cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8332
Views
13
Helpful
47
Replies

Radius session not found ISE and Guest Portal / Sponsored Portal

vaniat
Level 1
Level 1

When client joins network for a first time, we get "Radius session not found. Please contact helpdesk for assistance". After turning WiFi of the device Off and back on, everything works fine. We are running 17.11.1 on WLC9800 and 3.2 patch 4 on ISE

47 Replies 47

thomas
Cisco Employee
Cisco Employee

You clearly have a lot more going on here than you initially described and did not provide enough troubleshooting details. Please see How to Ask The Community for Help and call TAC so they may take the time to understand all components involved and where it might be wrong.

Just for my understanding, which exact troubleshooting details did I not provide? 

For anyone that might get an issue, solution was to change "port-bounce" to "re-auth" in Administration >> System >> Settings >> Profiling

How many ISE PSNs you have?

Only one PSN. I have seen the issue with F5 but that does not apply to our case I guess

Screenshot 2024-01-31 at 12.27.14.png

 as you can see 3rd entry is failed one:

Result

Calling-Station-IDa235.82d1.87be
Error-Cause200
cisco-command-code2

Also first time Authorization result is empty:

Overview

Event5231 Guest Authentication Passed
Usernamefdoyle1
Endpoint IdA2:35:82:D1:87:BE 
 
Endpoint Profile 
Authorization Result

compared to second attempt:

Overview

Event5236 Authorize-Only succeeded
Usernamefdoyle1
Endpoint IdA2:35:82:D1:87:BE 
 
Endpoint ProfileApple-iPhone
Authentication PolicyDefault
Authorization PolicyDefault >> Wi-Fi_Guest_Access_AV_Control
Authorization ResultPermitAccess,my681-AV-Control

Can you make l2 secuirty none and select mac filtering and check'

I Think using psk plus portal is issue here.

MHM

It is a bit of problem as site is in production, but I will give it a try. Can you please explain to me why do you think that PSK is a problem? 

No need adjust wlan and new test wlan and test the config 

For psk+ cwa I already check and you can run both in same wlan 

But I find bug so let wait your results to see if issue from ISE not from wlc.

Until you try it I will also analyze wireshark you share to see if there is other problem

Thanks 

MHM

OK. Got it. I will create a Test WLAN and test with open no PSK and we see..

vaniat
Level 1
Level 1

I have tested with Open SSID and it does seem to be working. However I do see the same issue on ISE Live logs as what is seen when PSK is enabled.

Result

Calling-Station-ID524e.476d.3e5b
Error-Cause200
cisco-command-code2

Also what is different is that username is empty in this request when compared with one with PSK:

Overview

Event5205 Dynamic Authorization succeeded
Username 
Endpoint Id52:4E:47:6D:3E:5B 
 
Endpoint Profile 
Authorization Result

However, not using PSK is not acceptable solution for us, but it might be a good lead to troubleshoot further.

So I did some further troubleshooting, on this newly created TEST SSID, I added PSK and it worked again. Then I added WPA with AES (which I need in order to support some very old devices) and Fast transition and then it stopped working. Removing those back still did not solve the issue. I had to set SSID back to Open and then again to WPA2 and now it seems again to be working fine. So it is inconclusive still if the issue is related to WPA and Fast Transition, or it is just random that it does not work.... 

FT and the Client failed to auth is Mac iOS?

MHM

It is IOS Apple iPhone 11