cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1192
Views
0
Helpful
2
Replies

WLC logs Authentication failed for client xxx ACL override mismatch from AAA server

Not applicable

Hi,

 

Have simple setup where the wlc uses ISE for Radius for AAA , and get this message 

%APF-3-CLIENT_NO_ACCESS: Authentication failed for client: 74:8d:08:6a:f1:43. ACL override mismatch from AAA server

The authC policy checks wireless MAB and default network access and continue if user not found.

At this point the from the ISE does not show an error, but the wlc displays the above error in the log, and the user is not able to connect to the WLAN .

Any useful suggestions would be great 

2 Replies 2

Francesco Molino
VIP Alumni
VIP Alumni

Hi 

Do you have a firewall in between your wlc and ISE? They're communicating through port udp/1700 for CoA.

What are ISE logs? 

Was it working before? Does the acl name in ISE profile and wlc is exactly the same (case sensitive)?

Thanks 

PS: Please don't forget to rate and mark as correct answer if this answered your question


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Duplicate of https://supportforums.cisco.com/discussion/13329386/wlc-logs-authentication-failed-client-xxx-acl-override-mismatch-aaa-server