01-22-2024 03:54 AM
When client joins network for a first time, we get "Radius session not found. Please contact helpdesk for assistance". After turning WiFi of the device Off and back on, everything works fine. We are running 17.11.1 on WLC9800 and 3.2 patch 4 on ISE
Solved! Go to Solution.
02-10-2024 12:11 AM
You clearly have a lot more going on here than you initially described and did not provide enough troubleshooting details. Please see How to Ask The Community for Help and call TAC so they may take the time to understand all components involved and where it might be wrong.
02-10-2024 02:47 AM
Just for my understanding, which exact troubleshooting details did I not provide?
02-23-2024 12:33 AM
For anyone that might get an issue, solution was to change "port-bounce" to "re-auth" in Administration >> System >> Settings >> Profiling
01-31-2024 03:09 AM
How many ISE PSNs you have?
01-31-2024 03:12 AM
Only one PSN. I have seen the issue with F5 but that does not apply to our case I guess
01-31-2024 03:28 AM
as you can see 3rd entry is failed one:
Calling-Station-ID | a235.82d1.87be |
Error-Cause | 200 |
cisco-command-code | 2 |
01-31-2024 03:32 AM
Also first time Authorization result is empty:
Event | 5231 Guest Authentication Passed |
Username | fdoyle1 |
Endpoint Id | A2:35:82:D1:87:BE |
Endpoint Profile | |
Authorization Result |
compared to second attempt:
Event | 5236 Authorize-Only succeeded |
Username | fdoyle1 |
Endpoint Id | A2:35:82:D1:87:BE |
Endpoint Profile | Apple-iPhone |
Authentication Policy | Default |
Authorization Policy | Default >> Wi-Fi_Guest_Access_AV_Control |
Authorization Result | PermitAccess,my681-AV-Control |
01-31-2024 04:08 AM
Can you make l2 secuirty none and select mac filtering and check'
I Think using psk plus portal is issue here.
MHM
01-31-2024 04:59 AM
It is a bit of problem as site is in production, but I will give it a try. Can you please explain to me why do you think that PSK is a problem?
01-31-2024 05:10 AM - edited 01-31-2024 05:10 AM
No need adjust wlan and new test wlan and test the config
For psk+ cwa I already check and you can run both in same wlan
But I find bug so let wait your results to see if issue from ISE not from wlc.
Until you try it I will also analyze wireshark you share to see if there is other problem
Thanks
MHM
01-31-2024 05:24 AM
OK. Got it. I will create a Test WLAN and test with open no PSK and we see..
02-01-2024 06:07 AM
I have tested with Open SSID and it does seem to be working. However I do see the same issue on ISE Live logs as what is seen when PSK is enabled.
Calling-Station-ID | 524e.476d.3e5b |
Error-Cause | 200 |
cisco-command-code | 2 |
Also what is different is that username is empty in this request when compared with one with PSK:
Event | 5205 Dynamic Authorization succeeded |
Username | |
Endpoint Id | 52:4E:47:6D:3E:5B |
Endpoint Profile | |
Authorization Result |
However, not using PSK is not acceptable solution for us, but it might be a good lead to troubleshoot further.
02-02-2024 03:42 AM
So I did some further troubleshooting, on this newly created TEST SSID, I added PSK and it worked again. Then I added WPA with AES (which I need in order to support some very old devices) and Fast transition and then it stopped working. Removing those back still did not solve the issue. I had to set SSID back to Open and then again to WPA2 and now it seems again to be working fine. So it is inconclusive still if the issue is related to WPA and Fast Transition, or it is just random that it does not work....
02-02-2024 03:50 AM
FT and the Client failed to auth is Mac iOS?
MHM
02-02-2024 04:05 AM
It is IOS Apple iPhone 11
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide