02-12-2019 08:29 PM - edited 03-11-2019 01:55 AM
So we have newly deployed ISE in our environment.
We have new and old SSID. New SSID is using ISE.
Problem description:
From ISE logs, the user already allowed network access and is connected to new SSID.
But for some reason, the user doesn't seem to have network/internet access.
When I check inside WLC, the user seems still connected to the old SSID.
Action taken:
So what I did was, I remove the user endpoint from WLC.
After that, reconnect back to the new SSID, and confirmed in WLC it is connected to the new SSID.
Question:
From ISE point of view, it did send the CoA and give access to the enduser, but from WLC it seems like the enduser still retaining the previous session (with old SSID).
What was happening actually as I can't quite figure out why WLC still retaining the previous session, while the user is already connected to another SSID.
Thanks in advance.
Solved! Go to Solution.
02-13-2019 04:50 AM
02-13-2019 03:19 AM
What OS version is running on WLC. I suggest to start looking at the recommended OS for ISE integration and move to it. Below for ISE 2.4 with WLC
https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/compatibility/b_ise_sdt_24.html#ciscowlcs
02-13-2019 04:50 AM
02-13-2019 08:38 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide