I am working on my first 9800 implementation and set up a 9800-C in the lab. I am having issues using radius to log in to the controller.
I can log in via WEB GUI using radius credentials, I am using ISE as the radius server. I see good radius transactions and the av-pair (shell:priv-lvl=15) is returned from ISE when I log in via web GUI.
When I try to log in via CLI, no request is sent to the radius server. aaa / RADIUS debug shows:
AAA/AUTHEN/LOGIN (000044CE): Pick method list ' Permanent Local' and there is no transaction in the RADIUS log.
Current config is:
c9800-test-1.stp#show run aaa
aaa authentication login authentication_login local group ise_radius_grp
aaa authentication dot1x authentication_dot1x group ise_radius_grp
aaa authorization exec authentication_login local group ise_radius_grp
username admin privilege 15 secret 9 $x$012345abcde#
aaa server radius dynamic-author
client 10.28.16.77 server-key 7 012345abcde
client 10.18.16.77 server-key 7 012345abcde
radius server isepsn1
address ipv4 10.1.2.3 auth-port 1645 acct-port 1646
key 7 012345abcde
radius server isepsn2
address ipv4 10.1.2.4 auth-port 1645 acct-port 1646
key 7 012345abcde
radius-server load-balance method least-outstanding
aaa group server radius ise_radius_grp
server name isepsn1
server name isepsn2
aaa local authentication authentication_login authorization authentication_login
aaa session-id common
Also, on the console, I am always automatically logged in.
This event was scheduled for September 23rd, but it has been moved to November 10 due to complex and unexpected circumstances. We apologize for all the issues this may cause.
Community Live- All Things LTE…4G, 5G and Whatever’s Next
(Live event - formerly...
Hello i have acces point 1815i cisco and we want installed in entreprise and we have camera surveillance wireless cisco so i want to know how much distance between ap 1815i and camera surveillance wi...
We want to broadcast a SSID (and allow users to connect) between certain times each day, and then take it offline. Unfortunately we dont have prime and only DNA Essential Smart licencing. All documents that I am seeing is that its possible if you have pri...
Hi all,I am looking for some guidance here, and I am quite certain that some of you, great minds, will be able to stir me in the right direction here. And a big thanks in advance. Here we go, i have three sites connected over private link MPLS....
Hi to all I purchase new AP C9120AXE converted to EWC.I notice when AP is booting a message related to default route not set that it says that can affect performance.Message is : %Default route without gateway, if not a point-to-point interface,...