021-07-04T02:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 4400: Web Authentication Using LDAP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599631#M8592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is your AD domain really "domain.local" ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To reply to your questions :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) It can be anonymous if you configured your AD to accept anonymous binding which is not the default behavior if I have a good memory&lt;/P&gt;&lt;P&gt;2) Yes it searches subtrees&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you type "test@domain.local" in the login page ? Try with "test" simply. Since you configured your base DN to be the ORG ou on domain.local, that's where the AD will search, no need of precising the domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Mar 2011 19:00:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599631#M8592</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-03-15T19:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 4400: Web Authentication Using LDAP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599632#M8593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you for your answers, &lt;SPAN&gt;&lt;A class="jiveTT-hover-user jive-username-link" href="https://community.cisco.com/people/ndarchis" id="jive-30385850,801,568,369,944,204"&gt;Nicolas Darchis&lt;/A&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps" title="Нажмите, чтобы увидеть альтернативный перевод"&gt;"All the&lt;/SPAN&gt; &lt;SPAN class="hps" title="Нажмите, чтобы увидеть альтернативный перевод"&gt;characters&lt;/SPAN&gt; &lt;SPAN class="hps" title="Нажмите, чтобы увидеть альтернативный перевод"&gt;are fictional" &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-author"&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About login...I think, when we use &lt;SPAN&gt;sAMAccountName we just need to type in the login, &lt;/SPAN&gt; and &lt;SPAN&gt;userPrincipalName requires typing the whole domain name &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any way I tried a lot of variants, but nothing worked out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what about debug? What can &lt;STRONG&gt;LDAP_CLIENT : No matched DN&lt;/STRONG&gt; mean?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Mar 2011 20:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599632#M8593</guid>
      <dc:creator>Jaaazman777</dc:creator>
      <dc:date>2011-03-15T20:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 4400: Web Authentication Using LDAP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599633#M8594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It says that AD returns "user not found".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, where is your admin account located ? The one you are authenticating with ?&lt;/P&gt;&lt;P&gt;Can you post the complete ldap configuration with the admin user as well ?&lt;/P&gt;&lt;P&gt;Note that the admin has to be under the same base DN as your search DN (so it has to be under ORG too).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In such situations, I usually download softterra ldap browser and connect to the AD from my laptop via LDAP, I use the same config as on the WLC to connect (admin username and then I do a search). It's often a small typo that makes it not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A sniffer trace of the ldap traffic also sometimes help to determine if the problem is with the admin user authentication or the search itself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Mar 2011 20:31:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599633#M8594</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-03-15T20:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 4400: Web Authentication Using LDAP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599634#M8595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-author"&gt;&lt;DIV class="jive-thread-username"&gt;&lt;DIV class="jive-thread-username"&gt;Nicolas Darchis, thank you very much for your advice!&lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt; &lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt;yes, my admin account is located in the same Base DN&lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt; &lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt;Server Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN&gt; &lt;/SPAN&gt;*.*.*.*&lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt;Port Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN&gt; &lt;/SPAN&gt;389 &lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt;Bind Username&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN&gt; &lt;/SPAN&gt;admin&lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt;Bind Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN&gt; &lt;/SPAN&gt;***&lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt;Confirm Bind Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN&gt; &lt;/SPAN&gt;***&lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt;User Base DN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN&gt; &lt;/SPAN&gt;ou=ORG,dc=domain,dc=local&lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt;User Attribute&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN&gt; &lt;/SPAN&gt;userPrincipalName&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt;User Object Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN&gt; &lt;/SPAN&gt;Person&lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt; &lt;/DIV&gt;&lt;DIV class="jive-thread-username"&gt;I'll try to use ldap browser, I hope It'll be helpful&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-body-container"&gt;&lt;DIV class="jive-thread-reply-subject"&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Mar 2011 20:41:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599634#M8595</guid>
      <dc:creator>Jaaazman777</dc:creator>
      <dc:date>2011-03-15T20:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 4400: Web Authentication Using LDAP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599635#M8596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Nicolas!&lt;/P&gt;&lt;P&gt;Thank you very much for your advices!&lt;/P&gt;&lt;P&gt;Everything works now!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested the settings with the help of ldap browser, and then applied them to the controller&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Final WLC Ldap-server settings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simple Bind -&amp;nbsp; &lt;AUTHENTICATED&gt; (Anonymous doesn't work) &lt;BR /&gt;Bind Username - the user must be created in User Base DN folder (ex. OU=ORG)&lt;BR /&gt;User Base DN -&amp;nbsp; the core OU, that contains all users (ex. &lt;OU&gt;)&lt;BR /&gt;User Attribute - there can be two variants:&lt;BR /&gt;- sAMAccountName - &lt;USER1&gt; &lt;BR /&gt;- userPrincipalName - &amp;lt;&lt;A href="https://community.cisco.com/"&gt;user1@domain.local&lt;/A&gt;&amp;gt; &lt;BR /&gt;User Object Type - &lt;PERSON&gt;&lt;/PERSON&gt;&lt;/USER1&gt;&lt;/OU&gt;&lt;/AUTHENTICATED&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 12:42:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599635#M8596</guid>
      <dc:creator>Jaaazman777</dc:creator>
      <dc:date>2011-03-16T12:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 4400: Web Authentication Using LDAP</title>
      <link>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599636#M8597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Jaaazman777 wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dear Nicolas!&lt;/P&gt;&lt;P&gt;Thank you very much for your advices!&lt;/P&gt;&lt;P&gt;Everything works now!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested the settings with the help of ldap browser, and then applied them to the controller&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Final WLC Ldap-server settings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Simple Bind -&amp;nbsp; &lt;AUTHENTICATED&gt; (Anonymous doesn't work) &lt;BR /&gt;Bind Username - the user must be created in User Base DN folder (ex. OU=ORG)&lt;BR /&gt;User Base DN -&amp;nbsp; the core OU, that contains all users (ex. &lt;OU&gt;)&lt;BR /&gt;User Attribute - there can be two variants:&lt;BR /&gt;- sAMAccountName - &lt;USER1&gt; &lt;BR /&gt;- userPrincipalName - &amp;lt;&lt;A class="jive-link-anchor-small"&gt;user1@domain.local&lt;/A&gt;&amp;gt; &lt;BR /&gt;User Object Type - &lt;PERSON&gt;&lt;/PERSON&gt;&lt;/USER1&gt;&lt;/OU&gt;&lt;/AUTHENTICATED&gt;&lt;/PRE&gt;
&lt;/PRE&gt;&lt;P&gt;I have the same strange problem.&lt;/P&gt;&lt;P&gt;i have WCS and 3 2000 seriec controllers.&lt;/P&gt;&lt;P&gt;everything works fine through ldap browser but authenticationalways gives me an error:&lt;/P&gt;&lt;P&gt;the username and password combination is invalid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;im also using WPA2 AES PSK and Mac filtering, in case this may affect anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/1/9/11917-WCS.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 15:42:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-4400-web-authentication-using-ldap/m-p/1599636#M8597</guid>
      <dc:creator>vince.steiner</dc:creator>
      <dc:date>2011-03-16T15:42:30Z</dc:date>
    </item>
  </channel>
</rss>

